Compliance
Igris generates compliance artifacts populated from your actual audit events — not templates filled with placeholder data. This gives auditors and regulators evidence backed by real system behavior.Supported Frameworks
HIPAA BAA
Generate Business Associate Agreements as PDF with digital signature workflow.
SOC 2 Evidence
Export evidence mapped to Trust Services Criteria with Type II validation.
Plan Gating
Compliance features are available on higher-tier plans:| Feature | Free | Govern ($49) | Comply ($199) | Enterprise ($499) |
|---|---|---|---|---|
| HIPAA BAA Generation | — | — | Yes | Yes |
| SOC 2 Evidence Export | — | — | Yes | Yes |
| Custom Compliance Reports | — | — | — | Yes |
How It Works
- Audit events accumulate — every proxy tool call and ingested log is stored in the unified
audit_eventstable - Compliance engine queries — when you generate an artifact, Igris queries the relevant events for your date range
- Auto-population — fields like “number of access controls enforced”, “denied requests”, and “processing activities” are filled from real data
- Validation — for SOC 2, Igris validates Type II requirements (90-day minimum observation period)
- Export — download as PDF (BAA), CSV/JSON (SOC 2 evidence), or view in the dashboard