Skip to main content

Compliance mapping

AISafe tags every finding with a CWE identifier and an OWASP Top 10 category at detection. Compliance mapping projects those tags onto formal control catalogues, so a security or GRC team can pull audit-ready evidence out of work that has already run instead of commissioning a second exercise for the auditor.

The result is a control matrix: one row per control, with the findings that implicate it, how many remain outstanding, and the worst severity still open.

What this is not

This is findings-derived evidence, not a compliance attestation and not a certification. It says which controls the detected vulnerability classes touch. It does not say an organization satisfies a framework.

AISafe assesses what an application does. It cannot observe organizational, physical or procedural controls, and it never implies one from a clean application result. Every export names those control families explicitly rather than leaving a reader to assume coverage where none exists:

  • Governance and management-system controls
  • Physical security and facility access
  • Personnel screening and security awareness training
  • Key-management ceremonies and hardware security module operations
  • Log-retention infrastructure and clock synchronization
  • Vendor due diligence and third-party risk registers

Frameworks covered

FrameworkVersion cited
PCI DSSv4.0.1
SOC 2AICPA Trust Services Criteria 2017
ISO/IEC 270012022, Annex A
OWASP ASVSv4.0.3

OWASP Top 10 2021 and CWE are the detection tags underneath, and both appear in the report alongside the four catalogues.

Each mapping edge carries a confidence label and a citation to the section of the standard that supports it, so a reviewer can check a row rather than take it on trust. Both travel with every export.

The unmapped bucket

A finding whose CWE or OWASP category the catalogues cannot resolve is listed in its own bucket, with its identifiers. It is never dropped and never folded into a control it does not belong to.

That bucket is the honest part of the matrix. A report that quietly discards what it could not classify reads as better coverage than it has, which is the one failure mode an auditor cannot detect from the outside.

Where to get it

Per assessment. Every assessment includes its own compliance mapping, on every plan. It is a deliverable of the work the credits paid for, the same as the finding list and the PDF report. Open the assessment and export the mapping as JSON or CSV.

Per project. The project-level posture is the same mapping aggregated across every assessment in a project, over time, which is what shows an auditor a trend rather than a snapshot. It is part of Pro. Open the project's Compliance tab and export it as CSV or as a PDF.

The PDF is the document form: a cover naming the project and the frameworks, the severity distribution, a control table per framework, the unmapped bucket, and the list of controls outside AISafe's detection surface. It is rendered when you ask for it and reflects the findings as they stand at that moment. Regenerate it after triage rather than keeping an old copy.

Two people with different assessment access in the same project will export different documents, because both exports respect the same per-assessment permissions as the rest of the product.

The PDF prints a bounded number of finding identifiers per control. When a control has more, the CSV and JSON forms carry the complete list.

Attestation letters

An attestation letter is a dated, one-page statement that an assessment was performed: what was in scope, the methodology, a severity summary, and whether any critical finding remains open. It is available for every assessment that produced a report, on every plan.

Each letter carries a verification identifier. The identifier is derived with a server-side key, so it cannot be forged, and it resolves at a public URL that needs no AISafe account. An auditor who receives the letter can confirm it directly against AISafe rather than taking the customer's copy at face value.

Open the report and use Download PDF for the letter, or copy the verification link to send on. The link is separate from a shared report URL and does not expire with one.

Re-running an assessment produces a new completion, and a new completion mints a new identifier. The earlier one keeps resolving, so a letter already in an auditor's hands stays verifiable.