Prove you handle data responsibly without handing your data to a vendor
Most compliance platforms ask you to upload your cloud access and audit evidence to their servers to prove you protect data. Scorifya Controls runs on your own infrastructure instead: 54 automated checks and 49 manual controls across five frameworks, with proof an auditor can verify without trusting anyone.
The contradiction at the center of compliance software
Here is the strange bargain most compliance platforms offer. To demonstrate that your company handles sensitive data responsibly, you connect your cloud accounts to their service, grant it read access to your infrastructure, and upload your policies and evidence to their servers. The tool then reads your posture, stores it, and presents it back to your auditor. To prove you are careful with data, you first hand your data to one more vendor.
For a seed-stage team that is exactly the wrong direction. Your first SOC 2 or ISO 27001 push is often the moment you are trying to *reduce* the number of third parties touching your systems, not add a well-funded one that now holds a map of every gap in your security. The contradiction is usually just accepted, because the tooling has always worked that way.
Scorifya Controls resolves it by running on infrastructure you already control. You deploy it on your own server in about ten minutes. It reads your cloud configuration with read-only credentials that never leave that server, stores your check results and evidence locally, and produces the same audit-ready output, without a vendor in the middle holding any of it. The only thing it ever sends out is a once-a-day license check containing your key and your domain, nothing else.
One evidence base, five frameworks
The second quiet cost of compliance is duplication. A control like "production databases encrypt data at rest" is evidence for SOC 2, for PCI DSS, for ISO 27001, and for HIPAA. Tools that treat each framework as a separate project make you gather that evidence four times.
Controls maps one evidence base to five frameworks at once: **SOC 2** (AICPA TSC 2017), **PCI DSS 4.0.1**, **ISO/IEC 27001:2022**, the **HIPAA Security Rule**, and **CMMC Level 1**. Every one of the 54 automated checks is mapped to its SOC 2, PCI DSS, and ISO 27001 Annex A criteria; 52 of the 54 also carry a HIPAA citation, and 24 carry a CMMC Level 1 practice ID. Do one access review and it counts everywhere it should. Filter the dashboard to a single framework when you are preparing for that specific audit, or view the whole posture at once.
Every framework is included in every tier. There is no per-framework upcharge, no "HIPAA add-on", no module to unlock. The full coverage page lists every check and every mapping if you want to see exactly what is covered before you decide anything.
Automated where it can be, honest where it cannot
Compliance is not only a cloud-scanning problem, and any tool that pretends otherwise is setting you up to fail an audit. Controls runs **54 automated checks** across AWS, GCP, Azure, and GitHub, the things a machine can verify directly, like encryption settings, access-key hygiene, logging, and branch protection. When a check fails, it opens a tracked finding with an owner and a due date, and closes it automatically on the next passing run.
But a real audit also asks for the things a scanner cannot see: your onboarding and offboarding process, your incident-response plan, your vendor reviews, your risk assessment. Controls tracks **49 manual controls** for exactly those, each with a place to attach evidence and record who attested to it and when. It does not paper over the human half of compliance; it gives that half the same structure as the automated half, so nothing lives in a spreadsheet or in one person's memory.
Proof an auditor can check without trusting you
The uncomfortable question underneath every attestation is: how does the auditor know you did not write it the week before the audit and backdate it? Most tools answer with "trust our timestamps", which just moves the trust to the vendor.
Controls answers with cryptography instead. When you attest a manual control, adopt a policy, or accept a risk on the record, the decision is sealed with an **RFC 3161 trusted timestamp** issued by an independent authority. The seal covers the exact content and the exact date, and anyone can verify it offline with standard OpenSSL, no Scorifya account, no call to our servers, no trust in your machine's clock. An attestation written months ago and one written yesterday are provably distinguishable.
All of it bundles into a one-click **audit package**: a single archive with the report, every automated result, every attestation and its evidence, your adopted policies, and the raw timestamp tokens. You hand it to your auditor and they can verify the whole thing on their own laptop. It also ships **NIST CSF 2.0** and **CIS Controls v8 IG1** coverage views, which are useful for the security questionnaires and cyber-insurance forms that arrive alongside the formal audit.
What it costs, and what it does not cost you
Pricing is flat and predictable, not per-seat. **Starter is $99/mo** and covers one cloud provider of your choice (AWS, GCP, or Azure) plus GitHub, the right fit for a startup running on a single cloud heading into its first SOC 2. **Pro is $249/mo** and covers all four providers and all 54 checks. **Team is $499/mo** and adds multi-tenant licensing for agencies and consultants managing several clients from one instance. Every tier includes all five frameworks, all 49 manual controls, unlimited users, and unlimited check runs. Adding a teammate never changes your bill.
There is no time-boxed free trial and no card-required countdown. Instead there is a **30-day money-back guarantee** on every self-serve tier: your first month is effectively the trial, and if it is not a fit you email us within 30 days for a full refund. That is the whole pricing story. What Controls costs you in vendor risk, ongoing data exposure, and per-seat creep is the part worth noticing: nothing.
See it before you decide anything
You do not have to take any of this on description. There is a **live demo** at the Controls demo page, a real, running instance with the full dashboard, all 54 checks with run history, the manual controls, and the read-only auditor view. It uses fictional data for a made-up company, needs no email and no signup, and you can download the very audit package an auditor would receive.
When you are ready for your own stack, the setup guide walks through it end to end: buy a license, deploy on a server you control, connect your cloud with read-only credentials, and run your first checks. It takes about ten minutes, and your evidence starts accumulating on your own infrastructure from the first run. Questions along the way live on the Controls help page.
Try a scan on scorifya.com, read how we score, or see Pro for unlimited scans and exports.
Get a weekly digest
New KEV CVE notices and (later) score changes on the domains you watch. One email a week, easy unsubscribe. We don't share or sell your address.
By subscribing you confirm you can receive transactional security updates from Scorifya at this email.