NullSquare

concept

Compliance Agent

The compliance loop end to end — select a framework, run the agent, read control states, upload or sync evidence, automate re-runs, and export a readiness report.

The Compliance Agent prepares you for an audit — it does not pass one for you. You pick the frameworks that matter, run a compliance assessment, and the agent maps every framework control to a status: passing, failing, needs action, not checked, or excluded. Where a control needs evidence you cannot prove by testing, you upload a document or sync it from a provider, then run the agent again to review it and update the control.

This page walks the whole loop end to end. If you own SOC 2, ISO 27001, NIST CSF, HIPAA, or PCI DSS readiness, read it once — the order of the steps matters, and the boundary between "readiness evidence" and "auditor opinion" matters more.

How compliance works, end to end

Compliance readiness is a loop, not a one-time scan. You give the agent a framework, it tells you where you stand control by control, you close the gaps it flags with evidence, and you run it again so it can confirm the evidence and move the controls. Repeat until the matrix reflects reality, then export the readiness report.

The compliance loop. Adding evidence does not change readiness on its own — you re-run the agent, it reviews the new evidence, and the controls update.
Play: compliance walkthroughInteractive demo · opens in the app

Step 1 — Select the framework

Framework selection happens per scope — during onboarding, or any time in scope settings. Pick the frameworks each environment genuinely needs to support: SOC 2, ISO 27001, NIST CSF, HIPAA, or PCI DSS. Adding more frameworks does not make you "more compliant"; it just enlarges the control surface you have to populate.

Framework selection is per scope — in onboarding, or later in scope settings. Pick what each environment genuinely needs; a payment service and a marketing site can carry different sets.

Step 2 — Start a compliance run

From the home launcher, switch the assessment type to Compliance, pick the framework to assess, and start the run. The agent expands the framework into its individual controls, tests what it can technically verify, reviews any evidence already in the library, and records a status for every control.

From the home launcher, switch the card to Compliance, pick the framework, and click Start — the compliance equivalent of launching a pentest.

Step 3 — Read the control states

When the run finishes, every control carries one of five outcomes. Open any control to see exactly why it landed there — what must be true, the agent's verdict and reasoning, and, when it needs action, the specific evidence it is waiting for.

Every control carries a status. Open a passing control to see the agent's reasoning, or one that needs action to see the exact evidence it is waiting for — with its overview, evidence, and remediation.
  • Passing — the agent has evidence the control is satisfied.
  • Failing — the agent found the control is not met.
  • Needs action — the control cannot be decided yet; it is waiting on evidence you must provide.
  • Not checked — not yet evaluated in a run.
  • Excluded — you have marked the control out of scope for this environment.

Step 4 — Add the requested evidence

Where a control needs evidence you cannot prove by testing, provide it: upload a document, or sync it from a connected provider. Here is the catch people miss — uploading does not pass a control by itself. The evidence sits as "awaiting agent review" until you run the agent again, and that run reviews the evidence, records a control check that cites it, and updates the control. Reviewer, dates, and reasoning are preserved, so every status is traceable to the evidence and the run that credited it.

Upload the document a control asked for — a policy, an access review, a runbook. It lands in the evidence library as "awaiting agent review": advisory until a run reviews it.

Step 5 — Connect an integration

Some evidence is better synced than uploaded. Connect a provider to pull configuration straight into the evidence library — Google Workspace 2-step verification and admin roles, Microsoft Entra MFA, GitHub branch protection. Synced evidence is read-only and, like an upload, stays advisory until a compliance run reviews it against the controls it maps to.

Connect a provider — Google Workspace, Microsoft Entra, GitHub — to sync configuration as evidence automatically: MFA, admin roles, branch protection. It syncs read-only and stays review-gated until a run credits it.

Step 6 — Automate to stay compliant

Readiness drifts as your environment changes and evidence goes stale. Instead of re-running by hand, schedule it: an automation re-assesses the framework and reviews newly synced or uploaded evidence on a cadence, so the matrix stays current and gaps surface early.

Schedule the re-run so readiness stays current. An automation re-assesses controls and reviews new evidence on a cadence — nightly, weekly, or on an event — without you driving each run.

Step 7 — Export the readiness report

Once the matrix reflects your current evidence, export a readiness report. It summarizes the snapshot at a point in time, cites the evidence behind each control, lists remaining gaps, and recommends next steps — suitable for sharing internally or with an external advisor ahead of a real audit. Reports are reproducible; regenerate after evidence changes.

The readiness snapshot, at a point in time — what you export as a report to share internally or with an external advisor ahead of a real audit. Regenerate it after evidence changes.

What readiness is not

Readiness is not certification, attestation, or auditor opinion

NullSquare produces supporting evidence and a written assessment of how well your environment is positioned to undergo audit. It does not certify, attest, or replace an independent auditor. Real audits are performed by accredited firms; readiness is the artifact set you bring to one.

Related articles

Last updated Jul 14, 2026