For Compliance

Your audit evidence,
generated automatically.

VulnPilot turns every vulnerability scan into SOC 2 CC7.1 and ISO 27001 A.8.8 evidence. One command. Your scan history becomes your audit trail.

How it works

From scan to evidence in one command.

Export your Nessus scan as CSV.

vulnpilot analyze scan.csv — findings scored, SLA tracked, history recorded.

Remediate findings according to your SLA policy.

vulnpilot verify new_scan.csv — every fix documented with a before/after diff.

Audit requires documented evidence of vulnerability management.

vulnpilot analyze scan.csv --evidence soc2 — Markdown evidence pack, mapped to CC7.1.

Compliance frameworks

Built for real audits.

SOC 2 CC7.1

CC7.1 requires documented vulnerability monitoring and remediation. VulnPilot generates an evidence pack mapping each finding, its risk score, remediation status, and SLA compliance directly to this control.

ISO 27001 A.8.8

A.8.8 requires management of technical vulnerabilities. VulnPilot's local scan history and evidence generation provide the documentation trail auditors look for.

SLA breach tracking

Every finding is tracked against configurable remediation deadlines. When breaches occur, they are logged with exception handling — critical context for any audit.

Remediation verification

vulnpilot verify diffs consecutive scans, classifying each finding as fixed, still open, or newly introduced. This creates a documented remediation chain your auditor can follow.