Platform · Compliance and standards

Continuous compliance for your code, data and cloud.

Every application, data store and cloud account is assessed daily against the standards you report on. Reports for auditors and the board come from the same evidence.

Applications and code

Assess every application against the standards you report on.

OWASP ASVS 5.0.0, the EU Cyber Resilience Act and DORA, assessed daily from your scans, guardrails, SLOs and SBOMs.

ruleTarget level set by application tier, with overrides
fact_checkVerified only with positive evidence, never just no findings
edit_noteAttest manual requirements with a re-review date
OWASP ASVS 5.0.0 · payments-apiTarget L2 · Tier 1
63% met at L2
EU CRA Annex I · 71%
DORA (simplified) · 58%
ASVS L1, all apps · 84%
ViolatedV1.2.4 Parameterized queries3 SAST findings · orders/repository.py
VerifiedV13.3.1 Secrets kept out of source code
AttestedV15.1.1 Remediation time frames documenteda.patel · re-review Mar 2027
picture_as_pdfReport for auditors · PDF or CSV, with the CIS Controls v8.1 crosswalkOct 2026
Data

Know where regulated data lives, from code to datastore.

Heeler classifies the data your code handles and maps it to the regulations that cover it, down to the endpoint and the database.

badgeGDPR, HIPAA, PCI DSS, CCPA, ISO 27001, SOX, EU AI Act and more
apiRepositories, API endpoints and cloud datastores tagged
picture_as_pdfReport by company, application or regulation
Data inventory115 attributes · 16 categories
AttributeCategoryRegulationsReposAPIsRisk
card_numberFinancialPCI DSSSOX34Critical
diagnosis_codeHealthHIPAA22High
emailContactGDPRCCPA711Medium
date_of_birthIdentityGDPRCOPPA45Medium
Compliance report · PCI DSS · PDF3 repositoriespayments-api, billing-worker, checkout-web1 datastoreorders-db · RDS · prod-payments
Cloud

Score every cloud account against the benchmarks you follow.

AWS Foundational Security Best Practices and CIS benchmarks for AWS, Google Cloud and Oracle Cloud, plus frameworks you build yourself.

cloudScores by framework, account and organizational unit
tuneYour own frameworks, with versions and crosswalks
linkCloud results count as evidence for ASVS, CRA and DORA
Cloud benchmarks · acme38 failing checks
CIS AWS 7.0 · primary · 51%
AWS FSBP · 63%
CIS Google Cloud 4.0 · 71%
Payments framework v3 · 78%
FamilyCIS AWS 3.0 to 7.0, one primary version for scores
CrosswalkPayments framework v3 · controls mapped to CIS and FSBP
verified_userExemption EXM-0042 · approved by a second adminEnds 31 Mar
For the board and auditors

Answer the questions the board asks.

The same evidence that drives daily assessment answers the board and the auditor, without a separate reporting project.

Audit evidenceCan we show compliance evidence?Reports auditors can useASVS, CRA and DORA reports, plus SLO, remediation, guardrail and Audit Log records
Top risksWhat are our top risks in business terms?Urgent risk on Tier 1 appsRanked by business impact, environment, internet exposure and active exploitation
TrendIs our risk going down?MTTR 41 to 18 daysTime to fix, SLO adherence, findings fixed and cloud posture over time
Due diligenceCould we show due diligence after a breach?Every decision on recordSLO policy and adherence, finding history, risk acceptances with expiry, attestations and the Audit Log

How it works

AdoptPick your standards onceApplication and code standards and cloud benchmarks, from one library in Program settings.
AssessEvidence collected for youScans, guardrails, SLOs, SBOMs and cloud checks are assessed every day.
ReportReports on demandPDF and CSV reports per application, standard or regulation, ready for auditors.
Stay compliant as code changes

Turn standards into checks, alerts and reports.

Enforce a standard on every pull request.

Guardrail bundles turn ASVS, CRA and DORA into pull request checks.

Explore PR Guardrails

Know the moment a requirement slips.

When a requirement gets worse, a workflow opens a ticket for the owner.

Explore Autonomous Operations

Build the board report from your agent.

The Heeler MCP server gives your coding agent posture, trends and top risks to report from.

Explore MCP Server

Purpose-built for the AI SDLC

Assess, prove and report compliance from one place.