Compliance evidence
Audit evidence as a side effect of monitoring.
Auditors don't just ask whether you monitor your external infrastructure — they ask you to prove it operated all year. Bastion produces that proof by running: scheduled scans with full history, an alert trail, and dated PDF reports you hand over as-is instead of reconstructing the past the week before fieldwork.
No card required to start. Plans from $25/month; first scan in about a minute.
Where the evidence lands
SOC 2
The Common Criteria expect you to monitor infrastructure for vulnerabilities and configuration change (CC7.1) and to evaluate that monitoring (CC4.1). A year of scheduled scans, alerts and resolved findings is that control operating — across the whole period, not just the week before fieldwork.
ISO 27001
Annex A 8.8 asks how you manage technical vulnerabilities; A.5.7 asks where threat intelligence comes from. Scan history plus CT-log discovery and lookalike-domain watching answer both with dated records instead of a described process.
Security questionnaires
"Do you perform external vulnerability scanning?" — attach last week's PDF, with scope, findings, severities and date on the first page, instead of a paragraph the assessor takes on faith.
Point-in-time proof
Every scan is kept, and any of them exports as a branded, dated PDF. When an auditor asks what your posture was in March, you send March's report.
Why continuous beats point-in-time
The audit question is never "were you secure on scan day" — it's "does the control operate". A scanner you run before the audit produces one data point; a schedule produces a record.
History is the control
Scheduled scans, the changes they caught, and the findings that got resolved form a timeline. That timeline is what "monitoring operated effectively" looks like as evidence.
Alerts prove response, not just detection
The alert trail shows issues were surfaced when they happened — and the findings you accepted with a review date show risk decisions being made deliberately.
Honest scoping
Bastion is monitoring evidence for a handful of controls, not a compliance program. It does not replace a penetration test and is not a PCI ASV scan. It covers the "continuous external monitoring" row of the controls matrix — and covers it well. Control-by-control mapping →
The gap most programs have
Plenty of stacks have internal scanning and no external eye at all — the gap assessors increasingly ask about. Why external scanning is the missing row →
Common questions
Is Bastion itself SOC 2 certified?
Bastion produces evidence for your audit; it does not confer certification, and we don't claim its reports are a compliance program. For questions about Bastion's own security posture, ask us directly — support reaches a person.
Will auditors accept these reports?
Auditors accept evidence that a control operated: dated, scoped, and covering the period. Bastion's scan history and PDF exports are exactly that shape for external monitoring controls. Your auditor decides sufficiency — most treat continuous scanning with an alert trail as stronger evidence than an annual one-off.
Does this replace a penetration test?
No. A pentest is humans attempting exploitation at a point in time; Bastion is continuous passive observation. SOC 2 and ISO 27001 programs typically want both — they answer different questions.
Start the record now.
Evidence for the audit period starts accumulating with your first scheduled scan.
Start your 7-day trialNo card required to start. Cancel any time.