Workspace Dashboard
Continuous compliance assessments and quick-fix tasks.
Pass Checks
Warnings
Failing Checks
Score compiles verified integrations and manual uploads. Keep checks secure to satisfy audit criteria.
SOC 2 Type II System Summary
Grade FISO 27001 Control Index
Grade F| Framework | Standard | Monitored Rules | Status | Scan Type |
|---|---|---|---|---|
| SOC 2 Type II | AICPA Trust Services Criteria | 16 Controls Monitored | Unprepared | API Continuous |
| ISO/IEC 27001 | Annex A Control Matrix | 10 Controls Checked | Unprepared | API Continuous |
| HIPAA Security | Safeguards Rule (45 CFR) | 8 Controls Audited | Unprepared | API Continuous |
Platform Integrations
Connect your cloud providers, code repositories, identity providers, and HR systems. Each integration enables automated compliance checks that run continuously in the background.
AWS Cloud Platform
Monitors your AWS account for security configuration gaps across VPC, IAM, KMS, and CloudTrail services.
Prerequisites
- AWS account with IAM administrator access
- VPC Flow Logs enabled on target VPCs
- CloudTrail active in the primary region
How to Connect
- Log in to the AWS Console → IAM → Roles
- Create a new role: select "Another AWS Account" as trusted entity
- Attach the
SecurityAuditmanaged policy (read-only) - Copy the Role ARN (e.g.
arn:aws:iam::123456:role/SCoreScan) - Click "Connect AWS" below and paste the Role ARN
Compliance Checks Unlocked
Microsoft Azure
Audits Azure Active Directory policies, Blob container encryption, and tenant-level MFA enforcement rules.
Prerequisites
- Azure AD with Global Admin or Security Reader role
- An App Registration in Azure Portal
- API permissions:
Directory.Read.All,SecurityEvents.Read.All
How to Connect
- Go to Azure Portal → App registrations → New registration
- Name it "S-Core Compliance Scanner" and register
- Under Certificates & secrets, create a new Client Secret
- Copy the Client Secret value (shown only once)
- Note your Application (client) ID and Tenant ID
- Click "Connect Azure" below and paste the Client Secret
Compliance Checks Unlocked
Google Cloud (GCP)
Verifies Compute Engine firewall rules, IAM service account keys, and Cloud Logging retention configuration.
Prerequisites
- GCP project with Security Command Center enabled
- A Service Account with
Security Reviewerrole - Firewall logging enabled on your VPC networks
How to Connect
- Go to GCP Console → IAM & Admin → Service Accounts
- Create a new service account named "s-core-scanner"
- Grant roles:
Viewer+Security Reviewer - Click Keys → Add Key → Create new key → JSON
- Download the JSON key file
- Click "Connect GCP" and paste the JSON key contents
Compliance Checks Unlocked
GitHub Repositories
Validates branch protection rules, pull request review requirements, and scans for leaked secrets in code.
Prerequisites
- GitHub organization with admin access
- Branch protection enabled on main/master branches
- GitHub Advanced Security or Dependabot alerts active
How to Connect
- Go to GitHub → Settings → Developer settings → Fine-grained tokens
- Click Generate new token
- Set resource owner to your organization
- Select repository access: "All repositories" or specific repos
- Grant read-only permissions for:
Administration,Contents,Metadata - Click "Connect GitHub" and paste the token. Enter your org/repo name in the scope field.
Compliance Checks Unlocked
Vercel Deployments
Audits TLS/SSL certificate status, deployment edge headers, and automated domain redirect configurations.
Prerequisites
- Vercel account on Pro or Enterprise plan
- At least one active deployment with a custom domain
- Access to Vercel account settings for token generation
How to Connect
- Go to Vercel Dashboard → Settings → Tokens
- Click Create Token, give it a name like "S-Core Audit"
- Set scope to "Full Account" for complete audit coverage
- Copy the generated token (shown only once)
- Click "Connect Vercel" below and paste the token
Compliance Checks Unlocked
Okta Directory SSO
Maps employee identity records, enforces MFA policies, and verifies SSO login compliance across your organization.
