Compliance evidence capabilities
DRC can provide execution and analysis records that a customer may use as one input to an internal control process. It is not a certification, audit report, legal opinion, or guarantee that a deployment satisfies a framework.
Available primitives
- API-key and bearer-JWT authentication paths;
- tenant- and role-scoped authorization;
- audit metadata for state-changing operations;
- configurable redaction and bounded event payloads;
- transport and storage encryption configuration;
- retention, deletion, and legal-hold controls;
- authenticated web evidence workflows;
- health, readiness, and metrics endpoints.
Evidence workflow
Team/Enterprise users can issue evidence from the authenticated web workspace by selecting an authorized execution and policy/framework, reviewing the resulting analysis, and exporting the server-issued record. Access remains tenant- and role-scoped.
Customer configuration
Customers remain responsible for access reviews, retention, deletion, data residency, secret management, redaction policy, backups, incident response, and independent audit requirements. Keep raw execution data and evidence access-controlled.