Compliance · every cloud · continuous

One audit.
Every cloud already covered.

Every cloud has its own console, its own drift, its own auditor screenshots. OnDuty maps CIS, PCI DSS, SOC 2, ISO 27001, HIPAA and NIST 800-53 to live resource state across AWS, Azure, GCP and OCI — so evidence is always current, not quarterly.

Six capabilities, one platform

Compliance, mapped
once. Proven always.

Capability / 01

Unified multi-cloud control mapping

Every control in every framework mapped once, then evaluated continuously across AWS, Azure, GCP and OCI resources.

  • Single control library
  • Cross-cloud normalization
  • No per-cloud rework
Capability / 02

20+ built-in frameworks

CIS Benchmarks, PCI DSS, SOC 2, ISO 27001, HIPAA, NIST 800-53, GDPR and more — ready on day one.

  • Framework crosswalks
  • Custom control packs
  • Shared-control dedupe
Capability / 03

Continuous evidence collection

Every control check produces timestamped, exportable evidence — automatically, not once a quarter before an audit.

  • Point-in-time snapshots
  • Auditor-ready exports
  • Evidence retention policies
Capability / 04

Risk-weighted control scoring

Failing controls are ranked by real exposure and blast radius, so teams fix what actually threatens the audit outcome first.

  • Exposure-weighted scoring
  • Toxic combination detection
  • Executive scorecards
Capability / 05

Ownership & accountability

Every failing control routes to the team and resource owner responsible — with SLAs tracked to closure.

  • Auto-routing by tag
  • SLA tracking
  • Jira & ServiceNow sync
Capability / 06

Audit-day readiness

Generate a full evidence package for any framework, any date range, in minutes — not the week before the audit.

  • One-click evidence export
  • Historical compliance trend
  • Auditor collaboration view

How the platform works

From spreadsheet chaos
to always-audit-ready.

Unified control plane

One control library, every cloud.

Stop maintaining a separate SOC 2 workbook for AWS, another for Azure and a third for GCP. OnDuty maps every control once and evaluates it continuously against live resource state — the same rule, the same result, on every hyperscaler.

Single control libraryCross-cloud normalizationNo per-cloud rework
AWS
Azure
GCP
OCI

Map once

One control library

Continuous evidence

Timestamped proof, not quarterly screenshots.

Every control check produces exportable evidence with a timestamp, cloud, resource and framework citation — automatically. Auditors get proof, not a promise, and your team stops burning weeks on the screenshot marathon before every audit.

Auto-collected each checkAuditor-ready exportsRetention policies built in

Evidence stream · today

LIVE · timestamped
14:02CIS 1.4 — MFA on rootpass
14:02PCI DSS 3.4 — RDS encryptionpass
14:03SOC 2 CC7.2 — CloudTrail retention 90dfail
14:03ISO 27001 A.9.4 — Privileged access reviewpass
14:04HIPAA §164.312 — At-rest encryptionpass

Auditor package generated · 12,438 evidence items

SOC 2 Type II · 01 Jan → 30 Jun · one click

Risk-weighted scoring

Fix what threatens the audit, first.

Not every failing control is equal. OnDuty scores failures by real exposure, data sensitivity and blast radius — so the internet-facing bucket with PCI data outranks a dev sandbox missing a tag. Your team fixes what auditors will actually flag.

Exposure-weighted scoringToxic combinationsExecutive scorecards

Ranked by audit blast radius

audit-blocking · fix first
Internet-exposed + PCI data94
Privileged access without MFA82
Weak encryption on prod store71
Missing tag on dev sandbox14

Public S3 with cardholder data · PCI DSS 3.4

Top of 847 open controls · fixes 3 frameworks

Ownership & SLAs

Route every failing control to its owner.

OnDuty ties each failing control to a resource, an owner and an SLA — then syncs it to Jira or ServiceNow. Compliance stops being a spreadsheet passed between teams and becomes a tracked ticket with a deadline.

Auto-routing by tagSLA tracking to closureJira & ServiceNow sync

CloudTrail retention < 90d

SOC 2 CC7.2 · cloudtrail://audit

Routed by tag

team:platform · owner: @alice

Jira ticket opened

PLAT-4218 · SLA 72h

Control passing

Retention 90d applied · evidence attached

OnDuty AI

AI that drafts the fix and the evidence.

OnDuty AI closes the loop between a failing control and a passing one. Ask which controls a change breaks and get an answer, not a query. Let AI draft the Terraform fix, generate the auditor narrative or map a custom control — so your team spends time on judgment, not paperwork.

AI remediation draftsAI evidence narrativesAI control mapping

AI Remediation

Terraform & policy fixes for failing controls

AI Discovery

Ask which changes break which controls

AI Evidence Narrative

Auditor-ready write-ups, generated

AI Control Mapping

Map custom controls across frameworks

The compliance lifecycle

From control mapping
to audit-ready.

Phase / 01

Map

Map every control across CIS, PCI, SOC 2, ISO, HIPAA and NIST to live resources, once.

Phase / 02

Evaluate

Continuously evaluate control status across AWS, Azure, GCP and OCI — no manual checks.

Phase / 03

Prioritize

Rank failing controls by exposure and blast radius so teams fix what matters to the audit.

Phase / 04

Prove

Export timestamped, audit-ready evidence for any framework and date range in minutes.

FAQ

Frequently asked questions.

Multi-cloud compliance is the discipline of proving that resources across every cloud you use — AWS, Azure, GCP, OCI — meet the same set of regulatory and framework controls (CIS, PCI DSS, SOC 2, ISO 27001, HIPAA, NIST 800-53 and more). Instead of running a separate audit workflow per cloud, you map controls once and evaluate them continuously against live resource state.

Retire the screenshot marathon

See every control,
across every cloud.

See your real compliance posture, failing controls and auditor-ready evidence in a 30-min guided demo with our team.

  • One control library across AWS, Azure, GCP & OCI
  • 20+ built-in frameworks — CIS, PCI, SOC 2, ISO, HIPAA, NIST
  • Continuous, timestamped evidence — no quarterly screenshots
  • Risk-weighted scoring focuses fixes on audit blast radius
  • One-click auditor exports for any framework, any date range