Vornin
Start Free
For compliance teams · DORA + NIS2

Audit-ready,
by default.

DORA Article 5, NIS2 Article 21, ISO 27001 Annex A — controls mapped at scan time. Evidence chain hashed per finding. Auditor pack on demand.

The Problem

Auditors want evidence.

Proof that you're scanning. Proof that you're tracking remediation. Proof that you're meeting SLAs — and proof the records weren't massaged after the fact. Pulling this data from multiple tools into audit-ready format eats days every audit cycle. Doing it under DORA / NIS2 timelines makes it worse.

The Fix

Nine frameworks, one map.

Every finding in Vornin auto-links to the controls it impacts across all nine frameworks at scan time. Compliance scores update live. Auditor pack exports include a chain-verification manifest.

§ 01Mapping

Automatic framework mapping.

Every vulnerability is auto-linked to relevant controls across DORA (EU 2022/2554), NIS2 (EU 2022/2555), ISO 27001:2022, SOC 2 Type II, PCI DSS 4.0, HIPAA Security Rule, GDPR, NIST 800-53 Rev 5, and CIS Controls v8.

§ 02Scoring

Live compliance scores + 90-day trend.

Per-framework coverage % updates as findings are opened and closed. Daily snapshots build a 90-day score chart for every selected framework.

§ 03Reporting

Per-finding auditor ZIP.

Download a ZIP per finding: manifest.json with chain verification, state.json, events.json, comments, compliance mappings, evidence files, attestation evidence, and a README with the canonicalization recipe.

§ 04SLA

SLA evidence.

SLA policies prove you're meeting remediation deadlines. Historical MTTR per severity and SLA compliance charts feed straight into audit narratives.

§ 05Trail

Full audit log.

Every action logged: scans run, findings acknowledged, assignments made, rules created. Give auditors read-only access or export.

§ 06Import

Bring your own scans.

Import Nessus / OpenVAS / CSV / JSON to fold external scans into the same compliance pipeline and the same evidence chain. One system of record.

§ 07Export

Mappings as CSV or JSON.

Auditors live in spreadsheets. Every framework page exports a control-by-control table with status, open-finding count, and the actual finding titles — CSV or JSON, on demand at /api/compliance/{slug}/mappings.csv.

§ 08Honest

Honest scoring + coverage gaps.

Governance, training, third-party, and BCP controls are excluded from the score denominator and shown separately as “manual attestation required”. The framework page also surfaces every scan type you haven’t run yet plus the controls it would cover — so you know exactly what your score is missing.

Regulatory Coverage

DORA, NIS2, and seven more — pre-mapped.

Compliance mapping isn't a side feature — it's the wedge. Mapping is a single source of truth (ComplianceMappingRules) consumed by both the scan-time tracker and the per-framework UI block, so what you see in your evidence pack is what was actually applied at write-time.

§ 01EU · NEW

DORA — EU 2022/2554

Digital Operational Resilience Act. Articles on ICT risk management, incident classification, resilience testing, and third-party risk. Map your scanner findings to the right articles before an auditor asks. Read the Article 5 walkthrough →

§ 02EU · NEW

NIS2 — EU 2022/2555

Network and Information Security Directive 2. Article 21 risk-management measures spanning asset management, supply-chain security, encryption, and incident handling — mapped to scanner controls and SLA evidence. Read the Article 21 walkthrough →

§ 03ISO

ISO 27001:2022

Annex A controls (A.5 Organisational, A.6 People, A.7 Physical, A.8 Technological) cross-walked to scan types.

§ 04SOC

SOC 2 Type II

Trust Services Criteria mapped to scanner output. Useful for software vendors approaching first audit, often paired with ISO 27001.

§ 05PCI

PCI DSS 4.0

Requirements 6 (secure development) and 11 (testing) cross-mapped to web, code, and infra scanner findings.

§ 06HIPAA

HIPAA Security Rule

Administrative, Physical, and Technical safeguards mapped to vulnerability lifecycle and SLA evidence.

§ 07GDPR

GDPR (2016/679)

Articles 32 (security of processing) and 33 (breach notification) mapped to severity and SLA enforcement.

§ 08NIST

NIST 800-53 Rev 5

Control families RA, SI, CM cross-walked. Useful for federal-adjacent and US-export buyers.

§ 09CIS

CIS Controls v8

153 controls including IG1 / IG2 / IG3 baselines. Available on every tier as the compliance preview.

DORA
DORA
EU 2022/2554
NIS2
NIS2
EU 2022/2555
ISO
ISO 27001
2022 Annex A
SOC
SOC 2
Type II · TSC
PCI
PCI DSS
v4.0
HIPAA
HIPAA
Security Rule
GDPR
GDPR
Art. 32 · 33
NIST
NIST 800-53
Rev 5
CIS
CIS Controls
v8 · 153 controls
Tamper-Evidence

An evidence chain auditors can verify themselves.

A spreadsheet of scan results doesn't survive an auditor's "are you sure these weren't edited last night?" question. A cryptographic per-tenant chain does. On Business, every status change is hashed into a tamper-evident ledger, and the auditor pack ships with the verification result baked in. The same evidence layer your NIS2, DORA, or ISO 27001 assessor expects.

§ 01Chain

Per-tenant SHA-256 chain.

Every status change — UI, API, or background — writes a VulnerabilityEvent row. Each row carries Hash and PreviousHash. Tampering with one event invalidates every later one.

§ 02Lock

Advisory-locked transactions.

Each save takes pg_advisory_xact_lock(tenantId) before stamping. Concurrent writers serialize per tenant, so the chain stays linear — no fork, no race.

§ 03Time

Microsecond-truncated timestamps.

.NET ticks (100ns) get truncated to Postgres microsecond precision before hashing, so canonical hashes round-trip exactly across read and write.

§ 04Verify

Walk + verify on demand.

The verification service walks a tenant's events, recomputes hashes, and returns the first break. The result is included in every auditor-pack manifest so an auditor can re-run the calculation themselves.

§ 05Pack

Per-finding ZIP, tenant-wide PDF.

From any finding, download a ZIP containing manifest, state, events, comments, mappings, evidence, attestation evidence, and a canonicalization README. Business also renders a tenant-wide PDF rolling every chain into one auditor document.

§ 06Roadmap

External anchor.

Today the chain is self-anchored to Vornin (still tamper-evident inside your tenant). Roadmap: stamp tip-hashes into RFC 3161 timestamp authorities and a public transparency log so even Vornin can't rewrite history.

Business and above: tamper-evidence chain, per-finding auditor ZIP, and tenant-wide auditor PDF. Built for buyers under NIS2, DORA, and ISO 27001 audit pressure.

Get started

Be audit-ready,
always.

Free includes CIS Controls as a preview so you can see the mapping UX. Team unlocks all nine frameworks and the attestation workflow. Business adds the tamper-evidence chain, the per-finding auditor pack ZIP, and the tenant-wide auditor PDF.