| CIS Controls v8.1Stamped by a shipped checkCenter for Internet Security | Every finding Guard raises carries a Safeguard ID. A fixed table stamps it the same way every time, before any model takes part. The ID rides with the finding into the CSV, the SARIF, the PDF and the screen. | Four safeguards are in use today. They cover credentials in content and injectable query text. This maps the checks that ship. It is not a coverage claim over the whole catalogue. CIS Benchmarks are a separate CIS publication of secure setup baselines. This maps nothing to them. |
|---|
| NIST CSF 2.0Stamped by a shipped checkNIST | The same finding carries its CSF function, from the same fixed table. Your security team gets the control reference already attached. It arrives in a format their own software reads. | The functions in use are Identify, Protect and Detect. Govern, Respond and Recover cover work that happens around the product. No finding claims them. |
|---|
| SOC 2Evidence you mapAICPA | You get the change approval, the person who gave it, and a hash-chained record of both, made as you work. A common-criteria walkthrough asks for exactly this. | Boreon holds no SOC 2 report of its own. Your own auditor issues your own report, about your own controls. |
|---|
| ISO 27001Evidence you mapISO and IEC | The product produces access review, credential handling and a record of admin change. Each one exports. | Boreon holds no ISO 27001 certificate of its own. This page says nothing about your own certification scope. |
|---|
| HIPAAEvidence you mapUS Department of Health and Human Services | Risk finds protected health identifiers inside published content and reports where they sit. Provider identifiers are checked by their real check digit, not by a pattern that looks right. | Detection tells you where the data is. Whether a use is allowed is a judgement about your organisation. The product makes none. |
|---|
| GDPREvidence you mapEuropean Union | Personal data in published content is found, and ownership is resolved. Lineage answers where a field came from. That is the question a record of processing keeps asking. | A register of processing is a document your organisation keeps. The product supplies the findings for it. You write the register itself. |
|---|
| PCI DSSEvidence you mapPCI Security Standards Council | Card numbers in content are found and checked with the real Luhn check. A report names candidates that pass it, not any sixteen digits in a row. | Scope, segmentation and the assessment itself belong to your qualified assessor. |
|---|
| CCPAEvidence you mapState of California | The same detection and ownership surfaces show which published content holds personal information. They also name who is responsible for it. | Your organisation answers consumer requests. The product helps you find the data, and you send the reply. |
|---|
| NIST 800-53Evidence you mapNIST | Audit records, access enforcement and configuration change all come out as evidence you can export. A control owner can attach it to a body of evidence. | Today the stamped control references are CIS Controls v8.1 and NIST CSF 2.0. Identifiers from this catalogue are not stamped on any output. |
|---|
| FINMAEvidence you mapSwiss Financial Market Supervisory Authority | Access management and the record of who changed what are the operational-risk artefacts asked for most. Both are made as you work, not assembled before a review. | What your regulator expects applies to your institution. Where you choose to host is a fact about where data sits. It carries no regulatory approval. |
|---|
| nLPD/revDSGEvidence you mapSwitzerland | Personal data is found in published content. On the hosted edition, processing stays inside the single deployment that serves you. The sub-processor list is published, not described. | Your own processing register and your own transparency notices remain yours to write. |
|---|
| DORAEvidence you mapEuropean Union | Field level lineage answers what a change will hit, before it is made. The migration and approval trails record ICT change the way a dependency review reads it. | Register of information, incident classification and testing programmes sit with your institution. |
|---|