Answer the audit with evidence, not a fire drill.
Regulators and enterprise customers increasingly want proof of what's in your software and how you manage its risk — a bill of materials, license posture, and a record of remediation. Heeler produces that evidence continuously as a byproduct of securing your code, so audit season becomes an export, not a scramble.
Compliance evidence shouldn't be a quarterly scramble.
SBOM requests, license reviews, and audit questionnaires usually mean weeks of manual data-gathering across tools. When the inventory isn't continuous and accurate, every audit starts from zero.
SBOMs on demand
Customers and regulators now ask for a bill of materials — and a stale spreadsheet won't pass.
License risk hides in the tree
Copyleft and restricted licenses arrive through transitive dependencies no one reviewed.
Proof, not promises
Auditors want evidence that risk is tracked and remediated to policy — not an assurance that you're 'on it.'
A continuous, accurate bill of materials.
You can't attest to what you can't see. Heeler keeps a live SBOM of every component — direct, transitive, first-party, and bundled — so the inventory is current the day the request comes in.
Standard-format SBOMs
Export a CycloneDX bill of materials on demand — not a spreadsheet assembled by hand the night before.
The whole tree
Direct, transitive, first-party, and bundled dependencies — the components that don't show up in a manifest still show up here.
Always current
The inventory updates as your code changes, so there's no gap between what's deployed and what's documented.
License and dependency policy, enforced.
Compliance isn't only about listing components — it's about proving you control them. Heeler enforces your policy at the pull request, before a violation ever merges.
License policy
Define which licenses are allowed and route or block the ones that aren't — including copyleft arriving through transitive dependencies.
Blocked at the PR
Guardrails stop policy-violating, unmaintained, or too-new dependencies at the pull request, on your SCM's native checks.
Consistent across repos
Policy applies uniformly across the portfolio, so an auditor sees one standard, not per-team exceptions.
EVIDENCE OF CONTROL
Remediation, on the record.
Proving you found something is easy. Proving you fixed it — and that the fix actually reached production — is what an auditor asks for. Heeler produces that record as a byproduct of doing the work, not as a separate reporting exercise.
SLOs you can report against
Every finding carries a due date derived from your policy — Urgent 14 days, Plan 60, Defer 120 by default. Attainment against those deadlines is a number, not an impression.
Every automated fix is auditable
The sequence of agent attempts, the CI results across iterations, and every code change made along the way — with the reasoning at each step. Automation did the work; the record shows exactly what it did.
Deployed, not just merged
A finding closes when Heeler confirms the vulnerable code is genuinely gone from your running services — Active, then Fixed, then Deployed. Closing at merge is an assumption about production; this is evidence.
Change management, enforced
Ticket enforcement is an opt-in setting requiring every remediation to be linked to a ticket before an agentic fix can run — a hard guarantee that automated changes stay traceable to an approved request.
EXCEPTIONS ON THE RECORD
What you've accepted, who accepted it, and when it lapses.
Granting an exception happens on the finding. Reviewing them is a different job — so every risk exception and every custom remediation deadline across the program sits in a register you can work, rather than a justification field someone has to go looking for.
Every live exception, in one list
Accepted risk and extended deadlines, each with its reason, the person who granted it, the team that owns the code, and the date it lapses.
See how far a deadline moved
A deadline exception shows the date now in force beside the one Heeler originally calculated — so the size of the concession is on the page, not buried in a comment.
Answer “what did they accept?”
Filter by who granted it — the review you want when someone changes role or leaves. Filter by date to find what's about to lapse, or already has and quietly put a finding back on the books.
Exceptions extend. They don't defer forever.
A remediation deadline can be pushed out, but never pulled in and never more than a year past the original. Remove an exception and the finding returns to its automatic treatment immediately.
THE AUDIT
The questions an auditor actually asks.
Audit conversations tend to reduce to the same handful of questions. Each one has a specific answer in Heeler, and each answer is data rather than an assertion. Heeler itself holds a SOC 2 Type II attestation.
“What's your posture, and is it improving?”
Dashboards showing current posture and how it's moving — the two things every audit opens with, and the two hardest to assemble by hand.
