Generate compliance reports for SOC 2, HIPAA, and similar
Surfaces used: dashboard compliance reports + audit retention Modes supported: Hosted Hybrid Tiers: Solo (basic) Teams (full retention + export)
What you'll do
Configure retention, pick a report template (SOC 2 CC-style, HIPAA-style, or custom), set a date range, and generate a packaged report containing the activity summary, policy inventory, incident log, and raw audit export. Hand to your auditor.
Why this is the right path for you
- If an auditor has asked "how do you control AI use of customer data?" and you need a document, not a conversation, this is the fastest path.
- The complete audit trail records every decision and its event-level coverage. It distinguishes did not run from ran and found nothing, giving an auditor evidence that a control executed rather than an unexplained absence of findings.
- If you do not yet have enforcement deployed, start there: gateway, browser extension, coding hooks, or an SDK.
When NOT to use this approach
caution
If you need a SOC 2 Type II report of Control Zero itself (the product), that is a separate artifact. Contact us. This use case is about generating a report of your AI activity, governed by Control Zero.
5-minute setup
- Dashboard -> Settings -> Retention. Audit log retention is an organization setting, not a project one: it defaults to 30 days today, and an owner can change it (1 to 2555 days). The plan windows -- 7 days on Free, 90 days on Solo, and 365 days on Teams -- are plan policy and are not applied yet. Automatic deletion of audit records at the end of the window is not currently running on the production audit store, so audit records are kept longer than the window; deletion will be switched on only after dated notice to affected organizations. When tiered retention takes effect, new organizations follow their plan's window and Free organizations created before then keep their existing 30-day window unless an owner changes it.
- Dashboard -> Compliance -> New report. Pick:
- Template: SOC 2-style, HIPAA-style, or Custom.
- Date range.
- Scope: all projects or selected.
- Click Generate. The report builds in seconds to minutes depending on volume, and produces:
- A signed PDF summary (controls, counts, top rules, top denies, top users).
- A CSV of every audit event in the range.
- A JSON manifest with a hash of each artifact for tamper-evidence.
- Click Download or Share via signed link to hand to your auditor.
Verifying it's working
-
Open the generated PDF. The summary page should list:
- Total requests governed in the window.
- Breakdown by surface (gateway, hooks, extension, SDK).
- Policy inventory with publish dates.
- Top-10 deny reasons.
- Incident log (any tamper alerts, quarantine events).
-
Spot-check the CSV: count of rows should match the summary.
-
Verify the manifest hash:
sha256sum compliance-report-2026-Q2.pdf# Compare to the hash printed in the manifest.json
Common follow-ups
- "I need longer retention" -> Contact us for extended retention on Teams.
- "I need to export events to my SIEM" -> pull the audit trail as ArcSight CEF or RFC 5424 syslog from the export endpoint, the formats Splunk, ArcSight, and QRadar ingest directly. Alert channels also ship individual events by webhook.
- "I want a dashboard of ongoing posture" -> Analytics, Coverage.
- "I need self-hosted retention" -> Self-Hosted.
Reference
- Surface page: Compliance reports
- Concepts: Policies, Pricing & tiers
- API: API reference