RosettaOps™ Compliance
Continuous compliance
Compliant today.
Still compliant tomorrow.
An audit is a snapshot. Your cloud changes every day in between. Ten standards are checked continuously against live accounts, every finding maps to the control it breaks, and drift is corrected as it appears.
What gets checked
One policy library, assembled into a pack per standard. A check that satisfies several standards is written once and appears in each, so there is no second rule set to keep in step with the first.
PCI DSS v4.0
ISO/IEC 27001
HIPAA Security Rule
NIST SP 800-53 Rev 5
NIST SP 800-171 Rev 2
NIST Cybersecurity Framework
FedRAMP Moderate
SOC 2
GDPR
CIS AWS Foundations Benchmark
Findings point at controls,
not at categories
Most tools tell you a bucket is public. Useful, and not what the auditor asked. Every check here carries the control identifiers it satisfies, so a finding lands against a named requirement.
One finding, several standards
The same check often satisfies a requirement in three or four frameworks at once. Fix it once and every mapped control moves with it.
Evidence an auditor accepts
Reports come out per standard, so the answer to which controls are met is a report rather than a spreadsheet somebody assembled by hand.
Continuous, not annual
Checks run against live accounts on a schedule you set, not as a point-in-time review. A control that was met last month and is not met today shows up today.
Cloud Custodian and AWS Config
Two engines. Use either,
or use both together.
Run Cloud Custodian on its own, run AWS Config on its own, or run them together and let each cover what the other cannot. Most estates already have one of the two, and nothing here asks you to abandon it.
Cloud Custodian alone
Checks and fixes in one step. A policy finds the failing resource and acts on it, which is why most of the library lives here.
AWS Config alone
Some controls have an AWS Config managed rule and no policy equivalent. Those rules are deployed for you, so the control is covered rather than quietly skipped.
Both, wired together
AWS Config detects, Cloud Custodian remediates. Anything Config marks as failing is picked up and acted on, so a finding does not sit waiting for somebody to notice it.
AWS Config is very good at noticing. It was never meant to be the thing that fixes it.
Most compliance tools
stop at the report
Compliance automation platforms are built for audit readiness across the whole company: policies, training, vendor reviews, evidence collection. They do that well, and on the cloud side they connect read-only. When a check fails, they tell you.
Read-only tooling
A finding becomes a ticket
The dashboard turns red and an engineer is asked to go and fix it. Between the finding and the fix is a queue, and the queue is where compliance drift lives.
RosettaOps
A finding becomes a fix
The same checks run, and where you have allowed it the resource is corrected. Drift is corrected when it appears rather than recorded for somebody to deal with later.
Both answer whether you are compliant. Only one of them makes you compliant.
There are also specialist policy platforms, which do enforce and do it well. The difference there is not capability, it is scope: compliance here is not a separate product with its own console and its own contract. The checks act on the same accounts, under the same permissions, as the budgets and the landing zone.
Read it before you run it
Compliance tooling gets approved by a security team or not at all, so the checks are written to be reviewed.
Open, not proprietary
The compliance layer is built on Cloud Custodian, an open source CNCF project. The checks are plain readable files, not something only we can interpret.
Reporting first
Remediation is off until you switch it on, and a scan can run without acting, so you see exactly what would change before anything does.
Yours to keep
Because the format is open, the policies stay usable outside our platform. Nothing about your compliance posture is trapped here.
Common questions
Which compliance standards are covered?
Ten: PCI DSS v4.0, ISO/IEC 27001, the HIPAA Security Rule, NIST SP 800-53 Rev 5, NIST SP 800-171 Rev 2, the NIST Cybersecurity Framework, FedRAMP Moderate, SOC 2, GDPR and the CIS AWS Foundations Benchmark. They are built from one policy set, so a check that satisfies several standards is written and maintained once.
Does it map findings to individual controls?
Yes. Each policy carries the control identifiers it satisfies, so a finding points at a named control rather than a general security category. That is what an auditor asks for, and it is why one finding can close a requirement in more than one standard at once.
Will it change our resources automatically?
Not unless you enable it. Scanning reports first, remediation is off by default, and policies can be run against your account without acting so you can see exactly what would change before anything does.
Do we have to use Cloud Custodian, or can we use AWS Config?
Either, or both. Cloud Custodian checks and fixes in one step and carries most of the library. AWS Config covers controls that have a managed rule and no policy equivalent. Run them together and AWS Config detects while Cloud Custodian remediates, so a finding does not wait for someone to notice it.
Are we locked into your policy format?
No. The compliance layer is built on Cloud Custodian, an open source CNCF project, and the policies are plain readable files. Your security team can review them before anything runs, and they remain usable outside our platform.