“Do you fix things within a defined window?”
SLO policy sets the deadline per risk level, and attainment against it is reportable. Not a promise that things get fixed — a measurement of whether they did.
“How do you control open-source licenses?”
License policy enforced at the pull request, across the full SPDX catalog, with exceptions that are scoped, time-boxed, and recorded.
“What's in this application — and who changed what?”
A continuously generated CycloneDX SBOM for the first half, and an audit log recording who changed a security setting and when for the second.
BEYOND SOFTWARE INVENTORY
Know what regulated data your code handles.
Audit readiness isn't only a dependency question. Heeler also derives sensitive-data and API scope directly from the schemas and contracts already in your repositories.
Know what data your code actually handles.
Heeler reads the models and contracts already in your repositories to find the entities you persist and the fields they carry — then classifies each one and maps it to the regulations that apply. Discovered from your code, not collected by survey.
Discovered, not declared
Entities come from the ORM models and schema definitions already in your code, plus the API contracts you already publish — across every framework your teams build in.
Classified field by field
Every attribute carries a category, a sensitivity, a severity, and the regulations that cover it — with protected health information flagged independently rather than inferred. Unclassified fields are counted, not quietly dropped.
A query, not a survey
Filter by regulation to get the repositories in scope. Filter by team to get their own data report. Every repository, service, and application carries its own Data tab.
Re-derived on every analysis
A new model in a pull request shows up once that code is analysed — so the inventory tracks the codebase instead of ageing the moment it's filed.
DATA IN TRANSIT
Entities tell you what your code stores. Endpoints tell you what it moves.
Every discovered API endpoint is classified by the data that passes through it — what arrives in the request, what leaves in the response, the categories it carries, and every regulation that treats it as in scope. Read from the OpenAPI, GraphQL, protobuf and JSON Schema contracts your code already declares, so nothing is tagged by hand.
Consumes and transmits, kept separate
Personal data arriving in a request is a collection and retention question. Personal data leaving in a response is an exposure question. Heeler reads each from the direction of the schema, so the two are never conflated.
Classification next to posture
Critical personal data on an endpoint that is also public and unprotected is a different problem from the same payload behind authentication — and both facts sit on one screen instead of in two tools.
The evidence, field by field
Every field on the schema, with the attribute and category it matched, its severity, the confidence, and what the classification keyed off. Health information is flagged in its own right rather than inferred.
The scope list for an audit
Filter by regulation to get the endpoints in scope. Filter by team to hand each one the endpoints it owns that touch regulated data. Then export it, or generate the report.
Mapped to the frameworks and regulations you report against.
Every attribute carries the regulations that cover it, so working out scope becomes a filter rather than a workshop. One attribute commonly maps to several — the counts overlap by design and aren't meant to sum.
Six frameworks and regulatory groupings
GDPR (EU) · CCPA (California) · HIPAA (US) · India DPDP · ISO/IEC 27001 · US State Privacy Laws.
Scope, on demand
Filter to a regulation and you have the repositories it touches, with the owning team attached to each one. Which services fall under HIPAA stops being a question you have to ask around.
A point-in-time report
Generate a Compliance Report scoped to exactly the filters you're looking at, export the same view to CSV, or pull it over the API.
An inventory, not a legal determination
Heeler tells you what data your code handles and which regulations reference it. What that means for your obligations stays with your privacy and legal teams — this is the evidence they work from, not the verdict.
Export-ready for the standards you report against.
When the audit or customer questionnaire arrives, the answer is already assembled: what you have, what's at risk, and what you've fixed — with the record to prove it.
Export what you need
Findings, SBOMs, and inventory export cleanly for reporting, customer security reviews, and audit evidence.
Remediation on the record
SLOs and remediation history show risk is tracked and fixed to policy — the proof auditors ask for.
Maps to your frameworks
The same evidence supports the software-supply-chain and AI-governance requirements your customers and regulators increasingly expect.
Make your next audit an export.
A demo shows the SBOM, license posture, and remediation record Heeler keeps current across your portfolio — the evidence your auditors and customers ask for.
