Skip to main content

Compliance Reports

Export control-mapped audit evidence for SOC 2 and HIPAA — audit data, DLP findings, and guardrail enforcement summaries in formats ready for your compliance team or auditors. These are evidence packages you provide to your auditor, not third-party attestations or certifications issued by Clevername.

Key Concepts

Supported frameworks

SOC 2Trust service criteria control mapping: security, availability, processing integrity, confidentiality, privacy.
HIPAATechnical safeguards control mapping: access controls, audit controls, transmission security, integrity. Cloud SaaS is not BAA-covered by default; dedicated HIPAA deployment is handled by request.

What reports include

Each compliance report compiles data from across the platform:

  • Audit summary — Total actions logged, hash chain verification status, retention compliance.
  • DLP findings — Content scanning results grouped by scanner type and action taken.
  • Guardrail enforcement — Tool drift blocks, model access denials, budget cap enforcements.
  • Emergency control log — Emergency actions with SignedApproval receipts or audited SOAR-key execution records.
  • Agent inventory — Active agents, their trust tiers, guardrail profiles, and review approval status.

Report formats

Reports can be exported as PDF (formatted for auditors), CSV (raw data for analysis), or JSON (machine-readable for integration with GRC tools).

Compliance reports page showing framework selection, date range picker, and a generated SOC 2 report preview with summary statistics
Select a framework, set the date range, and generate a report. Preview it inline before exporting.
Step-by-Step Guide
1

Navigate to Compliance Reports

Go to Security → Compliance Reports in the dashboard sidebar.

Dashboard sidebar with Security section expanded, Compliance Reports highlighted
Find Compliance Reports under the Security section.
2

Select a framework

Choose the compliance framework you need: SOC 2 or HIPAA. Each framework maps to specific platform controls and generates the appropriate control-mapped evidence structure for your auditor.

3

Set the reporting period

Select the date range for the report. Common periods are quarterly (for SOC 2) or monthly (for ongoing compliance monitoring). The report will include all audit data within this window.

Note
Reports can only cover data within your retention period. If your retention is 365 days, you cannot generate a report for activity older than 365 days. Extend retention in the guardrail profile if needed.
4

Generate and review

Click Generate Report. The system compiles data from audit trails, DLP events, guardrail enforcement logs, and the agent inventory. Preview the report inline before exporting.

Generated compliance report showing summary statistics, control coverage table, and finding details
Review the generated report inline. Each section maps to specific compliance controls.
5

Export the report

Click Export and choose your format: PDF for auditors, CSV for analysis, or JSON for GRC tool integration. The export includes all supporting data and hash chain verification.