Compliance Reports
Export control-mapped audit evidence for SOC 2 and HIPAA — audit data, DLP findings, and guardrail enforcement summaries in formats ready for your compliance team or auditors. These are evidence packages you provide to your auditor, not third-party attestations or certifications issued by Clevername.
Supported frameworks
What reports include
Each compliance report compiles data from across the platform:
- Audit summary — Total actions logged, hash chain verification status, retention compliance.
- DLP findings — Content scanning results grouped by scanner type and action taken.
- Guardrail enforcement — Tool drift blocks, model access denials, budget cap enforcements.
- Emergency control log — Emergency actions with SignedApproval receipts or audited SOAR-key execution records.
- Agent inventory — Active agents, their trust tiers, guardrail profiles, and review approval status.
Report formats
Reports can be exported as PDF (formatted for auditors), CSV (raw data for analysis), or JSON (machine-readable for integration with GRC tools).
Navigate to Compliance Reports
Go to Security → Compliance Reports in the dashboard sidebar.
Select a framework
Choose the compliance framework you need: SOC 2 or HIPAA. Each framework maps to specific platform controls and generates the appropriate control-mapped evidence structure for your auditor.
Set the reporting period
Select the date range for the report. Common periods are quarterly (for SOC 2) or monthly (for ongoing compliance monitoring). The report will include all audit data within this window.
Generate and review
Click Generate Report. The system compiles data from audit trails, DLP events, guardrail enforcement logs, and the agent inventory. Preview the report inline before exporting.
Export the report
Click Export and choose your format: PDF for auditors, CSV for analysis, or JSON for GRC tool integration. The export includes all supporting data and hash chain verification.