Skip to main content

Exchange

The Governance Exchange is a library of "reusable enforcement artifacts · community-tested defenses · compliance packs." Instead of writing every policy, DLP pattern, and inbound rule yourself, you install proven ones. Open Exchange from the More group.

Governance Exchange Exchange — browse enforcement artifacts by type and trust level, each tagged with the frameworks it satisfies.

Browsing

Three tabs: Explore (the artifact catalog), Packs (bundles), and Coverage (what your installed artifacts cover). Search across artifacts, techniques, and frameworks, and filter by:

  • Type — Policies, DLP Patterns, Inbound Rules.
  • Trust levelBehavry Verified, Red Team Tested, or Community Tested. For a regulated buyer, trust level matters: prefer Behavry Verified or Red Team Tested for anything enforcing in production.

Each artifact card shows what it does (e.g. "Block Bulk PII Export — deny read_file or query operations that return more than 100 PII records"), the frameworks it satisfies (SOC 2, GDPR, PCI-DSS, ISO 27001, OWASP ASI, HIPAA…), an install count, and a maturity tier.

Packs and coverage

  • Packs bundle related artifacts into a single install — for example a compliance pack that lays down the policies, DLP patterns, and inbound rules a framework expects. This is the fast path referenced by the Overview's "deploy a compliance pack to close coverage gaps" recommendation.
  • Coverage shows which controls your installed artifacts satisfy, so you can see gaps against a framework before an audit.

Installing and contributing

  1. Filter to the type and trust level you want.
  2. Open an artifact to review its rule and the frameworks it maps to.
  3. Install it — it lands in the matching surface (Policies, DLP, or Inbound Rules) where you scope and activate it like any other rule.
  4. Contribute your own hardened artifacts back to the Exchange.

See the Community Library overview and Publishing for how artifacts are shared and versioned.