Scrutineer.ai

Scrutineer · Platform

Security compliance software for cybersecurity and IT compliance teams

Security compliance software exists because security teams keep proving the same thing over and over. You already run access reviews, patch on a schedule and encrypt data at rest, then SOC 2 asks you to evidence it, ISO 27001 asks again in different vocabulary, and the HIPAA and PCI assessors ask a third time. Scrutineer maps your controls once and crosswalks them across every framework you carry.

The evidence collection is automatic. Scrutineer connects read-only to your cloud, identity and ticketing systems, pulls the artifacts behind each control, and watches for drift. A bucket that loses its encryption setting, a departed employee with a live token, a certificate three weeks from expiry: you find out that day rather than during audit fieldwork. It scores your third parties too, because your security posture includes every vendor holding your data. Readiness and decision-support; an accredited auditor issues the attestation.

or try it below ↓

Control-mapped findings · linked evidence · you decide what to remediate

The Scrutiny Desk

Illustrative sample · not an audit attestation

SOC 2 ISO 27001 HIPAA GDPR PCI DSS

Controls in evidence-linked report out

AI scrutinizes you decide

Why it works

What you get with security compliance

Nobody can certify you against half the frameworks your customers ask about

The first thing to settle in a security compliance program is who signs what, because the answer is different for every framework and two of the common ones have no signature at all. ISO/IEC 27001 produces a certificate from an accredited certification body. SOC 2 produces a report and an opinion from a licensed CPA firm, based on assertions management wrote, which is why there is no SOC 2 certificate and no certifying body. PCI DSS produces an Attestation of Compliance, signed by a QSA at higher levels and by you on a self-assessment questionnaire at lower ones. FedRAMP produces an authorization granted by a federal agency. HIPAA produces nothing: HHS states plainly that it does not endorse or otherwise recognize private organizations certifications regarding the Privacy Rule or Security Rule, and that such certifications do not absolve covered entities of their legal obligations. A vendor selling you HIPAA certification is selling a private badge, and a customer demanding one is asking for something that does not exist. Knowing the issuer per framework tells you what you can promise a buyer and what you have to explain to them instead.

The second framework costs a fraction of the first, and that ratio is the business case

Access control, encryption at rest and in transit, logging and monitoring, change management, vulnerability management, backup and recovery, incident response, and vendor management appear in some form in SOC 2, ISO 27001, HIPAA Security Rule, PCI DSS and the state privacy laws. The wording differs, the evidence usually does not. A screenshot of an access review satisfies a Trust Services criterion, an Annex A control and an administrative safeguard at the same time, if your control library is built once and mapped rather than rebuilt per framework. This is the entire economic argument for a crosswalk, and it is also where badly run programs lose the money: teams that stand up a second framework as a separate project pay close to full price twice, collect the same artifacts into two folders, and then have two sets of evidence that disagree by the following quarter. Build the control library first and treat frameworks as views over it.

Evidence has a shelf life, and expiry is what actually fails a Type 2

A Type 1 report asks whether controls were suitably designed at a point in time. A Type 2 asks whether they operated effectively across a period, typically three to twelve months, and that difference is where most first audits go wrong. A control that worked in month one and quietly stopped in month five is an exception, and it will be written up regardless of how good the policy document is. The common causes are boring: an offboarded employee whose token stayed live, a bucket that lost its encryption setting during a migration, a quarterly access review that slipped a quarter, a certificate that expired over a holiday, a subprocessor added without a review. None of these are visible in a policy library, and none of them show up in an annual walkthrough. They show up in the sample the auditor pulls. That is why continuous evidence collection is worth more than a better document template: the point is not tidier paperwork, it is finding the gap in month five instead of during fieldwork.

What it handles

Controls in, an evidence-linked report out

Point Scrutineer at a framework or a vendor and it maps every control, pulls the evidence it can find, flags the gaps and scores the risk, returning a report with linked evidence and a prioritized remediation list. Scrutineer is decision support for readiness, an accredited auditor still issues the attestation.

  • Maps existing security controls to every framework at once
  • Collects control evidence automatically and read-only
  • Crosswalks overlapping SOC 2, ISO 27001, HIPAA and PCI requirements
  • Detects control drift and routes it to an owner
  • Scores and monitors the vendors inside your security perimeter
  • Auto-answers inbound security questionnaires from live evidence
  • Tracks which framework each customer segment actually accepts, so you stop buying paper nobody asked for
  • Keeps a dated record of who approved each control and each exception, which is the first thing an assessor asks to see
SECURITY COMPLIANCE readiness_report
READINESS · 82%
ACCESS CONTROL 91

evidence · MFA enforced and access reviews evidenced.

