Solutions · Compliance & Regulatory

Every certificate control, audit-ready by default.

PCI-DSS, SOC 2, HIPAA, ISO 27001, GDPR — all of them care how you manage keys and certificates. TigerTrust captures the evidence continuously and generates the reports your auditors ask for.

The problem

Audit season is a screenshot marathon.

Compliance teams spend weeks chasing spreadsheets, exporting CSVs from three CAs, and negotiating with infra teams for evidence. One missing renewal record and the auditor writes a finding.

Without automated evidence
  • Auditors ask for six months of rotation logs; ops has three sources of truth
  • Weak algorithms and short RSA keys keep slipping into production undetected
  • No cryptographic signature on your audit trail — a determined insider can rewrite it
  • Policy drift between business units invalidates a single compliance narrative
  • Findings on cryptographic controls delay attestation letters and block sales
With TigerTrust compliance evidence
  • Immutable, cryptographically signed audit logs across every issuance and revocation
  • Policy engine blocks non-compliant certificates before they reach production
  • One-click evidence packs per framework (PCI, SOC 2, HIPAA, ISO 27001, GDPR)
  • 7-year default retention aligned to SOX, HIPAA, and PCI record-keeping requirements
  • Control mapping straight to the audit workpaper — no manual crosswalks
Audit evidence

Continuous, tamper-evident audit trail

Every certificate action — request, approval, issuance, deployment, revocation — recorded with actor, source IP, and cryptographic chain. Nothing can be quietly modified.

How it works
  • Signed hash-chained log records
  • Actor, timestamp, source IP, session
  • 7-year retention (configurable to 10+)
  • Export to SIEM, S3, or long-term archive
Compliance auditor reviewing detailed evidence records
Policy enforcement

Non-compliant certificates never issue

Central policy engine enforces algorithm strength, validity limits, name constraints, and approved CA lists. Violations are blocked at request time, not caught at audit time.

How it works
  • Minimum key length and algorithm allow-lists
  • Maximum validity windows per certificate class
  • Name and SAN constraints per issuer
  • Per-tenant policy inheritance
Policy engine dashboard showing enforcement rules
Reporting

Auditor-ready reports in minutes

Generate a PCI-DSS 4.0 pack, a SOC 2 CC6 evidence bundle, or an ISO 27001 A.8.24 report on demand. Each report is signed, timestamped, and mapped to specific control language.

How it works
  • PCI-DSS, SOC 2, HIPAA, ISO 27001, GDPR presets
  • Custom framework builder
  • Signed, timestamped PDF exports
  • Direct auditor share links with expiry
Team preparing a compliance report package
Continuous monitoring

Compliance posture, live

A dashboard that answers the auditor's question before they ask it: what percent of your inventory meets policy right now, and what needs remediation?

How it works
  • Real-time compliance scorecard
  • Drift detection per business unit
  • Slack / PagerDuty alerts on regressions
  • Executive report scheduling
Compliance monitoring dashboard displaying live posture
Framework coverage

Every framework your auditor cares about, pre-mapped.

Stop building crosswalks by hand. TigerTrust ships with control mappings for the frameworks that touch cryptographic controls.

PCI-DSS 4.0
Requirements 3.5, 3.6, 4.1, 4.2, and 6 for strong crypto and TLS.
  • Quarterly reports
  • ASV-ready evidence
  • Level 1 tested
SOC 2 Type II
CC6.1, CC6.6, CC6.7, CC7 trust service criteria mapped.
  • Observation window evidence
  • Exception tracking
  • Auditor share links
HIPAA Security Rule
§164.312 technical safeguards for PHI in transit and at rest.
  • BAA-ready deployments
  • PHI-scoped audit logs
  • Encryption reports
ISO 27001
A.5.31, A.8.24 cryptography controls and key management.
  • Annex A mapping
  • SoA support
  • Surveillance-audit ready
NIST 800-53 / FedRAMP
SC-12 key management and SC-17 PKI certificates coverage.
  • Moderate/High baseline
  • FedRAMP artefacts
  • CMMC 2.0 aligned
GDPR Article 32
Technical measures for encryption and pseudonymisation.
  • Data residency
  • Cross-border tracking
  • DPO reports

From customer audits

100%
Audit pass rate on crypto controls
80%
Reduction in evidence prep time
5 min
Time to generate a framework report
7 yrs
Default log retention

Mapped to the control language auditors use.

Selected cryptographic controls across the five most-common frameworks and the TigerTrust capability that covers each.

