Compliance Posture¶
Control-aligned posture indicators mapped to SOC 2, PCI, and HIPAA control families, derived from your security events. They are surfaced with trend analysis in the scheduled threat reports.
These are operational indicators to inform your own audit — not a certification or a substitute for a qualified assessor.
The posture view treats all three handled states — resolved, false positive, and dismissed — consistently: dismissing a threat removes its type from the open-findings tally, the same as resolving or marking it a false positive.
Retention and compliance fit¶
Retention is set by tier and maps onto the hot-vs-total split that compliance frameworks are written around. See the retention table in getting started for the per-tier values. In summary:
- Essential and above keep at least 90 days immediately searchable, meeting PCI DSS's three-month hot requirement.
- Advanced and above provide a full 12 months searchable, covering PCI DSS's 12-month total and typical SOC 2 audit periods.
- For HIPAA (6 years) or SOX (7 years) audit-log obligations, raise the
AuditRetentionDaysstack parameter at deploy (up to 36500 days) and chooseCOMPLIANCEObject-Lock mode if records must be immutable until retention elapses. The audit trail can be extended independently of the tier.