Compliance Radar maps your system evidence against GDPR, ISO 27001, HIPAA, PCI-DSS, or custom frameworks — using a two-phase AI pipeline that never skips a mandatory control.
One row per system, one click to run a full audit.
| System | Regulation | Score | Status | Last Audit |
|---|---|---|---|---|
| Production DB | GDPR | 91 | ✓ Compliant | 1h ago |
| Payment Gateway | PCI-DSS | 0 | ✗ Gate Failed | 3h ago |
| Auth Service | ISO 27001 | 78 | ✓ Compliant | Yesterday |
| HR System | HIPAA | 55 | ⚠ Non-Compliant | 2d ago |
Must-Have controls block an item from passing regardless of its weighted score.
The AI tells you exactly which controls it could not verify — not a vague "failed" verdict.
Compliance Radar ships with five pre-configured frameworks. Custom frameworks let you define your own rules from scratch.
Data protection, right to erasure, consent management, and data breach notification requirements under EU regulation.
Information security management system controls covering risk assessment, access management, and cryptography policies.
Protected health information safeguards including PHI encryption, access controls, and audit trail requirements.
Payment card industry standards: cardholder data environment, network segmentation, and encryption at rest requirements.
Define your own Must-Have gates, weighted categories, and passing threshold to match internal security policies or bespoke regulatory requirements.
No — Compliance Radar evaluates pasted evidence. You paste config exports, policy documents, penetration test summaries, or any text-based evidence into the sandbox, and the AI evaluates it against your chosen framework. There is no live agent or API connection to your infrastructure.
Very specific. Write gates as verifiable statements the AI can confirm or refute: "AES-256 encryption at rest confirmed" rather than "encryption enabled". Vague gates produce vague verdicts. The more precise the gate, the more actionable the missing-gate report becomes.
No — Compliance Radar is an AI-assisted assessment tool, not a certified audit. It helps your team identify control gaps and prepare evidence before a formal review. Always validate findings with a qualified compliance professional before regulatory submission.
Compliance Radar is available in TotalApp's Security module.