Compliance
TurboPentest maps your pentests to the compliance frameworks auditors ask about, tracks whether your evidence is still fresh, and exports an auditor-ready evidence package on demand.
Supported frameworks
| Framework | Default max age |
|---|---|
| SOC 2 | 365 days |
| PCI-DSS | 365 days |
| HIPAA | 365 days |
| ISO 27001 | 365 days |
Each framework has a default max-age of 365 days - the window after which its evidence is considered stale. You can override the cadence per framework.
Compliance dashboard
The dashboard gives you a per-framework view of where you stand:
- Scope - whether an asset or target is
in_scope,connected_to, orout_of_scopefor the framework - Staleness state -
fresh,stale, ornever_tested, evaluated against the framework's max-age - Last scan date and total scan count
- Next scheduled scan - the upcoming recurring pentest that will refresh evidence
- Control mappings - findings and coverage mapped to framework controls (for example ISO 27001:2022 Annex A, PCI-DSS, HIPAA §164.312, and SOC 2)
- Per-framework and per-cadence overrides - tune the max-age and scope defaults for your environment
An asset is fresh when it has been tested within the framework's max-age window, stale once that window lapses, and never_tested if no in-scope pentest has run yet.
Evidence package export
Export a complete evidence package as a ZIP for your auditor. The package contains:
manifest- contents and metadata for the packageassets.csv- the in-scope assetsmapping.json- control-to-finding mappingsoverride-history- a record of framework and cadence overridesscan-history- past pentests and their outcomesscheduled-scans- the recurring scans that keep evidence currentmethodology.md- the testing methodology
CSV output is auditor-safe (formatted to avoid CSV injection and other spreadsheet hazards), so the package can be handed off as-is.
Keeping evidence fresh
Compliance evidence goes stale the moment it ages past a framework's max-age. Two features keep it current:
- Verified assets - cloud-verified and domain-verified assets define your in-scope attack surface so coverage is measured against the real targets.
- Scheduled recurring pentests - schedule scans (daily, weekly, biweekly, monthly, or quarterly) so evidence is refreshed automatically before it expires. The dashboard's next scheduled scan column shows exactly when each framework's evidence will next be renewed.
Together, verified assets and recurring pentests keep every framework in the fresh state without manual effort.
Pricing
TurboPentest pricing and plans: each pentest uses one credit, sold in four tiers priced by depth of analysis, from Audit-Ready to Adversarial-Depth.
AI Data Privacy & Security
How TurboPentest protects your data when using Anthropic's Claude - your inputs and findings are never used for AI training and stay confidential.