CHANGE MGMT 78

evidence · Mostly covered; one approval log left untested.

VENDOR RISK 64

evidence · Two subprocessors missing a current review.

ENCRYPTION 86

evidence · Data encrypted in transit and at rest, evidenced.

Example report layout, not customer data

Why Scrutineer

One platform that maps controls and scores risk

Not a static questionnaire, not a pass-fail black box, and not a spreadsheet you maintain by hand. Live control mapping across SOC 2, ISO 27001, HIPAA, GDPR and PCI, automatic evidence and a prioritized gap list, returned as a report you can act on. The AI scrutinizes, you decide.

Mapped to real controls

Every framework is broken down into the controls it actually requires, each scored on a red to amber to green scale, so readiness stays transparent and consistent.

Evidence behind every finding

Each control links to the exact evidence that satisfies it, the policy, the config, the log line, so the finding is auditable and your readiness is defensible.

A prioritized gap list

Open gaps roll up into a ranked remediation list, so the highest-risk findings sit at the top and your team fixes what matters before the audit begins.

Framework acceptance reference

Which security framework each buyer actually accepts, and what they will not take instead

Published comparisons line frameworks up control by control, which is useful once you have already chosen. The question that actually blocks deals is narrower: the person holding up your contract wants one specific document, and will not take a different one. This table runs on who is asking and what they will accept, because that is the order in which the decision gets made.

Who is asking What they will actually accept What they will not take instead Who issues it What it still does not prove
US enterprise SaaS buyer running a security review A SOC 2 Type 2 report covering a period that has not gone stale, with the product in scope A Type 1, a policy pack, or a badge that says SOC 2 compliant A licensed CPA firm, expressing an opinion on assertions management wrote That the scope covers the system they are buying. Management chose the description
European or UK enterprise buyer An ISO/IEC 27001 certificate, plus the Statement of Applicability behind it A SOC 2 report, which many non-US procurement teams do not recognize as equivalent A certification body accredited by a national accreditation authority That any particular control was tested. Certification audits work on samples
A US federal agency A FedRAMP authorization at the right impact level, listed on the marketplace Any commercial attestation, at any depth, however recent A sponsoring federal agency, through the FedRAMP process That you are authorized at an impact level other than the one listed
Anyone who touches your card payments An Attestation of Compliance for the correct merchant or service provider level A SOC 2 report. The Trust Services criteria do not cover the PCI DSS requirements A QSA at higher levels; you, on a self-assessment questionnaire, at lower ones Anything about the months after the assessment date. It is a point-in-time attestation
A US college or university A completed HECVAT, filed where the institution can actually find it A generic questionnaire response or a security one-pager from sales You. It is a self-report on the EDUCAUSE template That anybody checked the answers before the institution relied on them
A US defense prime flowing requirements down to you A NIST SP 800-171 self-assessment score in SPRS and the DFARS 252.204-7012 clause honored A SOC 2 or ISO 27001 certificate in place of the 800-171 score You, into SPRS. Third-party CMMC Level 2 assessment is suspended, not canceled, as of July 13, 2026 That the score is current. It reflects the day you filed it, not today
A US healthcare covered entity asking whether you are HIPAA certified Nothing, because no such thing exists. In practice: a HITRUST certification, or a SOC 2 with HIPAA criteria mapped in, plus a signed business associate agreement A HIPAA certified badge purchased from a private training or audit vendor Nobody. HHS does not endorse or otherwise recognize private organizations certifications regarding the Privacy Rule or the Security Rule That you are compliant. HHS states that such certifications do not absolve covered entities of their legal obligations

The last row is the one that costs the most time. HIPAA certification is the most requested document in US healthcare sales and it does not exist, so the work is not obtaining it, it is having a short, credible answer ready that offers the buyer HITRUST or a HIPAA-mapped SOC 2 plus a business associate agreement instead.

