Compliance
Behavry's compliance story is different from a policy binder: "continuous runtime audit evidence · proof before execution." It doesn't describe what should happen — it proves what did happen, independently, at execution time. Open Compliance from the Governance group.
Compliance — audit-chain integrity, runtime enforcement coverage, and per-framework readiness.
The posture cards
Six cards summarize your compliance posture over a 30-day window: Policy Coverage, Policy Gaps, Enforcement Mode (Active / Monitor), Audit Integrity, Control Effectiveness, and Unmapped Activity (click to filter to the actions no control maps to yet).
Audit chain integrity
The Audit Chain Integrity panel is the foundation of every claim on this page: "Hash-chain validated end-to-end. Every event cryptographically links to its predecessor." When it reads Verified, your evidence is tamper-evident and provable.
- Verify now re-runs the check on demand (e.g. 100,000 events checked).
- Forgiven breaks — breaks that were reviewed and baselined (for example during testing) are recorded with a reason and a timestamp, so the chain's history is honest. New breaks after the baseline still degrade the chain — you can't silently paper over a real tamper event.
See Audit Integrity for how the hash chain and signing work.
Runtime enforcement coverage
This is the number that separates Behavry from paper compliance:
98% of governed actions evaluated before execution.
The panel is careful about denominators, and you should be too:
- The headline % is over governed activity only — how well enforcement works where it applies.
- The legend % is over all activity — Runtime enforced + Observed only + Unmanaged = 100%.
So "98% runtime enforced" and "2% observed, 0% unmanaged" describe different slices. As the panel puts it: "Paper compliance describes what should happen. Runtime enforcement proves what did happen — independently, at execution time."
Framework readiness
The lower section tracks readiness per framework — OWASP ASI, Financial Services, Healthcare / HIPAA, Insurance / NAIC, EU AI Act, Data Privacy, and more. Filter by All / Active / Monitored / Inactive. Each framework card shows its attestation state (e.g. Partially Attested), the number of requirements, a readiness %, and open gaps — so you can see exactly where you stand for an audit and what's left to close.
For per-framework detail, see the Compliance overview and Framework Mapping, plus the individual guides (SOC 2, ISO 27001, HIPAA, EU AI Act, …).
Producing evidence for an auditor
- Confirm Audit Chain Integrity reads Verified (run Verify now).
- Note the runtime enforcement coverage — this is your "proof, not paper" headline.
- Open the relevant framework card for readiness and gaps.
- For a specific action or incident, export its Decision Trace evidence package (ZIP / PDF / JSON) — independently verifiable, no Behavry account required.