Compliance evidence

Evidence for SOC 2, ISO 27001 and SEBI CSCRF — between VAPTs.

Each verified fix is mapped to the controls it is evidence for, so a control owner can cite it in an audit or a customer's security questionnaire — with the line it does not cross written beside it.

ProvenClosed produces evidence, not an assessment. A check observes one resource at one moment; a control is an organisational requirement that no scanner can decide. Nothing ProvenClosed produces says a control has been met.

Which controls

Every check, and the controls it is evidence for.

The same mapping appears on every finding, in exports and inside every signed certificate.

What ProvenClosed checksSOC 2ISO/IEC 27001:2022SEBI CSCRF
Exposed services — databases, remote access, admin portsCC6.6A.8.20PR.AA, PR.IP, DE.CM.S5
AI model servers and consoles answering without authenticationProCC6.1, CC6.6A.8.20PR.AA, PR.IP, DE.CM.S5
Known vulnerabilities, from 100 reviewed templatesCC7.2A.8.8PR.IP, DE.CM.S5
Dangling DNS — a name pointing at something nobody owns any moreCC6.6A.5.7, A.8.9ID.AM, DE.CM.S5
TLS — expired, expiring, untrusted or mismatched certificates, old protocolsCC6.7A.8.24PR.DS
Missing browser security headersCC7.1A.8.9PR.IP, DE.CM
AWS — public bucketsBusiness & ProCC6.1, CC6.6A.5.23PR.AA, PR.DS
AWS — world-open security groups, public databasesBusiness & ProCC6.6A.8.20, A.5.23PR.AA, PR.IP
AWS — IAM users without MFA, stale access keysBusiness & ProCC6.1A.5.17PR.AA

In our words

What each control is about.

Written here rather than quoted, so the mapping can be argued with by somebody who does not have the standard open.

ISO/IEC 27001:2022, Annex A

A.5.7
Threat intelligence: knowing what is exposed and what is being attempted against it.
A.5.17
Authentication information: how credentials are issued, held and retired.
A.5.23
Cloud services: the security of what is configured inside them.
A.8.8
Technical vulnerabilities: they are found, judged and dealt with.
A.8.9
Configuration management: systems and software are configured as intended and stay that way.
A.8.20
Network security: what is reachable across a network boundary, and by whom.
A.8.24
Cryptography: where it is used and whether the configuration is sound.

Annex A has 93 controls. ProvenClosed's checks reach 7 of them.

SOC 2 trust services criteria

CC6.1
Logical access: access to systems and data is restricted to those authorised.
CC6.6
Access from outside: the boundary against people and systems outside the organisation.
CC6.7
Data in transit: how information is protected while it moves.
CC7.1
Detection: configuration is monitored and departures from it are noticed.
CC7.2
Monitoring: anomalies and vulnerabilities are identified and evaluated.

SOC 2 names criteria rather than a fixed list of controls, so no fraction is given.

SEBI CSCRF

Six identifiers, cited by category except one standard. What each means, and what CSCRF asks of the vendors of regulated entities: SEBI CSCRF for vendors.

The line it does not cross

  • Evidence, never an assessment. The sentence that says so travels inside the control list itself — on the screen, in exports and in the certificate — so it survives being pasted into a questionnaire on its own.
  • A judgement, and signed as one. Which control a check is evidence for is ProvenClosed's judgement, made without reading your scope document. A certificate that names a control says that its signature does not cover the mapping.
  • No "percent compliant". ProvenClosed never counts itself towards a score for any framework.

Between VAPTs, not instead of one

An annual VAPT is a point in time. ProvenClosed keeps watching after it — catching what appeared since, and proving which fixes actually held. ProvenClosed is not a CERT-In empanelled auditor, and its certificates are not VAPT certificates. It complements a penetration test; it does not replace one.

Answering a customer's security review

When a questionnaire asks how you know an issue is fixed, send the certificate. The reviewer runs one open script on their own machine; it checks the signature, then prints the finding, when it was seen gone, the coverage and the controls — with the caveat directly under them. How a reviewer verifies one.

ProvenClosed does not yet hold its own SOC 2 report or ISO 27001 certificate. How it treats your data.

Have the evidence ready
before the audit asks.

Signed certificates and evidence packs come with Business and Pro, in early access. Monitoring one domain is free.