Skip to main content
Cloud Fortress, por Cloud y Olé
Area 3 · Governance and compliance

Compliance is not a PDF: it is a picture that changes every day

Most teams live compliance as a one-off effort: the audit arrives and the evidence has to be rebuilt by hand. Cloud Fortress turns it around — the compliance status stays alive, fed by what is already happening on the platform.

What's included

From the control to the evidence

  • Compliance manager

    ENS and ISO, always current

    Tracking of your status against each framework (ENS, ISO 27001) with the evidence attached to the real controls.

    See capability
  • Inventory

    Inventory compliance

    Checks that what you have complies with what it should: the same Core inventory, now read through a conformity lens.

    See capability
  • Documentation

    Templates and metadata

    Regulatory templates and metadata management, so documentation stops being handcrafted work.

  • Verification

    Pentesting (Red Team)

    Offensive exercises to check that what holds on paper holds in reality.

Why it matters

The evidence is already there; you just have to show it

When the inventory, the vulnerabilities and the incidents all live in the same place, the proof an audit asks for does not have to be manufactured: it already exists. A control that demands an «up-to-date asset inventory» or «vulnerability management with tracking» is demonstrated with what the platform does every day. That is the advantage of having governance and operations under one roof.

The ENS compliance panel in Cloud Fortress showing controls, their evidence status and the thread on each one
Verification

A pentest that is worth something to the next one

An offensive exercise usually ends in a PDF, and the PDF loses exactly what cost the money: the story. Here the exercise is delivered as an operations room —the attack chain by phase, with the technique behind each step and what your defence saw at each one— and because every exercise shares the same model, this year's sits next to last year's and you can see what actually improved. Each finding also carries its retest: the step that almost never happens when the report is an attachment somebody files away.

And the target surface is not a list of names: they are assets from your inventory. «They compromised SRV-04» is a link to that machine, with its owner, its software and its vulnerabilities beside it. Findings flow into the same remediation cycle as everything else —with a plan and tracking through to the patch— instead of sitting in an appendix nobody opens again.

The exercise is run by the audit team, whether ours or a third party you hire. The platform is where it is coordinated, documented and delivered; it does not dictate who carries it out.

The Red Team operations room in Cloud Fortress, with the exercise chain by phase over real inventory assets
Frequently asked questions

Frequently asked questions

  • Does Cloud Fortress certify my ENS or my ISO?

    No. An accredited body certifies. What Cloud Fortress does is get you to that audit with the evidence ordered and alive, rather than rebuilt at the last minute.

  • Does it work for ISO 27001 as well as ENS?

    Yes — the manager is built to work with several frameworks in one platform: ENS, ISO 27001, NIS2, DORA and GDPR. Many controls are shared between frameworks and the evidence is reused. In the demo we go over which ones we cover today and how.

  • How is it recorded who did what on a control?

    Each control's history lives in its own thread: uploading evidence, changing status or reassigning the owner writes a system entry with its author and date. Only the real change is recorded — resubmitting the same status does not clutter the thread — and entries travel between your panel and the Cloud Fortress analyst's.

  • How do I know which controls are about to expire?

    The compliance dashboard brings together overall progress, progress per framework and upcoming control expirations. It is the view that avoids the last-minute scramble: what is about to lapse is visible ahead of time, not once it already has.

Understand the risk. Act with confidence.

30 minutes with a scenario close to yours. No canned deck, no strings attached.