Exchange
The Governance Exchange is a library of "reusable enforcement artifacts · community-tested defenses · compliance packs." Instead of writing every policy, DLP pattern, and inbound rule yourself, you install proven ones. Open Exchange from the More group.
Exchange — browse enforcement artifacts by type and trust level, each tagged with the frameworks it satisfies.
Browsing
Three tabs: Explore (the artifact catalog), Packs (bundles), and Coverage (what your installed artifacts cover). Search across artifacts, techniques, and frameworks, and filter by:
- Type — Policies, DLP Patterns, Inbound Rules.
- Trust level — Behavry Verified, Red Team Tested, or Community Tested. For a regulated buyer, trust level matters: prefer Behavry Verified or Red Team Tested for anything enforcing in production.
Each artifact card shows what it does (e.g. "Block Bulk PII Export — deny read_file or query operations that return more than 100 PII records"), the frameworks it satisfies (SOC 2, GDPR, PCI-DSS, ISO 27001, OWASP ASI, HIPAA…), an install count, and a maturity tier.
Packs and coverage
- Packs bundle related artifacts into a single install — for example a compliance pack that lays down the policies, DLP patterns, and inbound rules a framework expects. This is the fast path referenced by the Overview's "deploy a compliance pack to close coverage gaps" recommendation.
- Coverage shows which controls your installed artifacts satisfy, so you can see gaps against a framework before an audit.
Installing and contributing
- Filter to the type and trust level you want.
- Open an artifact to review its rule and the frameworks it maps to.
- Install it — it lands in the matching surface (Policies, DLP, or Inbound Rules) where you scope and activate it like any other rule.
- Contribute your own hardened artifacts back to the Exchange.
See the Community Library overview and Publishing for how artifacts are shared and versioned.