Good questions

Questions about security compliance

Security compliance software maps an organization's security controls to the frameworks it must satisfy, collects the evidence proving those controls operate, and flags gaps continuously. It replaces spreadsheet control matrices and manual screenshot collection with an automated, always-current view of where your security posture stands against SOC 2, ISO 27001, HIPAA, PCI DSS and GDPR.
Cybersecurity is the work of actually protecting systems and data. Security compliance is proving to an outside party that the work meets a defined standard. They overlap heavily but are not the same: you can be genuinely secure and fail an audit for lack of evidence, and you can pass an audit with controls that are documented better than they are operated.
They solve different problems. A SIEM detects and investigates security events in real time. Compliance software tracks whether your controls exist, are mapped to requirements, and have evidence behind them. Most teams that carry more than one framework end up needing both, and compliance software will typically pull log-retention and monitoring evidence from the SIEM you already run.
More than most teams expect. Access control, encryption, logging, change management, vulnerability management and incident response appear in some form in SOC 2, ISO 27001, HIPAA, PCI DSS, GDPR and SOX. A good crosswalk means the second and third frameworks cost far less than the first, which is exactly what control mapping is for.
Connecting systems and getting a scored readiness view takes days, not quarters. Closing the gaps that view surfaces is the real timeline and it depends on how much genuine remediation you need, typically a few weeks to a few months. The audit period itself is then set by your framework and your auditor, not by the software.
No. There is no government HIPAA certification and no accredited body that issues one. HHS states that it does not endorse or otherwise recognize private organizations certifications regarding the HIPAA Privacy Rule or Security Rule, and that such certifications do not absolve covered entities of their legal obligations. What US healthcare buyers will accept instead is a HITRUST certification, a SOC 2 with HIPAA criteria mapped in, and a signed business associate agreement.
SOC 2 is a US attestation engagement. A licensed CPA firm examines a system description management wrote and issues a report with an opinion, so there is no certificate. ISO/IEC 27001 is an international certification: an accredited body audits your information security management system and issues a certificate valid for three years with surveillance audits in between. US buyers usually ask for SOC 2. Buyers outside the US usually ask for ISO 27001.
Only if customers are asking for it. The controls overlap heavily, so the second framework is mostly a mapping and documentation exercise rather than a new evidence program, but it still costs an audit cycle and a certification body. The usual trigger is a European or UK enterprise deal where procurement will not accept a SOC 2 report, or an RFP that names ISO 27001 as a requirement.
A crosswalk maps one internal control to every framework requirement it satisfies. One access review control can map to a SOC 2 common criterion, an ISO 27001 Annex A control, a HIPAA administrative safeguard and a PCI DSS requirement at once. The value is that evidence is collected once and reused, so adding a framework becomes a mapping question rather than a fresh evidence project.
No, and be wary of any tool that implies otherwise. Software maps controls, collects evidence, flags drift and shows you where you stand before an auditor does. It cannot operate the control for you, and it cannot issue an opinion. An accredited auditor or certification body does that. What good tooling changes is how much of the audit is discovery and how much is confirmation.
It is checking control state on a schedule measured in hours rather than once a year. A read-only connection to your cloud, identity and ticketing systems pulls the artifact behind each control, compares it against the expected state, and raises an owner-assigned issue when the two diverge. The practical benefit is that drift surfaces in month five instead of during audit fieldwork, when it becomes an exception.
Published pricing in this category is unreliable enough that quoting a figure would mislead you. What actually drives the number is the count of frameworks you carry, the number of integrations, whether vendor risk and questionnaire response are included, headcount tiers, and whether audit support or an auditor introduction is bundled. Price two vendors on the same framework count and integration list, or the quotes are not comparable.
SOC 2 Type 2 dominates US enterprise software procurement by a wide margin. HIPAA obligations and a business associate agreement come next if you touch protected health information, PCI DSS if you touch cardholder data, ISO 27001 when you start selling internationally, and FedRAMP only if you are selling to federal agencies. Build for the buyer you have rather than collecting frameworks speculatively.

Keep reading

Guides that go deeper on security compliance

Explore more

More ways to scrutinize compliance and risk with Scrutineer

Stop guessing about readiness. Scrutinize on real evidence.

Point Scrutineer at a framework or a vendor and it maps every control, gathers evidence and scores the risk, returning an evidence-linked report and a prioritized gap list. The AI scrutinizes, you decide.

See pricing

SOC 2, ISO 27001, HIPAA, GDPR & PCI · evidence-linked controls · readiness, not certification