Compliance Reports
Export control-mapped audit evidence for SOC 2, ISO 27001, GDPR, and HIPAA — audit data, DLP findings, and guardrail enforcement summaries in formats ready for your compliance team or auditors. These are evidence packages you provide to your auditor, not third-party attestations or certifications issued by Clevername.
Two report surfaces
Clevername produces compliance evidence from two dashboard pages:
- Framework report — Security → Compliance (
/dashboard/security/compliance). Pick SOC 2, ISO 27001, GDPR, or HIPAA and a date range; the report maps platform controls to the framework and downloads as PDF. - Evidence data packages — Enterprise → Compliance (
/dashboard/enterprise/compliance). Raw evidence exports by report type, as CSV or JSON.
Supported frameworks (framework report)
Evidence data package types
The Enterprise → Compliance page generates one package per report type:
- Access control (
access_control) — Members, roles, and access review evidence. - Audit summary (
audit_summary) — Total actions logged over the period. - Change management (
change_management) — Configuration and policy changes. - DLP events (
dlp_events) — Content scanning findings and the action taken. - Hash chain verification (
hash_chain_verify) — Audit-chain integrity result for the period. - Encryption inventory (
encryption_inventory) — Where and how stored data and keys are encrypted. - User activity (
user_activity) — Per-user activity summary. - Agent approval history (
agent_approvals) — Agent Review submissions and decisions. - Human oversight records (
human_oversight) — Every high-risk (A4) action that required SignedApproval, with the approver, decision, tool, Ed25519 receipt id, signing key, fingerprint and an offline re-verification status, for EU AI Act Art. 14 and NIST AI RMF human-oversight evidence; the receipt can be re-verified with the SignedApproval public key.
Report formats
The framework report exports as PDF (formatted for auditors). Evidence data packages export as CSV (raw data for analysis) or JSON(machine-readable for GRC tools). Both are generated on demand from the dashboard.
Navigate to Compliance Reports
Go to Security → Compliance for the framework report, or Enterprise → Compliance for evidence data packages.
Select a framework
On the framework report page, choose SOC 2, ISO 27001, GDPR, or HIPAA. Each framework maps to specific platform controls and generates the appropriate control-mapped evidence structure for your auditor. On the evidence page, pick a report type instead.
Set the reporting period
Select the date range for the report. Common periods are quarterly (for SOC 2) or monthly (for ongoing compliance monitoring). The report will include all audit data within this window.
Generate and review
Click Generate Report. The system compiles data from audit trails, DLP events, guardrail enforcement logs, and the agent inventory. Preview the report inline before exporting.
Export the report
Download the framework report as PDF, or download an evidence package as CSV or JSON. Evidence packages include the supporting rows; the hash-chain package carries the verification result.