Compliance frameworks we automate
One platform, 27 frameworks. Pick the one your customers ask for — TensorShield maps your findings to its controls, prepares the fixes, and produces signed, auditor-ready evidence.
None of it is a separate exercise. The same work that finds and closes a real problem is what fills in the control — so compliance stops being a second project you run alongside security.
Security & trust
Trust Services Criteria — security & confidentiality for service organizations.
International standard for an information security management system (ISMS).
CIS Critical Security Controls — a prioritized set of defensive safeguards.
NIST Cybersecurity Framework 2.0 — govern, identify, protect, detect, respond, recover.
ISO 22301:2019 — business continuity management for resilience and recoverability.
UK Cyber Essentials — the NCSC scheme's five technical controls. Coarse by design, so many findings land on the same control.
Sector & payments
Payment Card Industry Data Security Standard — protecting cardholder data.
US healthcare Security Rule — safeguards for electronic protected health information.
Sarbanes-Oxley IT general controls over financial-reporting systems.
US GLBA Safeguards Rule — protecting customer financial information (16 CFR 314).
EU DORA (Reg. 2022/2554) — ICT operational resilience for financial entities. Mapped to the ICT-risk articles a finding can actually evidence (identification, protection and prevention, detection, resilience testing); its governance, incident-reporting and contractual duties are procedural and are not claimed.
Privacy
EU General Data Protection Regulation — security of personal-data processing (Art. 32).
Privacy extension to ISO 27001 — a Privacy Information Management System (PIMS).
California Consumer Privacy Act / CPRA — consumer data rights & reasonable security.
India's Digital Personal Data Protection Act 2023 — safeguards for personal data.
ISO/IEC 27018:2019 — protecting personally identifiable information in public clouds.
Canada's PIPEDA — fair-information principles for handling personal data.
Government
US federal control catalog for information systems (Rev. 5).
Protecting Controlled Unclassified Information (CUI) in non-federal systems.
US government cloud authorization baseline (Moderate), built on NIST 800-53.
US DoD Cybersecurity Maturity Model Certification 2.0 (Level 2) — defense supply-chain controls.
India regulatory
CERT-In Directions 2022 — India's mandatory six-hour cyber-incident reporting and log-retention duties.
RBI Cyber Security Framework — the Reserve Bank of India's Annex I baseline controls for regulated entities.
SEBI CSCRF — the Cybersecurity and Cyber Resilience Framework for SEBI-regulated entities.