Prerequisites
- Okta organization with Super Admin role access
- MFA policies configured in your Okta tenant
- API access management feature enabled
How to Connect
- Log in to Okta Admin Console → Security → API
- Click Tokens → Create Token
- Name it "S-Core Compliance" and click Create Token
- Copy the token value immediately (it won't be shown again)
- Click "Connect Okta" below and paste the token
Compliance Checks Unlocked
Google Workspace
Directory-wide 2-Step Verification enrollment, admin privilege hygiene, and stale account review via the Admin SDK.
Prerequisites
- Google Workspace Super Admin access
- A GCP project to create the service account in
- Domain-wide delegation enabled for the service account
How to Connect
- GCP Console → IAM & Admin → Service Accounts → create one, then Keys → Add key (JSON)
- Workspace Admin console → Security → API Controls → Domain-wide Delegation
- Authorize the service account's Client ID with scope admin.directory.user.readonly
- Click "Connect Google Workspace" below, paste the JSON key, and enter a super admin email to impersonate
Compliance Checks Unlocked
Penetration Testing
Automated, passive external security scan of your own public domain - security headers, TLS, exposed files, and email-spoofing protection, re-checked hourly.
Prerequisites
- A public domain you own or are explicitly authorized to test
- The domain must serve HTTPS on port 443
How to Connect
- Click "Run Pen Test" below
- Enter your domain as
https://yourdomain.com - S-Core runs a read-only, non-intrusive scan and re-checks it hourly
Compliance Checks Unlocked
Cloudflare
Verifies edge SSL/TLS mode, forced HTTPS, minimum TLS version, and security level on your Cloudflare zone.
Prerequisites
- A Cloudflare account with a zone (domain) added
- Permission to create API tokens on that account
How to Connect
- Cloudflare Dashboard → My Profile → API Tokens → Create Token
- Use the "Read" template, scoped to Zone Settings for your zone
- Copy the Zone ID from the zone's Overview page (right sidebar)
- Click "Connect Cloudflare" below and paste both
Compliance Checks Unlocked
Slack Workspace Security
Checks per-member 2FA enrollment and admin privilege hygiene across your Slack workspace. Different from Slack alerts (Settings) - this checks your workspace's own security.
Prerequisites
- Permission to create a Slack App on your workspace
- Workspace admin access to install the app
How to Connect
- api.slack.com/apps → Create New App → From scratch
- OAuth & Permissions → add Bot Token Scopes:
users:read,team:read - Install to Workspace, then copy the Bot User OAuth Token (
xoxb-...) - Click "Connect Slack" below and paste it
Compliance Checks Unlocked
PagerDuty
Verifies escalation policies are configured, someone is actually on call, and triggered incidents aren't sitting unacknowledged - live evidence your incident response actually operates.
Prerequisites
- A PagerDuty account with at least one escalation policy
- Permission to create a REST API key
How to Connect
- PagerDuty → Integrations → API Access Keys
- Create New API Key (read-only is enough)
- Click "Connect PagerDuty" below and paste it
Compliance Checks Unlocked
HRIS Roster (Deel/Bamboo)
Syncs employee records, verifies background checks, tracks MDM enrollment, and monitors security training completion.
Prerequisites
- Active Deel, BambooHR, or Rippling account
- Admin access to generate API/webhook credentials
- Employee roster with background check records
How to Connect
- In your HR platform, go to Settings → Integrations → API
- Generate a new API key or webhook secret
- Ensure read access to: employee directory, background checks, device status
- Click "Connect HRIS" below and paste the credential
Compliance Checks Unlocked
Policy Acceptances
Define operational rules and collect verification attestations from your staff.
Personnel & Workstation Auditing
Track background screenings, workstation device MDM enrollments, and safety training completions.
| Staff Roster Name | Device MDM Status | Background Screening | Trust Training | Status |
|---|
Evidence Documents
Upload manual reports, audit scans, or third-party certifications to satisfy compliance controls.
Select evidence files to upload
Drag and drop PDF, JSON, or CSV files here. Max 10MB.
Audit Trail
Timestamped evidence collected continuously from your integrations - the proof-over-time a SOC 2 Type II auditor samples across your observation window. Every hourly scan is recorded; control status changes and remediations are logged below.
Compliance Tasks
The recurring activities a SOC 2 / ISO program runs throughout the year - access reviews, vendor reviews, training, risk assessments. Complete each on its cadence; every completion is timestamped evidence for your auditor.
Vendor Risk
Track your third-party vendors and subprocessors, their risk, whether their SOC 2 / ISO report is on file, and whether you have a signed Data Processing Agreement with them. Auditors expect a maintained vendor inventory reviewed at least annually.
Answer a security questionnaire Enterprise plan
Received a vendor security review from a customer or prospect? Paste the questions and get a first draft, grounded only in your real connected evidence - frameworks, passing controls, policies, and vendors. Always review before sending.
Risk Register
The formal risk log SOC 2 and ISO 27001 both require: assets and threats, scored by likelihood and impact, with an owner and a treatment plan. Review and re-score at least quarterly - stale scores are one of the first things an auditor samples.
Framework Crosswalk Enterprise plan
Most controls are shared across frameworks - MFA, encryption, access reviews, and backups all count toward SOC 2, ISO 27001, HIPAA, and more at once. This shows how close you already are on frameworks you have not turned on yet, so you know which one to add next for the least extra work.
Trust Center Suite plan
Publish a shareable public page that shows prospects your live compliance posture - frameworks, security practices, and continuous-monitoring status. Send the link in sales conversations to close faster. Optional - most customers don't need this unless they field security questions from prospects often.
Auditor Portal Suite plan
Give an external auditor scoped, read-only access to your full evidence package - no S-Core account needed. Each link is a unique secret URL you can set to expire and revoke at any time.
- Your subscription monitors your controls continuously and keeps you "audit-ready" - this happens automatically, no action needed here.
- When you actually need an official signed SOC 2 / ISO 27001 report, request the Auditor Signature add-on (Reports panel, one-time fee, never recurring).
- We coordinate an independent, licensed CPA firm (or accredited body for ISO) to review your evidence and issue the opinion.
- Generate a link below and send it to that CPA firm - it gives them read-only access to everything they need to sign off, without creating them an account.
Activity Log
Who did what in your account - integrations connected, policies signed, vendors changed, auditor links issued, team members invited. Administrative accountability, separate from the automated SOC 2 evidence in your Audit Trail.
Security Awareness Training
Manage and review your organization's mandatory compliance training modules.
Security Awareness 101
General information security, password management, and physical security basics.
Phishing Defense
Identifying social engineering attacks, spoofed domains, and suspicious attachments.
Secure Coding Practices
OWASP Top 10, sanitizing inputs, and CI/CD security for engineering teams.
Team Training Seats
Invite team members to access these training videos. Each training seat is $15/user per month. This is separate from Team & Sub-Accounts in Settings, which controls who can manage your compliance workspace.
| Added | Actions |
|---|
Account Information
Manage your admin account details and workspace identity.
Profile Details
Plans & Billing
Manage your subscription. Upgrade to unlock additional frameworks, integrations, and team features.
- 1 compliance framework
- Up to 5 integrations
- Policy signature tracking
- Risk register & vendor tracking
- Basic report exports
- All compliance frameworks
- Unlimited integrations
- Sub-accounts & team roles
- Employee MDM verification
- AI Copilot, AI remediation & questionnaire drafting
- Framework crosswalk & Slack alerts
- Priority support
- Everything in Enterprise
- Dedicated compliance agent
- Custom control mappings
- Auditor portal access (for your signed-report engagement)
- Public Trust Center page
- SOC 1 + PCI DSS included
- Unlimited sub-accounts
Team & Sub-Accounts
Invite team members to collaborate on your compliance workspace and assign roles (Viewer, Auditor, Admin). This controls who can manage compliance. For training video access, use Team Training Seats in the Training section - that is billed separately per seat.
Team Members
| Role | Added | Actions |
|---|
Role Permissions
Compliance Frameworks
Add or remove compliance frameworks from your workspace. Active frameworks are continuously monitored and included in reports.
Active Frameworks
Click a framework to add it. Click the × to remove it from your workspace.
Notifications Enterprise plan
Send drift alerts and task reminders to a Slack channel, in addition to email.
Slack webhook
Create an Incoming Webhook at api.slack.com/apps for the channel you want alerts in, then paste the URL here.
Danger Zone
Irreversible actions that affect your entire workspace.
Delete Workspace
Permanently delete your compliance workspace, all connected integrations, policy signatures, team members, and audit history. This action cannot be undone.