Cross-framework equivalence engine
Solve a finding once and let the resolution propagate to every framework whose control it satisfies.
One resolution re-evaluates every mapped control across all 8 frameworks.
HIPAA · PHIPA · PIPEDA · GDPR · SOC 2 Type II · ISO 27001 · NIST CSF · AI Governance
Automatically normalize live security signals from AWS, Azure, GCP, Cloudflare, M365 and NinjaOne. Continuously map evidence across SOC 2, ISO 27001, GDPR, HIPAA, PHIPA and PIPEDA with proof-backed audit trails.
Agentless API connectors sync every 15 minutes, so evidence arrives on its own from the providers you already run.
IAM roleread-only
IAM posture, encryption at rest, CloudTrail coverage, VPC flow logs
App registrationread-only
Resource posture, Defender findings, key vault policy
Service accountviewer
Org policy, SCC findings, bucket exposure
OAuth 2.0read-only
MFA enrolment, conditional access, privileged roles
OAuth 2.0read-only
2SV enforcement, admin roles, sharing policy
API tokenread-only
Policy assignment, factor enrolment, lifecycle state
M2Mread-only
Tenant settings, MFA policy, anomaly detection
API keyread-only
Directory posture, device binding, MFA state
OAuth 2.0read-only
Policy assignment, factor coverage
OAuth 2.0read-only
Sign-on policy, MFA coverage
Admin APIread-only
Enrolment coverage, policy strength
OAuth 2.0read-only
User directory, access policy
OAuth 2.0read-only
Device inventory, patch state, disk encryption, AV status
API tokenread-only
WAF rules, TLS config, HSTS, bot protection
GitHub Appread-only
Branch protection, required reviews, Dependabot, secret scanning
Raw findings from AWS, Azure, NinjaOne and M365 are pulled into one Finding model keyed by (orgId, source, externalId), so the same alert reported by two providers stays one finding.
A headless browser renders your client DOM and reads what is on screen: personal data in visible text, cookie flags, HSTS headers and reachable endpoints.
Synthetic demo data only.
Uploads are validated at the byte level (%PDF-), checked for issue date, then scored for relevance against the control, so a reviewer opens files that already match what the control asks for.
› reading upload … access-review-q2.pdf
› magic bytes … %PDF- OK
› structure … 14 pages of content
› validity … issued 2026-04-02, in date
› relevance … 0.98 against CC6.2
› status … AWAITING REVIEWER APPROVAL
A control reaches Met once a reviewer approves the upload.
Generate an auditor-ready package: executive summary, evidence appendix, and the reviewer sign-off trail behind every control.
Every row below is a part of the platform you can point an auditor at.
| Area | How WeGuard does it |
|---|---|
| Audit preparation | Live evaluation every 15 minutes, with the evidence attached as it is collected |
| Multiple frameworks | Cross-framework equivalence: one resolution propagates to every control it satisfies |
| Met status | Granted on reviewer-approved evidence that is still in date |
| Rendered-page checks | DOM inspection of the page after JavaScript runs, on the text a user sees |
Solve a finding once and let the resolution propagate to every framework whose control it satisfies.
One resolution re-evaluates every mapped control across all 8 frameworks.
A headless browser reads visible text nodes, input fields, HSTS headers and cookie flags.
The scanner evaluates the page a real user loads, after JavaScript has run, so personal data that only appears in the rendered UI is reviewed alongside everything else.
SaaS, finance, healthcare and the public sector. WeGuard maps your controls to every framework your auditors ask for, and reuses the same evidence across all of them.
Hosting region, encryption, tenant isolation and log retention, stated in full.
Canadian customer data stays in Canadian datacentres, and backups and log archives stay in the same region.
Sensitive columns encrypted with AES-256-GCM. Keys live in a regional AWS Secrets Manager and rotate on a 90-day schedule.
A Prisma extension injects organizationId at the query layer, so every read is scoped to one organization by construction.
Append-only logging with SHA-256 content hashing and 10-year retention for sensitive-data access events.
A Business Associate Agreement is available and executed before any PHI reaches the platform.
Illustrative outcomes for the three teams WeGuard is designed around.
Runs HIPAA and SOC 2 in parallel, because evidence collected for one is reused by the other automatically.
NinjaOne endpoints, M365 identities and AWS infrastructure arrive as one normalized finding stream in a single console.
Each upload is validated for file type, issue date and relevance, and a reviewer approval is recorded before a control reaches Met.
Connect your cloud, identity and endpoint stack today. Every control evaluates against live signals, with the evidence behind it attached.