FEATURE_COMPLIANCE_REPORTS). Its
pages are hidden entirely for a workspace without it. See
Settings & licensing.
The five surfaces
Compliance lives at/compliance and is organised as five pages.
/compliance on its own redirects to Frameworks.
What honest evidence means here
A compliance product that quietly implies coverage it does not have is worse than no compliance product. Three rules are built into the report builder, and it is worth knowing them before you show a report to anybody.Unassessed controls are named, not implied
Unassessed controls are named, not implied
Blindsight assesses eight finding types. A control a standard
expects that no Blindsight detection maps to is reported as not
assessed. It is never silently counted as passing, and a report
that covers only part of a framework says so on its face.
Applicability is carried into every report
Applicability is carried into every report
Almost none of these frameworks bind every organisation
unconditionally. SOC 2 covers only the trust services categories
your engagement selected. ISO/IEC 27001 Annex A is a reference set
governed by your Statement of Applicability. HIPAA binds you only
with respect to ePHI. The EU AI Act’s duties turn on
classification and on whether you are the provider or the deployer.
Every report carries the applicability conditions for its
framework, so nobody reads a control listing as a duty you
necessarily owe.
A detection that was prevented is not a breach
A detection that was prevented is not a breach
Exposures the platform masked or blocked are counted separately
from exposures that were not prevented. A blocked disclosure is a
non-disclosure. Whether an unprevented exposure amounts to a
notifiable personal data breach stays the controller’s assessment,
and the report says so rather than deciding for you.
Declaring your scope
Two declarations shape everything Compliance produces. Both live under Frameworks and both need thecompliance.manage permission.
1
Select your frameworks
Pick the standards your organisation actually reports against.
The selection drives the Frameworks table, seeds report defaults,
and is what the Getting Started walkthrough checks against instead
of a self-attested checkbox.
2
Declare whether you process ePHI
Separate from the framework selection, because they answer
different questions. A workspace that has not declared ePHI scope
gets a HIPAA report saying it was never declared in scope, rather
than one inventing safeguards it does not owe.
Where the evidence comes from
See also
Frameworks
The six supported standards and what each mapping does and does not claim.
Data posture
Severity rollups, the attention queue, and the activity timeline.
Audit trail
Tamper-evident logging, filtering, export, and SIEM delivery.
Reports
Generating documents, depths, formats, and templates.

