🛡️ Security · MatrixEngine

AI Compliance Audits That Flag
Every Missing Control

Compliance Radar maps your system evidence against GDPR, ISO 27001, HIPAA, PCI-DSS, or custom frameworks — using a two-phase AI pipeline that never skips a mandatory control.

Start auditing free See all features
5
Frameworks
2-Phase
Pipeline
0
Manual Checklists
Real-Time
Remediation
Compliance Table

Track Every System Against Every Framework

One row per system, one click to run a full audit.

  • Add items with name + regulation type
  • Score badge + Compliant/Non-Compliant status at a glance
  • Timestamps track when each audit was last run
  • Re-audit after remediation — result overwrites instantly
Open Compliance Radar
totalapp.app/security/compliance-radar
🛡️ Compliance Radar 4 systems · 2 compliant · 2 remediation needed
System Regulation Score Status Last Audit
Production DB GDPR 91 ✓ Compliant 1h ago
Payment Gateway PCI-DSS 0 ✗ Gate Failed 3h ago
Auth Service ISO 27001 78 ✓ Compliant Yesterday
HR System HIPAA 55 ⚠ Non-Compliant 2d ago
Evaluation Rules

Define Hard Gates That Cannot Be Waived

Must-Have controls block an item from passing regardless of its weighted score.

  • Default categories: Veri Güvenliği (50%), Erişim Kontrolleri (30%), Loglama Altyapısı (20%)
  • Threshold default 70 — raise to 80+ for regulatory submissions
  • Must-Have examples: "AES-256 encryption at rest confirmed", "MFA enforced for admin accounts"
  • Nice-to-Have: "SOC 2 Type II report available"
Configure Rules
totalapp.app/security/compliance-radar/rules
Evaluation Rules
Pass Threshold 70
Weighted Categories
Veri Güvenliği
50%
Erişim Kontrolleri
30%
Loglama Altyapısı
20%
Must-Have Gates
AES-256 encryption at rest confirmed MFA enforced for admin accounts
Nice-to-Have
SOC 2 Type II report available
Remediation Report

Missing Gates Become Your Remediation Checklist

The AI tells you exactly which controls it could not verify — not a vague "failed" verdict.

  • Red banner shows failed gate with score forced to 0
  • Missing gates list: each absent control named precisely
  • Executive summary paragraph in plain language
  • Update sandbox with new evidence → re-analyze to verify fixes
View Remediation Report
totalapp.app/security/compliance-radar/report
🚨 ✗ NON-COMPLIANT — PCI-DSS Audit Score: 0 / 100
Missing Must-Have Gates
No evidence of AES-256 encryption at rest found in provided configuration. TLS in transit confirmed but storage encryption absent.
MFA enforcement for admin accounts not confirmed. Admin portal access policy documentation missing from sandbox.
Executive Summary
The Payment Gateway fails PCI-DSS mandatory controls. Two hard gates were not satisfied: storage encryption and MFA enforcement. Remediate these controls and re-submit evidence to unlock scoring.
Evidence Sandbox
Paste updated config exports, policy docs, or pen test summaries here then re-analyze…

Supported Regulation Frameworks

Compliance Radar ships with five pre-configured frameworks. Custom frameworks let you define your own rules from scratch.

🇪🇺

GDPR

Data protection, right to erasure, consent management, and data breach notification requirements under EU regulation.

🔐

ISO 27001

Information security management system controls covering risk assessment, access management, and cryptography policies.

🏥

HIPAA

Protected health information safeguards including PHI encryption, access controls, and audit trail requirements.

💳

PCI-DSS

Payment card industry standards: cardholder data environment, network segmentation, and encryption at rest requirements.

⚙️

Custom

Define your own Must-Have gates, weighted categories, and passing threshold to match internal security policies or bespoke regulatory requirements.

Frequently Asked Questions

Does Compliance Radar connect to live systems?

No — Compliance Radar evaluates pasted evidence. You paste config exports, policy documents, penetration test summaries, or any text-based evidence into the sandbox, and the AI evaluates it against your chosen framework. There is no live agent or API connection to your infrastructure.

How specific should Must-Have gates be?

Very specific. Write gates as verifiable statements the AI can confirm or refute: "AES-256 encryption at rest confirmed" rather than "encryption enabled". Vague gates produce vague verdicts. The more precise the gate, the more actionable the missing-gate report becomes.

Is this a certified audit?

No — Compliance Radar is an AI-assisted assessment tool, not a certified audit. It helps your team identify control gaps and prepare evidence before a formal review. Always validate findings with a qualified compliance professional before regulatory submission.

Automate Your Compliance Audit Workflow

Compliance Radar is available in TotalApp's Security module.