Introduction to Enforcer-CCA
Welcome to the Enforcer-CCA documentation. This guide will help you understand how to use our platform for continuous compliance evidence.
What is Enforcer-CCA?
Enforcer-CCA evaluates the live state of your AWS and Kubernetes infrastructure against ISO 27001-mapped policies and records every finding as a resource-level, timestamped evidence record carrying a SHA-256 hash. When you enable remediate mode and approve a specific fix, the finding, the approval, and the fix are stored as one linked audit trail. The policy engine is deterministic: no LLM sits in the evidence path.
Why Enforcer-CCA?
Your compliance tool answers "do we have a policy?" by polling integrations for point-in-time checkmarks. It cannot answer "did our infrastructure actually enforce it last month?" Enforcer-CCA exists for that second question — the one auditors and bank vendor-risk teams actually ask.
Head over to the Getting Started section to begin your journey.