Compliance evidence

Agnostic Compliance Suite

3,000+ controls
30 frameworks
15 languages

Version 5.0

What it is

The auditor still drives. ACS does the manual labour.

Policy adequacy, staff interviews, governance maturity — those remain the auditor's job. ACS does the code-level and infrastructure-level evidence gathering at machine scale, so the auditor has complete, traceable evidence to review instead of sampling by hand.

Every finding distinguishes clearly between code-verifiable controls (where ACS gives a definitive PASS / FAIL with line-level evidence) and auditor-only controls (which ACS flags for review but cannot decide).

  • file:line:snippet traceability on every finding
  • Code-verifiable vs auditor-only, clearly marked
  • 30 frameworks in 7 modular packs
  • 15 languages scanned natively
  • Tamper-evident evidence chain (ECDSA signed)
  • Full audit-ready evidence export (SARIF, CycloneDX, PDF)
Capabilities

Not just code. The full compliance surface.

ACS scans code, infrastructure, cryptographic inventory, and integrates with your existing security tools and GRC platforms.

Code scanning NEW: 15 langs

Python, Java, Go, TypeScript, JavaScript, Rust, C#, C/C++, PHP, Ruby, Swift, Kotlin, Dart. AST-aware rules mapped to compliance controls, not just vulnerability patterns.

Infrastructure scanning NEW

Docker, Kubernetes, Terraform, GitHub Actions, YAML secrets. IaC rules for privilege escalation, host exposure, unpinned images, resource limits, and CI/CD pipeline security.

Cryptographic inventory (CBOM) NEW

12-language coverage. CycloneDX v1.7 output with post-quantum readiness classification. Identifies every algorithm in your codebase and scores it against NIST PQC standards.

Tool integration (28 adapters) NEW

14 input adapters: Snyk, Trivy, Semgrep, Checkmarx, Veracode, AWS Security Hub, Azure Defender, GCP SCC, and more. Reads SARIF, CycloneDX, SPDX, OCSF. No rip-and-replace.

GRC platform integration NEW

14 output adapters: Drata, Vanta, Secureframe, RSA Archer, ServiceNow GRC, OneTrust, AuditBoard, Hyperproof, JIRA, Linear, GitLab Issues, and more. Push evidence directly to your GRC workflow.

Evidence chain

Audit-grade integrity, not just scan results.

Every ACS evidence packet includes 6 clauses: control ID, control name, scope declaration, evidence type, evidence narrative, and relevance clause. Signed with ECDSA, chained with SHA-384, published to Sigstore Rekor.

What your auditor receives

  • PASS/FAIL with file:line:snippet — verifiable in minutes
  • Scope: code-level, infrastructure, or organisational
  • Evidence type: FULL, EXAMPLE, or MANUAL
  • Tamper-evident chain — any modification breaks the hash
  • Offline verification: acs verify-chain

Output formats

  • SARIF (standard security format)
  • CycloneDX v1.7 (CBOM native)
  • SPDX (supply chain)
  • OpenVEX (vulnerability exchange)
  • OCSF (open cybersecurity schema)
  • PDF, HTML (reporting)
  • JSON (native ACS format)
Framework packs

Seven packs. 30 frameworks. Mix to match your scope.

Start with the Community pack for free. Add Fundamental for your baseline. Layer industry-specific packs for AI, healthcare, US government, UK defence, or financial services.

Community

Free · 2 frameworks · 40 controls

OWASP Top 10 Web, OWASP API Top 10.

Fundamental

ACS Starter · 3 frameworks · 466 controls

OWASP ASVS v5, OWASP API Security, NIS 2, Infrastructure Security.

AI Governance

Pro add-on · 6 frameworks · 117+ controls

EU AI Act, OWASP Agentic AI, NIST AI RMF, ISO 42001, OWASP LLM Governance, OWASP LLM Top 10.

Healthcare

Pro add-on · 1 framework · 68 controls

HIPAA Security Rule.

US Gov / Defence

Pro add-on · 7 frameworks · 807+ controls

NIST 800-53 (Moderate + High), NIST 800-171 Rev 3, FedRAMP (Moderate + High), CMMC L1/L2/L3, NIST CSF 2.0, SOC 2 Type II.

FinTech / EU

Pro add-on · 4 frameworks · 474 controls

PCI DSS v4, ISO 27001:2022, DORA, GDPR.

UK Defence

Pro add-on · 2 frameworks · 52 controls

UK MoD Secure by Design, Australia DISP.

What changed

ACS v3 vs ACS v5 — at a glance.

ACS v5 is a fundamentally different tool from v3. Here's what shipped.

Capability ACS v3 ACS v5 (current)
Languages 5 (Python, Java, Go, TS, Rust) 15 (+ C#, C/C++, PHP, Ruby, Swift, Kotlin, Dart, JS, Caddyfile)
Frameworks 3 (ASVS, API Security, Agentic AI) 30 (+ EU AI Act, NIST AI RMF, ISO 42001, HIPAA, NIST 800-53, FedRAMP, CMMC, NIST CSF, PCI DSS, ISO 27001, DORA, GDPR, NIS 2, UK MoD SbD, and more)
Controls ~400 3,000+
Scope Code only Code + IaC + CBOM (Docker, K8s, Terraform, GitHub Actions, cryptographic inventory)
Input adapters None 14 (Snyk, Trivy, Semgrep, Checkmarx, Veracode, AWS SH, Azure Defender, GCP SCC, and more)
GRC output adapters None 14 (Drata, Vanta, Archer, ServiceNow GRC, JIRA, Linear, and more)
Evidence chain JSON output ECDSA-signed, SHA-384 chained, Sigstore Rekor published
Output formats JSON, PDF SARIF, CycloneDX, SPDX, OpenVEX, OCSF, JSON, PDF, HTML
CBOM / Post-quantum Not available 12-language CBOM with NIST PQC classification
Incremental scanning Full scan only Diff-scan engine with carry-forward evidence
FIPS 140-3 Not applicable OpenSSL 3.0.2 CMVP #4794
Roadmap

What's coming next.

We don't ship vapourware. The list below is what's funded and scheduled.

Pricing

Pricing to be confirmed.

ACS pricing is being finalised based on infrastructure costs. Get in touch for early access and pilot pricing.

Community
Free

ACS Community

OWASP Top 10 Web + API. 40 controls. Free for anyone.

Starter
Get in touch

ACS Starter

Fundamental pack. All 30 frameworks. 15 languages. CI integration + trend tracking.

Pro / Enterprise
Get in touch

ACS Pro

All packs. GRC integrations. Risk management. CBOM. Signed PDF reports. Custom rules. SSO.

ACS pricing depends on infrastructure and scanning volume. Get in touch for pilot pricing and early access.

Auditors, get in touch.

If you're conducting compliance audits and want to see what ACS does on a real codebase, we'll set up a session. No sales theatre.

Request a session →