Skip to main content

Compliance Reporting

Generate audit-ready compliance reports and evidence packages for SOC 2, HIPAA, GDPR, PCI DSS, ISO 42001, and more — directly from Rivaro's detection and governance data.

Overview

Rivaro's enforcement and detection activity automatically generates compliance evidence. Every blocked request, redacted response, and governance action is recorded and tagged with the relevant compliance frameworks — ready to export for audits or GRC platforms.

Supported Frameworks

Framework reports

FrameworkReportKey metrics
SOC 2SOC 2 Compliance ReportControl effectiveness (CC7.2/CC7.3), detection coverage, incident counts
HIPAAHIPAA Compliance ReportPHI detections, access events, audit log completeness
GDPRGDPR Compliance ReportPII processing events, data subject rights actions, cross-border transfers
PCI DSSPCI DSS Compliance ReportCardholder data detections, credential exposure events, access controls
CCPA / CPRACCPA/CPRA Compliance ReportCalifornia consumer data events, opt-out compliance
ISO 42001ISO 42001 Evidence PackageAI management system evidence, clause-by-clause coverage

Industry standard reports

ReportDescription
ISO 42001 Evidence PackageStructured evidence for GRC platforms (Vanta, Drata, Secureframe) — exports clause-by-clause coverage
Incident RegisterISO 27001 A.16 compliant incident register of all enforcement events
Detection Control EffectivenessSOC 2 CC7.2/CC7.3 — statistical analysis of detection coverage and action rates
Security Operations DashboardSIEM-style metrics export — detection rates, severity breakdown, trend analysis
Executive AI Risk SummaryHigh-level executive dashboard — overall AI risk posture, top risks, compliance scores

Report Metrics

Each framework report includes:

MetricDescription
percentageCompliance score (0–100) for this framework
incidentsNumber of policy violations detected in the reporting period
totalScansTotal requests scanned
detectionBreakdownViolation counts by severity: critical, high, medium, low
trendPercentage change in compliance score vs. previous period
lastGeneratedWhen this report was last generated

ISO 42001 Evidence Package

The ISO 42001 evidence package maps Rivaro's enforcement activity to the standard's clauses — ready to upload directly to Vanta, Drata, or Secureframe.

ClauseEvidence Rivaro provides
Clause 8.2 — AI Risk AssessmentDetection taxonomy, risk domain coverage, violation history
Clause 8.3 — Human OversightQuarantine queue reviews, governance decision history, step-up approvals
Clause 8.5 — AI System DevelopmentAppContext configurations, allowed model lists, policy rule coverage
Clause 8.6 — Data for AI SystemsTraining stage detections, data classification events, connector policies
Clause 9.1 — Monitoring and MeasurementEnforcement metrics, detection rates, trend data
Annex B.4 — AI System SecurityPrompt injection detections, adversarial attack events, access control logs

Lifecycle Stage Filtering

Reports can be scoped to a specific lifecycle stage:

StageWhat's included
EXECUTION / RUNTIMEAll proxy enforcement — INGRESS + EGRESS detections (default for most reports)
TRAININGTraining data pipeline detections from connectors
DEPLOYMENTInfrastructure scan findings from discovery channels

Generating Reports

From the dashboard

Go to Compliance in the navigation. Select your framework, set the reporting period, and click Generate. Reports generate asynchronously — you'll be notified when ready.

Via API

# Check compliance status across all frameworks
GET /api/compliance/status?lifecycleStage=EXECUTION

# List available reports
GET /api/compliance/reports/available

# Generate a framework report
POST /api/compliance/reports/generate
{
"framework": "SOC2",
"startDate": "2026-01-01",
"endDate": "2026-03-31"
}

# Generate an industry standard report
POST /api/compliance/reports/industry/{reportId}/generate

# Export ISO 42001 evidence package
GET /api/compliance/iso42001/evidence?format=json

Export Formats

FormatBest for
PDFHuman-readable audit evidence, auditor submissions
JSONAPI integration with GRC platforms (Vanta, Drata, Secureframe)
CSVSpreadsheet analysis, custom reporting

Compliance Dashboard

The Compliance dashboard provides a live view of your compliance posture:

  • Framework scores — compliance percentage per framework with trend indicators
  • Control coverage — which compliance controls have active detection coverage
  • Trend charts — compliance score over time per framework
  • Violation breakdown — severity distribution for the current period
  • Top violations — most frequent detection types impacting compliance

Next steps