ControlRequirementTigerTrust Capability
SOC 2 CC6.1Logical access controls restrict access to authorised users, systems, and data.RBAC on issuers, keys, and templates; SSO/MFA-enforced approval workflows.
SOC 2 CC6.6Restrict transmission and movement of information to authorised systems.Enforced mTLS via issuance policy; disallow weak ciphers at the CA layer.
SOC 2 CC6.7Encrypt data in transit using approved cryptographic methods.Algorithm allow-lists (RSA-2048+, ECDSA P-256+); TLS 1.2+ certificates only.
ISO 27001 A.5.31Legal, statutory, regulatory, and contractual requirements are identified and documented.Region-scoped policy sets; residency-aware issuance; regulator-facing reports.
ISO 27001 A.8.24Rules for the effective use of cryptography, including key management, are defined and implemented.HSM-backed key generation, custody, rotation, and revocation with full lineage.
PCI-DSS 4.0 Req 4Protect cardholder data with strong cryptography during transmission over open networks.TLS 1.2/1.3 enforced; weak cipher blocklist; discovery of legacy endpoints.
PCI-DSS 4.0 Req 6Develop and maintain secure systems and software; manage vulnerabilities.Certificate inventory tied to CVEs (Debian OpenSSL, ROCA, etc.) with auto-rotation.
HIPAA §164.312(a)(2)(iv)Implement a mechanism to encrypt and decrypt electronic protected health information.PHI-scoped issuance profiles, mandatory HSM key storage, BAA-covered ops.
HIPAA §164.312(e)(1)Implement technical security measures to guard against unauthorised access to ePHI during transmission.mTLS between clinical systems; automated rotation without transmission gaps.
GDPR Article 32Implement appropriate technical measures, including encryption of personal data.Residency-aware CAs, pseudonymisation-ready certificates, DPO evidence packs.
Case study
Multinational · Regulated industry

Audit prep cut from six weeks to one afternoon.

PCI, SOC 2, ISO 27001 — three frameworks, three auditors, one evidence pipeline. We stopped screenshotting spreadsheets and started closing findings.
Director of GRC
80%
Less evidence prep time
5 min
To generate a framework report
0
Findings on crypto controls
Integrations

Fits your existing stack

Ships evidence into the SIEM, GRC, and ticketing tools your compliance team already runs on.

Splunk
SIEM
Datadog
SIEM
IBM QRadar
SIEM
ArcSight
SIEM
ServiceNow
GRC / ITSM
Jira
Ticketing
Archer
GRC
OneTrust
GRC
Vanta
GRC
Drata
GRC
Kyverno
Policy
OPA
Policy
FAQ

Frequently asked questions

Out of the box: PCI-DSS 4.0, SOC 2 Type II, HIPAA Security Rule, ISO 27001:2022 (including A.5.31 and A.8.24), NIST 800-53 / FedRAMP Moderate & High, CMMC 2.0, GDPR Article 32, and HITRUST CSF. The mapping engine is extensible — you can add a custom framework or overlay by declaring controls and the TigerTrust capability that covers each, then reports render straight to the auditor workpaper format.
Every action — request, approval, issuance, deployment, revocation — is written as a signed, hash-chained log record. Each record includes actor, timestamp, source IP, and session identifier and hashes the previous record. A determined insider cannot rewrite history without breaking the chain. Records export to S3, SIEM, or long-term archive with the chain verifiable at any point.
Yes. Tenants inherit central policy but can be scoped tighter — one BU may require ECDSA P-384 while another operates on RSA-3072, one may require HSM key custody while another allows software keys. Policy inheritance is layered so central compliance retains guardrails while local teams retain autonomy. Every override is logged with justification.
CC6.1 (logical access) is covered by RBAC on issuers and templates plus SSO/MFA-enforced approval workflows. CC6.6 (secure transmission) maps to enforced mTLS policy and cipher blocklists. CC6.7 (encryption in transit) maps to algorithm allow-lists (RSA-2048+, ECDSA P-256+) and TLS 1.2+ policy. Observation-window evidence exports as a signed PDF with control cross-references.
Region-pinned deployments keep issuance, keys, and audit logs in the EU. Cross-border data flows are tracked with lineage so the DPO can attest to Article 32 requirements and Schrems II obligations. Regional CAs support sovereign cloud deployments (AWS Frankfurt, Azure Germany, and equivalent).
7 years by default — aligned to SOX and HIPAA record-keeping. Configurable up to 10+ years with tiered storage: hot in Postgres for recent queries, warm in S3, cold in Glacier or equivalent. Retention rules can be scoped per tenant or per control family so PCI logs age separately from GDPR logs.

Turn audit season into a status meeting.