Scrutineer · Platform
Security compliance software for cybersecurity and IT compliance teams
Security compliance software exists because security teams keep proving the same thing over and over. You already run access reviews, patch on a schedule and encrypt data at rest, then SOC 2 asks you to evidence it, ISO 27001 asks again in different vocabulary, and the HIPAA and PCI assessors ask a third time. Scrutineer maps your controls once and crosswalks them across every framework you carry.
The evidence collection is automatic. Scrutineer connects read-only to your cloud, identity and ticketing systems, pulls the artifacts behind each control, and watches for drift. A bucket that loses its encryption setting, a departed employee with a live token, a certificate three weeks from expiry: you find out that day rather than during audit fieldwork. It scores your third parties too, because your security posture includes every vendor holding your data. Readiness and decision-support; an accredited auditor issues the attestation.
Control-mapped findings · linked evidence · you decide what to remediate
›
Illustrative sample · not an audit attestation
Controls in evidence-linked report out
AI scrutinizes you decide
Why it works
What you get with security compliance
Nobody can certify you against half the frameworks your customers ask about
The first thing to settle in a security compliance program is who signs what, because the answer is different for every framework and two of the common ones have no signature at all. ISO/IEC 27001 produces a certificate from an accredited certification body. SOC 2 produces a report and an opinion from a licensed CPA firm, based on assertions management wrote, which is why there is no SOC 2 certificate and no certifying body. PCI DSS produces an Attestation of Compliance, signed by a QSA at higher levels and by you on a self-assessment questionnaire at lower ones. FedRAMP produces an authorization granted by a federal agency. HIPAA produces nothing: HHS states plainly that it does not endorse or otherwise recognize private organizations certifications regarding the Privacy Rule or Security Rule, and that such certifications do not absolve covered entities of their legal obligations. A vendor selling you HIPAA certification is selling a private badge, and a customer demanding one is asking for something that does not exist. Knowing the issuer per framework tells you what you can promise a buyer and what you have to explain to them instead.
The second framework costs a fraction of the first, and that ratio is the business case
Access control, encryption at rest and in transit, logging and monitoring, change management, vulnerability management, backup and recovery, incident response, and vendor management appear in some form in SOC 2, ISO 27001, HIPAA Security Rule, PCI DSS and the state privacy laws. The wording differs, the evidence usually does not. A screenshot of an access review satisfies a Trust Services criterion, an Annex A control and an administrative safeguard at the same time, if your control library is built once and mapped rather than rebuilt per framework. This is the entire economic argument for a crosswalk, and it is also where badly run programs lose the money: teams that stand up a second framework as a separate project pay close to full price twice, collect the same artifacts into two folders, and then have two sets of evidence that disagree by the following quarter. Build the control library first and treat frameworks as views over it.
Evidence has a shelf life, and expiry is what actually fails a Type 2
A Type 1 report asks whether controls were suitably designed at a point in time. A Type 2 asks whether they operated effectively across a period, typically three to twelve months, and that difference is where most first audits go wrong. A control that worked in month one and quietly stopped in month five is an exception, and it will be written up regardless of how good the policy document is. The common causes are boring: an offboarded employee whose token stayed live, a bucket that lost its encryption setting during a migration, a quarterly access review that slipped a quarter, a certificate that expired over a holiday, a subprocessor added without a review. None of these are visible in a policy library, and none of them show up in an annual walkthrough. They show up in the sample the auditor pulls. That is why continuous evidence collection is worth more than a better document template: the point is not tidier paperwork, it is finding the gap in month five instead of during fieldwork.
What it handles
Controls in, an evidence-linked report out
Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.
- Maps existing security controls to every framework at once
- Collects control evidence automatically and read-only
- Crosswalks overlapping SOC 2, ISO 27001, HIPAA and PCI requirements
- Detects control drift and routes it to an owner
- Scores and monitors the vendors inside your security perimeter
- Auto-answers inbound security questionnaires from live evidence
- Tracks which framework each customer segment actually accepts, so you stop buying paper nobody asked for
- Keeps a dated record of who approved each control and each exception, which is the first thing an assessor asks to see
evidence · MFA enforced and access reviews evidenced.
evidence · Mostly covered; one approval log left untested.
evidence · Two subprocessors missing a current review.
evidence · Data encrypted in transit and at rest, evidenced.
