Skip to main content

Compliance Reports

Export control-mapped audit evidence for SOC 2, ISO 27001, GDPR, and HIPAA — audit data, DLP findings, and guardrail enforcement summaries in formats ready for your compliance team or auditors. These are evidence packages you provide to your auditor, not third-party attestations or certifications issued by Clevername.

Key Concepts

Two report surfaces

Clevername produces compliance evidence from two dashboard pages:

  • Framework reportSecurity → Compliance (/dashboard/security/compliance). Pick SOC 2, ISO 27001, GDPR, or HIPAA and a date range; the report maps platform controls to the framework and downloads as PDF.
  • Evidence data packagesEnterprise → Compliance (/dashboard/enterprise/compliance). Raw evidence exports by report type, as CSV or JSON.

Supported frameworks (framework report)

SOC 2Trust service criteria control mapping: security, availability, processing integrity, confidentiality, privacy.
ISO 27001Annex A control mapping for the information security management system.
GDPRArticle-level mapping for data protection, access, and retention controls.
HIPAATechnical safeguards control mapping: access controls, audit controls, transmission security, integrity. Cloud SaaS is not BAA-covered by default; dedicated HIPAA deployment is handled by request.

Evidence data package types

The Enterprise → Compliance page generates one package per report type:

  • Access control (access_control) — Members, roles, and access review evidence.
  • Audit summary (audit_summary) — Total actions logged over the period.
  • Change management (change_management) — Configuration and policy changes.
  • DLP events (dlp_events) — Content scanning findings and the action taken.
  • Hash chain verification (hash_chain_verify) — Audit-chain integrity result for the period.
  • Encryption inventory (encryption_inventory) — Where and how stored data and keys are encrypted.
  • User activity (user_activity) — Per-user activity summary.
  • Agent approval history (agent_approvals) — Agent Review submissions and decisions.
  • Human oversight records (human_oversight) — Every high-risk (A4) action that required SignedApproval, with the approver, decision, tool, Ed25519 receipt id, signing key, fingerprint and an offline re-verification status, for EU AI Act Art. 14 and NIST AI RMF human-oversight evidence; the receipt can be re-verified with the SignedApproval public key.

Report formats

The framework report exports as PDF (formatted for auditors). Evidence data packages export as CSV (raw data for analysis) or JSON(machine-readable for GRC tools). Both are generated on demand from the dashboard.

Compliance reports page showing framework selection, date range picker, and a generated SOC 2 report preview with summary statistics
Select a framework, set the date range, and generate a report. Preview it inline before exporting.
Step-by-Step Guide
1

Navigate to Compliance Reports

Go to Security → Compliance for the framework report, or Enterprise → Compliance for evidence data packages.

Dashboard sidebar with Security section expanded, Compliance highlighted
Find the framework report under Security → Compliance and evidence packages under Enterprise → Compliance.
2

Select a framework

On the framework report page, choose SOC 2, ISO 27001, GDPR, or HIPAA. Each framework maps to specific platform controls and generates the appropriate control-mapped evidence structure for your auditor. On the evidence page, pick a report type instead.

3

Set the reporting period

Select the date range for the report. Common periods are quarterly (for SOC 2) or monthly (for ongoing compliance monitoring). The report will include all audit data within this window.

Note
Reports can only cover data within your audit retention period, which is set by plan (7 days on Free, 30 on Pro, 365 on Team, unlimited on Enterprise) or by an organization-level override. The guardrail profile does not change retention.
4

Generate and review

Click Generate Report. The system compiles data from audit trails, DLP events, guardrail enforcement logs, and the agent inventory. Preview the report inline before exporting.

Generated compliance report showing summary statistics, control coverage table, and finding details
Review the generated report inline. Each section maps to specific compliance controls.
5

Export the report

Download the framework report as PDF, or download an evidence package as CSV or JSON. Evidence packages include the supporting rows; the hash-chain package carries the verification result.