// Solutions · Compliance

The pentest evidence your audit needs.

When an auditor, a customer questionnaire, or your cyber-insurer demands a penetration test, Rift delivers a verified-findings report and a full, replayable action log you can attach as your pentest evidence, on the cadence your framework needs. It's the technical evidence, not a signed attestation letter.

// Frameworks

One test, evidence for your obligations

Rift produces the technical pentest evidence each framework asks for. Here's what each needs and what Rift gives you.

SOC 2 Type II

A SOC 2 pentest that gives independent evidence for the CC-series controls, as a verified-findings report you attach to your audit.

ISO 27001

ISO 27001 penetration testing that produces technical vulnerability-testing evidence to support your controls.

GDPR

Article 32 evidence of 'regular testing of technical measures' for systems processing EU personal data.

HIPAA

Technical-evaluation evidence you can use toward the Security Rule. Live confirmation is opt-in and runs safely against a target you authorize.

Cyber insurance

The proactive testing evidence underwriters increasingly require to bind or renew a policy.

Customer questionnaires

Answers the pentest sections of SIG, CAIQ, and custom vendor security reviews, fast.

// Cadence

Annual is the floor, not the ceiling

A yearly test checks the box. Re-running keeps it checked, and you never discover a regression the week before an audit. It's the same engine behind your web application penetration testing.

  • Annual: two tests plus a verified-findings report
  • Subscription: re-run any time, each run diffed against the last
  • Either way: the same evidence-backed findings and action log
  • Reports in JSON, Markdown, and SARIF you can attach as evidence
What lands in your evidence folder
Findings report
Each issue with code-path proof, severity, and remediation guidance (JSON, Markdown, or SARIF).
Scope summary
What was in scope and how it was tested.
Re-test record
Evidence that findings were fixed and verified on re-run.
Action log
Full, replayable record of what the agents did.
// For advisors

Auditors & vCISOs

If you recommend pentest vendors to your clients, Rift's per-size pricing is easy to scope, protects your margin, and scales cleanly across a book of business.

Referral & reseller tracksWhite-label reportingReferral trackingVolume pricingMulti-client dashboard

Stop scrambling before every audit.

Whether you need a one-off for an upcoming deadline or continuous coverage, get early access and we'll reach out the moment Rift is ready.