Compliance reports
8200.dev turns the data it already collects — posture findings, the identity inventory and agent-governance state — into exportable, auditor-consumable access-control evidence for SOC 2, ISO 27001 and GDPR.
Evidence, not certification. 8200.dev is not a certification body and does not grant SOC 2, ISO 27001 or any certificate. A report is documentation you hand to your auditor to prove your access controls and AI-agent access are governed — each control backed by dated, plain-language findings.
What is in a report
Each report maps your findings onto a framework's access-control families, derives a per-control status — pass, attention, fail or not assessed — and assembles evidence tables, a remediation backlog ordered by blast radius, and an agent-governance summary showing which AI agents and service accounts hold access to sensitive resources and under what policy.
Scope is your choice: the whole organization, or a single source.
Controls mapped
We map the access-control families only, and we are explicit about everything we do not assess:
- SOC 2 (TSC CC6): CC6.1 logical access · CC6.2 registration & deprovisioning · CC6.3 least privilege · CC6.6 external-threat protection · CC6.7 information-movement restriction. Not assessed: CC6.4 physical, CC6.8 malicious software.
- ISO 27001 (Annex A): A.5.15 access control · A.5.18 access rights · A.8.2 privileged access · A.8.3 information access restriction. Not assessed: A.8.5 authentication, A.8.24 cryptography, A.7 physical.
- GDPR: Art. 32 security of processing · Art. 5(1)(f) integrity & confidentiality · Art. 5(1)(c) access minimisation. Not assessed: Art. 32(1)(a) encryption, Art. 30 records of processing, Art. 33/34 breach notification.
Export formats
Reports export as a polished, auditor-presentable PDF — a branded cover with the evidence-not-certification disclaimer, an executive summary, per-control evidence, the agent-governance table and a remediation appendix — and as structured JSON containing the exact stored payload.
Previewing a report is available on every tier, including free. Exporting (PDF / JSON download) starts on the Starter tier — preview the value before you pay for it.
Honest about scope
Controls outside our access-control scope are reported as “not assessed” — never silently passed. Reports generated over mock data carry a demo-data badge. The disclaimer on every report, in every language, states that 8200.dev does not grant any certification.