SOC 2
- Vulnerability scan schedule (CC7.1)
- Finding lifecycle tracking (CC7.4)
- Change monitoring via scan diffs
- Incident detection via alert routing
- Access control via team RBAC
Scan continuously. Track remediation SLAs. Export audit-ready reports in five formats.
Metric Tower produces evidence that maps onto common control families. Your auditor decides how it fits your program.
The plumbing an auditor expects, built in from day one.
Per-severity SLA policies with breach alerts. Auditors see median time-to-fix and SLA pass rate per scan.
open -> triaged -> in progress -> fixed -> verified -> closed, plus accepted-risk and false-positive terminal states.
PDF for auditor handoffs, JSON for evidence archives, CSV for spreadsheets, SARIF for machine ingestion, Markdown for docs.
Plan-tier retention up to 365 days (Enterprise configurable). Every scan, finding change, and permission shift is captured.
Admin, analyst, viewer, and trainee roles enforced at middleware and query layers. Least-privilege by default.
Daily, weekly, monthly, or cron-expression-driven scans. Every run produces a fresh evidence artifact.
Compare any two scans to see which findings are new, fixed, or regressed. Regressed findings auto-reopen.
On-demand report aggregating team-wide security posture, grade, and trend -- suitable for board and exec review.
Scheduled weekly and monthly uptime PDFs with maintenance-window exclusions and per-check SLA pass/fail.
Metric Tower provides scanning and evidence tooling that supports compliance programs. It is not itself a compliance certification. Teams should pair Metric Tower with formal audit processes, auditor-reviewed controls, and legal counsel where required.
Create a free account, run your first scan, and export your first report in under ten minutes.