Compliance

Evidence your
auditor accepts.

Every pentest produces a signed, timestamped report, pre-mapped to the controls your auditor asks about. The compliance paperwork, done for you.

Start a pentest

Free to set up. Pay only when you run.

An ink fingerprint pressed into cream paper, dissolving into long streaks. A signed, tamper-evident seal.

What you get

Evidence,
not a checkbox.

Auditors want proof the test was real. Every run gives them:

  • A signed letter for every run, with the scope, dates, and outcome.
  • Every finding proven with a real attack they can re-run.
  • Each one mapped to the exact SOC 2, HIPAA, PCI, or ISO control.
  • All of it pushed into Vanta, Drata, or Secureframe automatically.
A lone figure walking a vast curved concrete structure, lit from one side. The paper trail, walked end to end.

After the run

One run,
every document.

When the pentest finishes and every finding is triaged, the evidence pack builds itself: a signed file per framework, mapped to the control and ready to file.

A HackZero compliance evidence pack produced after a pentest: a signed, timestamped report for SOC 2, HIPAA, PCI-DSS, and ISO 27001, each mapped to the exact control your auditor files against, plus a cryptographically signed attestation letter, pushed to Vanta, Drata, and Secureframe.

Frameworks

Mapped to the
frameworks you file.

Each report is formatted to what that framework's auditor expects:

  • SOC 2 Type II: a signed attestation per run, mapped to CC4.1 and CC7.1.
  • PCI-DSS 4.0: formatted to the Req 11.4 scope and evidence expectations.
  • HIPAA Security Rule: documents your technical evaluation under 164.308(a)(8).
  • ISO 27001:2022: per-build security testing evidence for A.8.29.

For tests the law requires a human to run, like DORA TLPT or CBEST, we give you continuous coverage between those engagements, not a replacement.

A heavy door ajar with a key in the lock, light spilling through the gap.
Sample report · 16 pages
Pages from a HackZero pentest report: an executive summary with a severity donut, the compliance scope, and two CRITICAL findings with reproduction steps.

Read the full report.

Redacted real engagement · no sales call

Frequently asked

Questions.

Often yes. Auditors accept it as evidence of regular penetration testing, and we map every finding to the control, so there is nothing for you to translate. Confirm the scope with your auditor.

SOC 2 Type II, PCI-DSS 4.0, HIPAA, and ISO 27001:2022. Each report is formatted to that framework's evidence expectations, with the control IDs already filled in.

Yes. Every attestation letter is cryptographically signed and timestamped, and carries a fingerprint your auditor can use to confirm nothing was changed after the fact.

For tests the law requires a human to run, like DORA TLPT or CBEST, no. We give you continuous coverage between those engagements, so you are never months out of date.

Yes. The evidence pushes straight into Vanta, Drata, or Secureframe, so your auditor finds it where they already look.