Control mappings
Fourteen shipped frameworks cross-walked to each other, plus custom frameworks with preventive, detective, corrective and compensating control types and an evidence frequency per control.
The same platform, applied to the regulators, attack patterns and asset types of your sector. Framework mappings, Rego policy templates and the finding ontology are shared; what changes is which controls, exposures and workloads matter most.
Which shipped framework mappings apply, which policy templates matter first, and where custom frameworks fill the sector-specific gap.
DORA, PCI DSS v4, SOX ITGC and NIS2 ship mapped; FFIEC and OCC expectations are expressed as custom frameworks cross-walked to NIST 800-53.
HIPAA Security Rule ships mapped; HITRUST, GxP and 21 CFR Part 11 obligations are modelled as custom frameworks over the same evidence.
NIST 800-53 Rev. 5 and the FedRAMP Moderate baseline ship as mappings. Fully self-hosted deployment keeps every byte inside your boundary. No authorization is held or claimed.
For platforms with thousands of services across multi-cloud. Engineer-first workflows: PR-based policy, signed builds, ephemeral environments.
PCI DSS v4 and CCPA/CPRA ship mapped. Continuous re-evaluation keeps control status current between assessments.
OT asset context from Claroty, Nozomi and Tenable OT connectors joins the same graph as IT findings. NERC CIP and IEC 62443 are modelled as custom frameworks.
Content-security obligations such as TPN and MPA are modelled as custom frameworks; the platform supplies the code, image and cloud evidence behind them.
IEC 62443 and TISAX obligations as custom frameworks; supply-chain checks and SBOMs for the software you ship inside products.
HECVAT v3 ships mapped; FERPA and CUI handling are modelled as custom frameworks cross-walked to NIST 800-53.
Mappings are cross-walked pair-wise from published crosswalks and closed transitively, so a control satisfied in one framework lights up its equivalents. Anything not listed is expressed as a custom framework with the same control model. SecurityVault holds no certification of its own.
Fourteen shipped frameworks cross-walked to each other, plus custom frameworks with preventive, detective, corrective and compensating control types and an evidence frequency per control.
Rego policy templates and a visual builder that compiles to Rego. Evaluation fails closed; every decision is Ed25519-signed.
Read-only, invitation-based access for auditors with signed evidence and its own key authority. Questionnaire responses are generated from the same evidence.
Hosted, your-cluster scan band, or fully self-hosted. Same charts, same signed images, same trust boundaries.
Every sector reads the same graph: which commit, which image, which workload, which identity, which data store. Attack paths and blast radius come from it.
Regulatory change ingestion with impact assessment against your mapped controls, so a framework revision shows up as work items, not a surprise.
A 30-minute session on your sector: which mappings apply today, which controls need a custom framework, and how a scan result becomes evidence for both.