Why Scrutineer
One platform that maps controls and scores risk
Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.
Mapped to real controls
Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.
Evidence behind every finding
Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.
A prioritized gap list
Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.
Framework acceptance reference
Which security framework each buyer actually accepts, and what they will not take instead
Published comparisons line frameworks up control by control, which is useful once you have already chosen. The question that actually blocks deals is narrower: the person holding up your contract wants one specific document, and will not take a different one. This table runs on who is asking and what they will accept, because that is the order in which the decision gets made.
| Who is asking | What they will actually accept | What they will not take instead | Who issues it | What it still does not prove |
|---|---|---|---|---|
| US enterprise SaaS buyer running a security review | A SOC 2 Type 2 report covering a period that has not gone stale, with the product in scope | A Type 1, a policy pack, or a badge that says SOC 2 compliant | A licensed CPA firm, expressing an opinion on assertions management wrote | That the scope covers the system they are buying. Management chose the description |
| European or UK enterprise buyer | An ISO/IEC 27001 certificate, plus the Statement of Applicability behind it | A SOC 2 report, which many non-US procurement teams do not recognize as equivalent | A certification body accredited by a national accreditation authority | That any particular control was tested. Certification audits work on samples |
| A US federal agency | A FedRAMP authorization at the right impact level, listed on the marketplace | Any commercial attestation, at any depth, however recent | A sponsoring federal agency, through the FedRAMP process | That you are authorized at an impact level other than the one listed |
| Anyone who touches your card payments | An Attestation of Compliance for the correct merchant or service provider level | A SOC 2 report. The Trust Services criteria do not cover the PCI DSS requirements | A QSA at higher levels; you, on a self-assessment questionnaire, at lower ones | Anything about the months after the assessment date. It is a point-in-time attestation |
| A US college or university | A completed HECVAT, filed where the institution can actually find it | A generic questionnaire response or a security one-pager from sales | You. It is a self-report on the EDUCAUSE template | That anybody checked the answers before the institution relied on them |
| A US defense prime flowing requirements down to you | A NIST SP 800-171 self-assessment score in SPRS and the DFARS 252.204-7012 clause honored | A SOC 2 or ISO 27001 certificate in place of the 800-171 score | You, into SPRS. Third-party CMMC Level 2 assessment is suspended, not canceled, as of July 13, 2026 | That the score is current. It reflects the day you filed it, not today |
| A US healthcare covered entity asking whether you are HIPAA certified | Nothing, because no such thing exists. In practice: a HITRUST certification, or a SOC 2 with HIPAA criteria mapped in, plus a signed business associate agreement | A HIPAA certified badge purchased from a private training or audit vendor | Nobody. HHS does not endorse or otherwise recognize private organizations certifications regarding the Privacy Rule or the Security Rule | That you are compliant. HHS states that such certifications do not absolve covered entities of their legal obligations |
The last row is the one that costs the most time. HIPAA certification is the most requested document in US healthcare sales and it does not exist, so the work is not obtaining it, it is having a short, credible answer ready that offers the buyer HITRUST or a HIPAA-mapped SOC 2 plus a business associate agreement instead.
Good questions
Questions about security compliance
Keep reading
Guides that go deeper on security compliance
ISO 27001 vs SOC 2
Which of the two your buyers will actually accept, what each one costs you, and why carrying both is cheaper than it looks.
Read the guideBest SOC 2 compliance software
How the categories of SOC 2 tooling differ once you get past the feature grid, and which fits a first audit.
Read the guideBest GRC software
The wider platform comparison, for teams whose control library has to carry risk and vendor work too.
Read the guideExplore more
More ways to scrutinize compliance and risk with Scrutineer
SOC 2 compliance
Map controls to the Trust Services Criteria, collect evidence, and close gaps before audit.
Learn moreSOC 2 compliance software
A platform that maps SOC 2 controls, automates evidence, and tracks readiness continuously.
Learn moreISO 27001 compliance
Map your ISMS to Annex A, automate evidence, and stay certification-ready.
Learn moreStop guessing about readiness. Scrutinize on real evidence.
Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.
SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification