ComplianceView: Compliance monitoring
Real-time visibility into 98 security controls
ComplianceView is a continuous compliance monitoring platform for financial services. It provides real-time visibility into the status of 98 security controls aligned with NIST (National Institute of Standards and Technology) is the US federal agency within the Department of Commerce that publishes cybersecurity standards such as the Cybersecurity Framework and the SP 800 family. Banking and insurance adopt them as a control catalog; ComplianceView maps its controls to NIST SP 800-53r5.Read more → NIST SP 800-53r5, ISO 27001 (ISO/IEC 27001:2022) is the international standard from ISO and IEC with the requirements for an information security management system (ISMS) and its reference controls. An accredited body audits and certifies conformity, the evidence banking and insurance use to demonstrate risk control.Read more → ISO 27001:2022, DORA (Digital Operational Resilience Act) is Regulation (EU) 2022/2554 on digital operational resilience for the financial sector. It requires EU banks, insurers and investment firms to withstand ICT disruptions and threats, respond to them and recover. It has applied since 17 January 2025.Read more → DORA, and FINOS (Fintech Open Source Foundation) is the Linux Foundation umbrella organization that unites financial services to build open technology and standards. It hosts the Common Domain Model (CDM) and the SDLC Controls working group, whose controls ComplianceView integrates alongside NIST, ISO 27001 and DORA.Read more → FINOS SDLC Controls.
Proving continuous compliance to regulators
Financial organizations must demonstrate to regulators that they maintain active and continuously verified security controls. Manual audit processes and spreadsheets don't scale, produce false positives, and fail to provide real-time visibility into actual compliance status.
Automated evidence and zone-weighted scoring
Weighted scoring
Scoring engine weighted by security zone (External 1.4x, Infra 1.2x, SDLC 1.1x) with maturity bonuses.
11 automated collectors
Automatic verification against Gitea, GitHub, Trivy, GCP, Docker, Kubernetes, NATS, GitHub Actions, AWS, Azure and GitLab CI.
Built-in RBAC
Role-based access control (admin / auditor / viewer) over multi-tenant email and password login.
30-day trending
SVG sparkline tracking daily compliance score evolution.
Coverage radar
Interactive radar chart showing coverage across security zones.
Zero Trust is the security model NIST formalizes in SP 800-207: network location grants no implicit trust, and every access is authenticated and authorized separately. In banking and insurance it limits lateral movement after a credential is stolen; BlueUP applies it with per-service cryptographic identity.Read more → Zero Trust native
Accessible as a dark service on the NetFoundry is the company that created and maintains OpenZiti, the open-source Zero Trust connectivity substrate, and counts Cisco Investments among its investors. A regulated entity uses it to keep services off the public internet. BlueUP is an official partner offering self-hosted deployment or managed connectivity.Read more → NetFoundry overlay (no internet exposure).
See the platform in action

Live Demo
The video showcases the interactive dashboard, automated collector execution, coverage radar, and audit timeline.
Each role sees the evidence it needs
Compliance officers
Monitor compliance status and generate regulatory reports.
CISOs
Gain executive visibility into security posture with weighted scoring.
IT security
Run automated collectors and manage technical evidence.
External auditors
Access the public Trust Center and export PDF/JSON/CSV reports.
From verified control to the auditor's report
- Interactive Dashboard — Weighted score ring chart, real-time stats, 30-day sparkline, and zone coverage radar
- 98 Unified Controls — Cybersecurity Framework (84) + FINOS SDLC³ (12) + DORA (2), cross-mapped to NIST, ISO 27001, and DORA
- 11 Automated Collectors — Gitea (branches, PRs, webhooks), GitHub, Trivy (CVEs, SBOM), GCP (IAM, KMS, audit), Docker (root, secrets), Kubernetes (RBAC, network policies), NATS (mTLS, auth), GitHub Actions, AWS, Azure and GitLab CI
- Scheduling + Alerts — Configurable scheduling (6h/12h/24h/weekly) with notifications to Slack, Discord, and Microsoft Teams
- Audit Timeline — Immutable record of every status change with attached evidence
- Trust Center — Public transparency page with real-time control status
- Multi-format Export — Professional PDF, structured JSON, and CSV for auditors
What compliance looks like on screen




Standard components, access over a Zero Trust overlay
| Layer | Technology |
|---|---|
| Frontend | React 19, Vite 8, Dark Glassmorphism CSS |
| Backend | Express 5, SQLite, node-cron |
| Auth | Multi-tenant email and password (HS256 JWT); Keycloak JWKS validation on the backend |
| Infrastructure | Docker, Gitea Actions CI/CD |
| Zero Trust | NetFoundry overlay (dark service) |
Declared limits
This list states what ComplianceView does not do yet, or does only in part, with the status of each piece according to its source repository.
- Sign-in: the interface login is multi-tenant email and password with HS256 JWTs, and it is the operational mode; Keycloak OIDC token validation is experimental and backend-only: the API validates RS256 via JWKS and accepts machine-to-machine calls with an externally obtained token, and the frontend implements no PKCE/callback flow against Keycloak, so that mode does not serve as the interface login.
- Deployment: the container deployment is declared in GitOps and reconciled by FluxCD in the bc-workload cluster; the Cloud Run variant is documented as a go-live runbook and has not been executed.
- High availability: the service runs on a single instance because persistence is local single-writer SQLite: there are no replicas and no horizontal scaling, and a deployment or a restart means downtime. The storage backend that removes that ceiling (managed libSQL) is evaluated and on the roadmap.
- Automated evidence: each collector requires its runtime dependency available and authenticated (Gitea API token, authenticated gcloud CLI, kubectl with an active cluster, a running Docker daemon, Trivy reports on disk, NATS monitor on :8222); without it that control has no automated verification.
- Regulatory frameworks: the catalog provides its own controls for the Cybersecurity Framework and FINOS SDLC³; NIST SP 800-53r5 and ISO 27001:2022 come in as reference mappings on those controls, not as imported catalogs.
- Audit retention: the evidence access log is purged after 90 days and billing events after 365; extending that window requires changing the retention configuration.
Regulatory compliance
DORA, NIST SP 800-53r5, ISO 27001:2022, and FINOS SDLC³ — full regulatory coverage. → View compliance
Request a Demo
Personalized 30-minute session for your organization. → Request demo
Platform fit
ComplianceView is the platform's evidence surface: it consumes no service from the other products and exposes its own HTTP API. The platform architecture lays out the three layers and their order.
What it receives. From the FINOS SDLC Controls catalog, the controls it integrates into its registry; that is its only declared dependency. From the other products in the portfolio, nothing: it subscribes to no NATS subject, and each automated collector depends on the runtime dependency of the system it audits (a credential, an authenticated CLI or a report on disk, among others), not on another product (see "Declared limits").
What it delivers. An HTTP API with the controls registry, the evidence store, the dashboard, the collectors and OSCAL export (/api/controls, /api/evidence*, /api/dashboard*, /api/collectors*, /api/export/oscal*). The other compliance product in the portfolio is BlueUPALM (AML/DORA), which covers the AML cycle and DORA incident management.
Talk to our team
Continuous control monitoring is best evaluated on the platform itself.