Compliance you can open, down to the evidence.
CCM assesses every application against your master framework from the evidence your tools already hold, derives compliance with the other frameworks you report on, and turns each failing control into a gap that a named person confirms, plans and closes.
- pillars, from inventory to report
- 4
- agents, each with a stated limit
- 5
- reports, in four formats
- 4
- stages in a gap's lifecycle
- 6
Four pillars, in the order the work runs.
The platform's navigation is grouped the same way, so what is described here is where it is found.
- 01Prerequisites
Every application in an inventory with an owner, a criticality and the business service it supports. One master framework, chosen once, that everything is assessed against.
Application inventoryCriticality C1 to C3Master frameworkRoles - 02Frameworks and integrations
Other frameworks are mapped onto the master, control by control, so compliance with them is derived rather than assessed twice. Tools are connected, and what they send is minimised before it is admitted as evidence.
Framework mappingConnected toolsFields kept, hashed or dropped - 03Continuous monitoring
Control tests run on a schedule against the tools' records. Vendors' SOC 2 reports are read and mapped. Each application is assessed every month and on demand, all controls, every time.
Control testsSOC 2 reportsMonthly and on-demand assessments - 04Reporting and gap register
A control that fails is a gap: confirmed by a person, scored for risk, given an SLA, planned, treated and verified by the next assessment. Reports are built from the record when they are opened.
Gap lifecycleRisk acceptanceFour reports, four formats
Evidence from the tools you already run.
CCM does not scan. It reads what your security tools already know about each application, keeps only the fields a control test needs, and says which tool every result came from.
- Qualys SSL Labs
- Snyk
- Aqua Security
- Azure DevOps
- Auth0
Cloudflare WAF
AWS WAF- Cisco Meraki
- Okta
- Microsoft Sentinel
Splunk EnterpriseTenable.io
- GitHub
SentinelOne- Palo Alto Panorama
Zscaler
Five agents. Each does one job and says what it will not do.
An agent here is a bounded piece of work with named tools. Two of them call no model at all, and every run of every one can be played back.
Scores one application against every control of the master framework from the evidence on record.
Calls no model and changes no evidence. A control with no evidence is not compliant.Reads a vendor's SOC 2 Type II report and maps the controls its auditor tested onto the master framework.
Never marks a control met without a tested control in the report to rest on.Maps the master framework onto another framework, control by control.
Assesses nothing. It only says which controls stand for which requirements.Drafts a remediation plan for one gap from its record: the control, the evidence, what the control tests found and the mapped clauses.
Never approves its own plan and never invents a source: citations it was not given are dropped.Answers questions about the estate from the record, with the figures the pages show.
Changes nothing unless the person asking confirms it in words.Reading a SOC 2 report, matching two frameworks and drafting a plan use a model. Scoring and testing do not.
A drafted plan cites the record items it was given on every step. A citation the model was not given is dropped.
Tool calls, reasoning, what was written and where a person decided, with tokens and cost where a model was used.
The agents do the reading. People take the decisions.
What runs on its own, what waits for a named person, and what is never automated are fixed by the platform, not by a prompt.
Viewer, assessor, compliance lead and administrator. Reading needs a session; changing a record needs a role that allows it.
Every move of a gap through its lifecycle is an entry with a date, a name and a role. Nothing is edited after the fact.
On sync, each field from a tool is kept, hashed or dropped by rule before anything is admitted as evidence, and the sync shows which.
Every agent run has a transcript: what was read, what the model reasoned, what was written, with tokens and cost where a model was used.