Konfirmity

// findings to evidence

Compliance falls out of the security work

This is the join. Everything the seven layers surface becomes work, and the work is what an auditor eventually reads.

// the thesis

Compliance-first tools build the artefact directly

If your platform starts at the framework, its job is to produce a document that satisfies a control. The security work is something you are trusted to have done elsewhere, and the evidence is a description of it.

We start at the other end. The seven coverage layers surface real broken things, fixing them generates a record, and that record is what the auditor reads. The compliance artefact is a by-product of work that had to happen anyway.

// the chain

Finding, task, control, evidence

Four steps, each one mechanical. Nothing in this chain requires somebody to remember to write something down.

  1. A findingOne of the seven layers

    A misconfigured cloud asset, a repository carrying a vulnerability, a non-compliant vendor, a device at critical severity, an identity acting out of scope.

  2. A taskPlatform

    The finding becomes work with an owner, a due date and an SLA category. Overdue, needs-attention and missing-SLA are all tracked distinctly, so nothing rots quietly.

  3. A controlFramework mapping

    The task is attached to the controls it satisfies, across every applicable framework at once rather than per-framework duplicated effort.

  4. EvidenceAudit

    Completing the task attaches the artefact to the control. The auditor reads the thing that was actually produced, with its date and its owner.

// frameworks

Run several at once, do the work once

Controls overlap heavily between frameworks. Because the chain starts at the finding rather than at the framework, one piece of remediation satisfies every control it touches.

  • SOC 2, ISO 27001, HIPAA, GDPR, PCI DSS and MAS TRM are all supported — read the framework guides
  • Adding a second framework re-uses the evidence the first one produced instead of restarting the programme.
  • Task metrics are reported per framework — overdue, needing attention, needing an SLA, open and completed — so you can see where a specific certification actually stands.

// showing your work

Where the evidence ends up

Producing evidence is only half of it. Somebody outside your company usually has to see some of it, and that is its own problem.

  • Auditors get their own read-only role rather than a shared login and a folder of exports, over evidence produced by the seven coverage layers
  • Your Trust Center publishes what you choose to publish, and gates the rest behind an NDA that is versioned and append-only, so every acceptance is pinned to the exact text that was signed.
  • Visitors requesting a document confirm their identity by email before the request is recorded at all.
  • Your own employees raise and track service requests through an employee portal, so security work reaching them does not become an email thread.
  • Vendors answer questionnaires in their own portal rather than by attachment.

// the difference

Why this ordering is not cosmetic

Starting at compliance gets you a certificate and an unknown security posture. Starting at security gets you both, in that order, and the certificate is the easier half.

// questions this answers

How compliance evidence is produced, answered directly

How does Konfirmity generate audit evidence?

As a by-product of security work. A finding from one of the seven coverage layers becomes a task with an owner and an SLA, the task attaches to every control it satisfies, and completing it attaches the artefact to those controls with its date and owner intact.

Which frameworks are supported?

SOC 2, ISO 27001, HIPAA, GDPR, PCI DSS and MAS TRM, each with its own guide. Because the chain starts at the finding rather than at the framework, adding a second framework re-uses the evidence the first one produced.

How do auditors and customers get access?

Auditors get their own read-only role rather than a shared login. External parties use your Trust Center, where gated documents sit behind a versioned, append-only NDA and every acceptance is pinned to the exact text that was signed.

Want to see this one live?

Book 30 minutes and we will walk through “Compliance falls out of the security work” in the actual platform, using your environment as the example.

Book a demo