The latest release ships enterprise governance, compliance automation, and identity management capabilities — giving security teams what they need to pass audits, not just run scans.
🔐
Enterprise RBAC — Three-Tier Access Control
Admin, Security Analyst, and Viewer roles enforced at the API level. Fine-grained permissions gate scans, findings governance, compliance snapshots, admin operations, and cloud posture ingestion.
📋
Compliance Reports — 10 Frameworks
Automated compliance snapshots for ISO 27001, SOC 2, NIST 800-53, PCI DSS, HIPAA, DORA, NIS2, HITRUST, ENS, and GDPR. Point-in-time evidence for auditors, always up to date.
📊
Enterprise Metrics & SLA Tracking
Finding trends over 8 ISO weeks, SLA compliance by severity (Critical 7d / High 30d / Medium 90d / Low 180d), severity distribution, cloud posture by provider, and per-framework compliance coverage — all via a single API.
🏢
SSO/SAML 2.0 + SCIM Directory Sync
SP-initiated SAML 2.0 with JIT user provisioning. Full SCIM 2.0 protocol (Users + Groups) with PATCH, DELETE, pagination, and filter — compatible with Okta, Azure AD, and any RFC 7644-compliant IdP.
☁️
Cloud Drift Detection
Ingest Prowler v3 findings from CI/CD pipelines or cloud workers. Track cloud posture findings (pass/open/suppressed) per provider, account, region, and asset — and compare live state against your IaC baseline.
📜
Immutable Audit Logs
Every action — scans, sign-ins, team changes, finding updates, compliance snapshots — is recorded with timestamp, user, IP, and outcome. Exportable audit trail for SOC 2 and ISO 27001 evidence packages.
🎯
Finding Governance Workflow
Assign findings to team members, set SLA targets by severity, track remediation status across sprints, and escalate overdue items. Governance overlays surface SLA breach risk before it becomes an audit finding.
📅
Scheduled & Automated Scans
Schedule recurring scans across your asset inventory — daily, weekly, or custom cadence. Pair with cloud posture workers for continuous drift visibility without manual trigger.
✦
AI Autofix — Business & Enterprise
One click generates a step-by-step fix plan for any finding: ordered remediation steps, a corrected code snippet, and OWASP/CWE references — all tailored to the specific vulnerability. Your team reviews and applies; no code changes happen automatically.