Compliance Reporting
Generate audit-ready compliance reports and evidence packages for SOC 2, HIPAA, GDPR, PCI DSS, ISO 42001, and more — directly from Rivaro's detection and governance data.
Where to find it in the app
Dashboard → Risk & Compliance → Framework Reports.
The Risk & Compliance tab has several views; the Framework Reports sub-tab is where you generate and download compliance reports. Other useful sub-tabs on the same page:
- Compliance — live compliance scores per framework with trend indicators
- Identity Reports — actor identity and authority-envelope reports for audit
- Posture Trends / Risk Scores — risk posture over time
A Stage filter at the top of the Risk & Compliance tab lets you scope what's included: EXECUTION (runtime), DEPLOYMENT, or TRAINING (when feature-flagged).
To generate a report:
- Open Risk & Compliance → Framework Reports.
- Select a framework or industry-standard report from the catalog.
- Set the reporting period (date range or shortcut like "last quarter").
- Click Generate. Reports generate asynchronously — when ready, the row updates with a download link.
- Pick PDF, JSON, or CSV from the export menu on the completed report.
Why these reports
Rivaro's enforcement and detection activity automatically generates compliance evidence. Every blocked request, redacted response, and governance action is recorded and tagged with the relevant compliance frameworks. The Framework Reports tab is the export interface — you don't manually assemble evidence; you pick a framework and Rivaro produces the report from data it already has.
Supported frameworks
Framework reports
| Framework | Report | Key metrics |
|---|---|---|
| SOC 2 | SOC 2 Compliance Report | Control effectiveness (CC7.2/CC7.3), detection coverage, incident counts |
| HIPAA | HIPAA Compliance Report | PHI detections, access events, audit log completeness |
| GDPR | GDPR Compliance Report | PII processing events, data subject rights actions, cross-border transfers |
| PCI DSS | PCI DSS Compliance Report | Cardholder data detections, credential exposure events, access controls |
| CCPA / CPRA | CCPA/CPRA Compliance Report | California consumer data events, opt-out compliance |
| ISO 42001 | ISO 42001 Evidence Package | AI management system evidence, clause-by-clause coverage |
Industry-standard reports
| Report | Description |
|---|---|
| ISO 42001 Evidence Package | Structured evidence for GRC platforms (Vanta, Drata, Secureframe) — exports clause-by-clause coverage |
| Incident Register | ISO 27001 A.16 compliant incident register of all enforcement events |
| Detection Control Effectiveness | SOC 2 CC7.2/CC7.3 — statistical analysis of detection coverage and action rates |
| Security Operations Dashboard | SIEM-style metrics export — detection rates, severity breakdown, trend analysis |
| Executive AI Risk Summary | High-level executive dashboard — overall AI risk posture, top risks, compliance scores |
Report metrics
Each framework report includes:
| Metric | Description |
|---|---|
| Compliance score | Score 0–100 for this framework |
| Incidents | Number of policy violations detected in the reporting period |
| Total scans | Total requests scanned |
| Detection breakdown | Violation counts by severity: critical, high, medium, low |
| Trend | Percentage change in compliance score vs. previous period |
| Last generated | When this report was last generated |
These same metrics drive the Compliance sub-tab's live posture view.
ISO 42001 Evidence Package
The ISO 42001 evidence package maps Rivaro's enforcement activity to the standard's clauses — ready to upload directly to Vanta, Drata, or Secureframe. Generate it from the Framework Reports catalog with ISO 42001 Evidence Package.
| Clause | Evidence Rivaro provides |
|---|---|
| Clause 8.2 — AI Risk Assessment | Detection taxonomy, risk domain coverage, violation history |
| Clause 8.3 — Human Oversight | Quarantine queue reviews, governance decision history, step-up approvals |
| Clause 8.5 — AI System Development | AppContext configurations, allowed model lists, policy rule coverage |
| Clause 8.6 — Data for AI Systems | Training stage detections, data classification events, connector policies |
| Clause 9.1 — Monitoring and Measurement | Enforcement metrics, detection rates, trend data |
| Annex B.4 — AI System Security | Prompt injection detections, adversarial attack events, access control logs |
Lifecycle stage filtering
The Stage filter at the top of Risk & Compliance scopes reports to a specific lifecycle stage:
| Stage | What's included |
|---|---|
| EXECUTION / RUNTIME | All proxy enforcement — INGRESS + EGRESS detections (default for most reports) |
| TRAINING | Training data pipeline detections from connectors |
| DEPLOYMENT | Infrastructure scan findings from discovery channels |
Reports generated with the filter applied scope their evidence to that stage only — useful when you need a runtime-only HIPAA report or a training-only data-handling attestation.
Export formats
| Format | Best for |
|---|---|
| Human-readable audit evidence, auditor submissions | |
| JSON | API integration with GRC platforms (Vanta, Drata, Secureframe) |
| CSV | Spreadsheet analysis, custom reporting |
Choose the format from the export menu on a completed report row.
Live compliance posture
In addition to the on-demand reports, the Compliance sub-tab of Risk & Compliance always shows your live posture:
- Framework scores — compliance percentage per framework with trend indicators
- Control coverage — which compliance controls have active detection coverage
- Trend charts — compliance score over time per framework
- Violation breakdown — severity distribution for the current period
- Top violations — most frequent detection types impacting compliance
Use this for a daily glance at where you are. Use Framework Reports to produce the audit artifact.
Next steps
- Policy Templates — Apply industry-specific enforcement defaults
- Understanding Detections — What Rivaro detects that feeds compliance reports
- Actor Governance — Governance history used in human oversight evidence
- Incident Management — Incidents feeding the ISO 27001 register