Compliance evidence
Audit evidence as a side effect of monitoring.
Auditors don't just ask whether you monitor your external systems; they ask you to prove it happened all year. Reconstructing that the week before fieldwork costs days and still reads as a described process. Attack Surface Scan produces the proof by running: scheduled checks with full history, an alert trail, recorded risk decisions, and dated reports you hand over as they are.
No card required to start. Plans from $25/month, flat; first report in minutes.
Where the evidence lands
SOC 2
The Common Criteria expect you to monitor infrastructure for vulnerabilities and configuration change (CC7.1) and to evaluate that monitoring (CC4.1). A year of scheduled checks, alerts and resolved findings is that control operating, across the whole period, not just the week before fieldwork.
ISO 27001
Annex A 8.8 asks how you manage technical vulnerabilities; A.5.7 asks where threat intelligence comes from. Dated history, exploitation-ranked findings and lookalike-domain watching answer both with records instead of a described process.
Cyber insurance and security questionnaires
"Do you perform external vulnerability scanning? How often? How do you track remediation?" Attach last week's report and the evidence pack instead of a paragraph the assessor takes on faith.
Framework views
Findings are mapped to OWASP Top 10, CWE, PCI DSS 4.0, CIS Controls and GDPR, plus a view of everything on the U.S. government's list of actively exploited vulnerabilities. Areas an outside view cannot assess are shown as not assessed, never as a pass. How the mapping works →
Why continuous beats point-in-time
The audit question is never "were you secure on scan day"; it's "does the control operate". A scan run before the audit produces one data point; a schedule produces a record.
History is the control
Scheduled checks, the changes they caught, and the findings that got resolved form a timeline. That timeline is what "monitoring operated effectively" looks like as evidence.
Alerts prove response, not just detection
The alert trail shows issues were surfaced when they happened, and risks accepted with a reason and a review date show decisions being made deliberately.
An evidence pack written for the auditor
A dated PDF that leads with cadence and coverage (how many checks ran, how many weeks they covered, the score trend) and then summarises posture by framework. It is written for an auditor or insurer, not an engineer.
Point-in-time proof when asked
Any check exports as a dated PDF. When an auditor asks what your posture was in March, you send March's report. Reports and evidence packs are kept for a year; download anything you need to keep longer.
Honest scoping: this is monitoring evidence for a handful of controls, not a compliance program. It does not replace a penetration test and it is not a PCI ASV scan. It covers the "continuous external monitoring" row of your controls matrix, and covers it well. SOC 2 Type 2 evidence → · Control-by-control mapping → · Why external monitoring is the missing row →
Common questions
Is Attack Surface Scan itself SOC 2 certified?
Attack Surface Scan produces evidence for your audit; it does not confer certification, and we don't claim its reports are a compliance program. For questions about Attack Surface Scan's own security and data handling, see the privacy policy and how scanning works, or ask us through support.
Will auditors accept these reports?
Auditors accept evidence that a control operated: dated, scoped, and covering the period. The check history and PDF exports are exactly that shape for external monitoring controls. Your auditor decides sufficiency, but continuous monitoring with an alert trail is stronger evidence than a single annual scan.
Which frameworks are covered?
The compliance views map findings to OWASP Top 10, CWE, PCI DSS 4.0, CIS Controls and GDPR, with a separate view of actively exploited vulnerabilities. The evidence pack is commonly filed against SOC 2 and ISO 27001 controls. Views and CSV exports are on every plan; the detail is in the documentation.
Does this replace a penetration test?
No. A penetration test is people attempting to break in at a point in time; Attack Surface Scan is continuous, read-only observation. SOC 2 and ISO 27001 programs typically want both; they answer different questions.
Start the record now.
Evidence for the audit period starts accumulating with your first scheduled check.
Start your 7-day trialNo card required to start. Cancel any time.