Skip to content

HIPAA · PHIPA · PIPEDA · GDPR · SOC 2 Type II · ISO 27001 · NIST CSF · AI Governance

Compliance automation software.

Automatically normalize live security signals from AWS, Azure, GCP, Cloudflare, M365 and NinjaOne. Continuously map evidence across SOC 2, ISO 27001, GDPR, HIPAA, PHIPA and PIPEDA with proof-backed audit trails.

389
automated controls
8
global frameworks
15+
read-only connectors
15 min
sync interval
Integrations

Read-only connectors for cloud, identity, endpoints and code.

Agentless API connectors sync every 15 minutes, so evidence arrives on its own from the providers you already run.

  • AWS

    IAM roleread-only

    IAM posture, encryption at rest, CloudTrail coverage, VPC flow logs

  • Azure

    App registrationread-only

    Resource posture, Defender findings, key vault policy

  • Google Cloud

    Service accountviewer

    Org policy, SCC findings, bucket exposure

  • Microsoft 365 / Entra ID

    OAuth 2.0read-only

    MFA enrolment, conditional access, privileged roles

  • Google Workspace

    OAuth 2.0read-only

    2SV enforcement, admin roles, sharing policy

  • Okta

    API tokenread-only

    Policy assignment, factor enrolment, lifecycle state

  • Auth0

    M2Mread-only

    Tenant settings, MFA policy, anomaly detection

  • JumpCloud

    API keyread-only

    Directory posture, device binding, MFA state

  • OneLogin

    OAuth 2.0read-only

    Policy assignment, factor coverage

  • PingOne

    OAuth 2.0read-only

    Sign-on policy, MFA coverage

  • Duo

    Admin APIread-only

    Enrolment coverage, policy strength

  • Zoho

    OAuth 2.0read-only

    User directory, access policy

  • NinjaOne RMM

    OAuth 2.0read-only

    Device inventory, patch state, disk encryption, AV status

  • Cloudflare WAF

    API tokenread-only

    WAF rules, TLS config, HSTS, bot protection

  • GitHub

    GitHub Appread-only

    Branch protection, required reviews, Dependabot, secret scanning

The engine

From provider signal to auditor export, in four stages.

  • AWS Security HubSeverity: HIGH
  • Microsoft 365riskLevel: high
  • NinjaOnealertClass: 3
Severity: highone finding

Bucket ACL set to public

Keyed by
orgId · source · externalId
Maps to
HIPAA §164.312(a)(1), SOC 2 CC6.1, ISO A.8.3
Status
Open, owner assigned
  1. 01

    One finding model for every provider

    Raw findings from AWS, Azure, NinjaOne and M365 are pulled into one Finding model keyed by (orgId, source, externalId), so the same alert reported by two providers stays one finding.

    • AWS Security HubSeverity: HIGH
    • Microsoft 365riskLevel: high
    • NinjaOnealertClass: 3
    Severity: highone finding

    Bucket ACL set to public

    Keyed by
    orgId · source · externalId
    Maps to
    HIPAA §164.312(a)(1), SOC 2 CC6.1, ISO A.8.3
    Status
    Open, owner assigned
  2. 02

    Checks on the page a user sees

    A headless browser renders your client DOM and reads what is on screen: personal data in visible text, cookie flags, HSTS headers and reachable endpoints.

    portal.example.com/customers
    CustomerJane Doe · ACCT 000-000PII · visible text
    Session cookiesid=… Secure flag: off
    TransportHSTS header: off TLS policy
    Audit logwrite confirmed

    Synthetic demo data only.

  3. 03

    Evidence validated before review

    Uploads are validated at the byte level (%PDF-), checked for issue date, then scored for relevance against the control, so a reviewer opens files that already match what the control asks for.

    reading upload … access-review-q2.pdf

    magic bytes … %PDF- OK

    structure … 14 pages of content

    validity … issued 2026-04-02, in date

    relevance … 0.98 against CC6.2

    status … AWAITING REVIEWER APPROVAL

    A control reaches Met once a reviewer approves the upload.

  4. 04

    One-click auditor export

    Generate an auditor-ready package: executive summary, evidence appendix, and the reviewer sign-off trail behind every control.

    Executive summary

    Technical appendix

    Coverage analysis

How it runs

How each area of the work runs.

Every row below is a part of the platform you can point an auditor at.

How WeGuard handles each area of compliance work
AreaHow WeGuard does it
Audit preparationLive evaluation every 15 minutes, with the evidence attached as it is collected
Multiple frameworksCross-framework equivalence: one resolution propagates to every control it satisfies
Met statusGranted on reviewer-approved evidence that is still in date
Rendered-page checksDOM inspection of the page after JavaScript runs, on the text a user sees
Architecture

Four parts of the platform, in detail.

Cross-framework equivalence engine

Solve a finding once and let the resolution propagate to every framework whose control it satisfies.

One resolution re-evaluates every mapped control across all 8 frameworks.

A headless browser reads visible text nodes, input fields, HSTS headers and cookie flags.

The scanner evaluates the page a real user loads, after JavaScript has run, so personal data that only appears in the rendered UI is reviewed alongside everything else.

Frameworks & standards

389 automated controls across 8 global frameworks.

SaaS, finance, healthcare and the public sector. WeGuard maps your controls to every framework your auditors ask for, and reuses the same evidence across all of them.

Security & residency

Where your data lives, and how it is protected.

Hosting region, encryption, tenant isolation and log retention, stated in full.

Canadian customer data stays in Canadian datacentres, and backups and log archives stay in the same region.

Field-level encryption

Sensitive columns encrypted with AES-256-GCM. Keys live in a regional AWS Secrets Manager and rotate on a 90-day schedule.

Per-tenant query isolation

A Prisma extension injects organizationId at the query layer, so every read is scoped to one organization by construction.

Append-only audit logs

Append-only logging with SHA-256 content hashing and 10-year retention for sensitive-data access events.

BAA ready

A Business Associate Agreement is available and executed before any PHI reaches the platform.

Who it is for

Built for SaaS teams, MSPs and the auditors who review them.

Illustrative outcomes for the three teams WeGuard is designed around.

100+engineering hours saved per audit cycle

Runs HIPAA and SOC 2 in parallel, because evidence collected for one is reused by the other automatically.

SaaS CTOSeries B B2B SaaS, ~60 engineers
1console for endpoints, identity and cloud

NinjaOne endpoints, M365 identities and AWS infrastructure arrive as one normalized finding stream in a single console.

MSP directorManages 40+ client environments
1recorded approval behind every Met control

Each upload is validated for file type, issue date and relevance, and a reviewer approval is recorded before a control reaches Met.

CISO / security auditorReviews evidence for regulated clients
Questions

Frequently asked questions.

Get started

Connect your first provider in under five minutes.

Connect your cloud, identity and endpoint stack today. Every control evaluates against live signals, with the evidence behind it attached.