Skip to main content

Compliance Reporting

Generate audit-ready compliance reports and evidence packages for SOC 2, HIPAA, GDPR, PCI DSS, ISO 42001, and more — directly from Rivaro's detection and governance data.

Where to find it in the app​

Dashboard → Risk & Compliance → Framework Reports.

The Risk & Compliance tab has several views; the Framework Reports sub-tab is where you generate and download compliance reports. Other useful sub-tabs on the same page:

  • Compliance — live compliance scores per framework with trend indicators
  • Identity Reports — actor identity and authority-envelope reports for audit
  • Posture Trends / Risk Scores — risk posture over time

A Stage filter at the top of the Risk & Compliance tab lets you scope what's included: EXECUTION (runtime), DEPLOYMENT, or TRAINING (when feature-flagged).

To generate a report:

  1. Open Risk & Compliance → Framework Reports.
  2. Select a framework or industry-standard report from the catalog.
  3. Set the reporting period (date range or shortcut like "last quarter").
  4. Click Generate. Reports generate asynchronously — when ready, the row updates with a download link.
  5. Pick PDF, JSON, or CSV from the export menu on the completed report.

Why these reports​

Rivaro's enforcement and detection activity automatically generates compliance evidence. Every blocked request, redacted response, and governance action is recorded and tagged with the relevant compliance frameworks. The Framework Reports tab is the export interface — you don't manually assemble evidence; you pick a framework and Rivaro produces the report from data it already has.

Supported frameworks​

Framework reports​

FrameworkReportKey metrics
SOC 2SOC 2 Compliance ReportControl effectiveness (CC7.2/CC7.3), detection coverage, incident counts
HIPAAHIPAA Compliance ReportPHI detections, access events, audit log completeness
GDPRGDPR Compliance ReportPII processing events, data subject rights actions, cross-border transfers
PCI DSSPCI DSS Compliance ReportCardholder data detections, credential exposure events, access controls
CCPA / CPRACCPA/CPRA Compliance ReportCalifornia consumer data events, opt-out compliance
ISO 42001ISO 42001 Evidence PackageAI management system evidence, clause-by-clause coverage

Industry-standard reports​

ReportDescription
ISO 42001 Evidence PackageStructured evidence for GRC platforms (Vanta, Drata, Secureframe) — exports clause-by-clause coverage
Incident RegisterISO 27001 A.16 compliant incident register of all enforcement events
Detection Control EffectivenessSOC 2 CC7.2/CC7.3 — statistical analysis of detection coverage and action rates
Security Operations DashboardSIEM-style metrics export — detection rates, severity breakdown, trend analysis
Executive AI Risk SummaryHigh-level executive dashboard — overall AI risk posture, top risks, compliance scores

Report metrics​

Each framework report includes:

MetricDescription
Compliance scoreScore 0–100 for this framework
IncidentsNumber of policy violations detected in the reporting period
Total scansTotal requests scanned
Detection breakdownViolation counts by severity: critical, high, medium, low
TrendPercentage change in compliance score vs. previous period
Last generatedWhen this report was last generated

These same metrics drive the Compliance sub-tab's live posture view.

ISO 42001 Evidence Package​

The ISO 42001 evidence package maps Rivaro's enforcement activity to the standard's clauses — ready to upload directly to Vanta, Drata, or Secureframe. Generate it from the Framework Reports catalog with ISO 42001 Evidence Package.

ClauseEvidence Rivaro provides
Clause 8.2 — AI Risk AssessmentDetection taxonomy, risk domain coverage, violation history
Clause 8.3 — Human OversightQuarantine queue reviews, governance decision history, step-up approvals
Clause 8.5 — AI System DevelopmentAppContext configurations, allowed model lists, policy rule coverage
Clause 8.6 — Data for AI SystemsTraining stage detections, data classification events, connector policies
Clause 9.1 — Monitoring and MeasurementEnforcement metrics, detection rates, trend data
Annex B.4 — AI System SecurityPrompt injection detections, adversarial attack events, access control logs

Lifecycle stage filtering​

The Stage filter at the top of Risk & Compliance scopes reports to a specific lifecycle stage:

StageWhat's included
EXECUTION / RUNTIMEAll proxy enforcement — INGRESS + EGRESS detections (default for most reports)
TRAININGTraining data pipeline detections from connectors
DEPLOYMENTInfrastructure scan findings from discovery channels

Reports generated with the filter applied scope their evidence to that stage only — useful when you need a runtime-only HIPAA report or a training-only data-handling attestation.

Export formats​

FormatBest for
PDFHuman-readable audit evidence, auditor submissions
JSONAPI integration with GRC platforms (Vanta, Drata, Secureframe)
CSVSpreadsheet analysis, custom reporting

Choose the format from the export menu on a completed report row.

Live compliance posture​

In addition to the on-demand reports, the Compliance sub-tab of Risk & Compliance always shows your live posture:

  • Framework scores — compliance percentage per framework with trend indicators
  • Control coverage — which compliance controls have active detection coverage
  • Trend charts — compliance score over time per framework
  • Violation breakdown — severity distribution for the current period
  • Top violations — most frequent detection types impacting compliance

Use this for a daily glance at where you are. Use Framework Reports to produce the audit artifact.

Next steps​