Use cases / 05 — Support Compliance
Use case · Compliance for Production Applications

Support compliance with runtime protection and evidence

Show what protects your production applications today. Raven connects running libraries, active protection and recorded outcomes, giving security and compliance teams concrete evidence to support control reviews, mitigation decisions and recurring assessments.
DORA
EVIDENCE
PCI DSS 4.0.1
EVIDENCE
SOC 2
EVIDENCE
ISO 27001
EVIDENCE
NIST 800-53
EVIDENCE
FedRAMP
EVIDENCE
ONE RUNTIME EVIDENCE BASE
Favor LogoSageSure Logogopuff LogoWindward LogoZesty Logo
Favor LogoSageSure Logogopuff LogoWindward LogoZesty Logo
Favor LogoSageSure Logogopuff LogoWindward LogoZesty Logo
/ 02 — SCENARIOS

Be ready for  the next assessment. 

SCENARIO A

The patch has to wait. What protects the application?

A vulnerable library is running in production. The update needs testing and a maintenance window. Apply protection to covered exploit behavior and document what is protected while the permanent fix proceeds.
SCENARIO B

The assessor asks what actually operated.

A policy document describes your intent. Runtime evidence shows what happened inside the application. Bring events, policy records and coverage history into the review for the relevant period.
/ 03 — MECHANISM

From running code to reviewable evidence.

CONTROL REVIEW — Q3 ASSESSMENT
inventory: observed libraries + execution context payment-api
validate: exploit test on protected workload
PREVENTED · RECORDED event #5521
connect: event policy v3 workload time
attach: coverage history · remaining risk · treatment record
ILLUSTRATIVE RUNTIME CONTROL AND EVIDENCE
1

See the application context

Add observed libraries and execution context to your application inventory and vulnerability reviews.
2

Apply and validate protection

Enforce policy against covered exploit behavior, then validate the result on the relevant workload.
3

Connect the evidence

Tie the event to its policy, affected workload and time. Combine it with coverage history, remaining risk and treatment records for the assessment.
/ 04 — EVIDENCE

Show the control  in action. 

Start with a verified prevention event. Connect the attempted action to its library, enforcing policy and affected workload. Carry that evidence into the review with its scope, test conditions and remaining work.
Raven event: anomalous code execution on log4j-4255-vulnerable workload, blocked via policy 3 2 1
1

Code and action

The attributed library and the sensitive action it attempted.
2

Protection that operated

The recorded prevention outcome and matching policy version.
3

Scope and time

The affected workload, timestamp and test reference.
SBOM and VEX stay complementary records — inventory and impact, alongside validation and enforcement evidence.
/ 05 — FRAMEWORK FIT

One evidence base. Six framework mappings.

DORA

Track third-party libraries and substantiate mitigation decisions.

PCI DSS 4.0.1

Add runtime context to software inventory and vulnerability management.

SOC 2

Support reviews of application monitoring and incident handling.

ISO 27001

Support risk treatment with application monitoring evidence.

NIST SP 800-53

Map runtime protection and monitoring to selected controls.

FedRAMP Rev5 / 20x

Bring runtime evidence into the assessed environment.
/ 06 — FAQ

Questions before the review

Does Raven make us compliant?

Raven supplies technical controls and supporting evidence. Your organization remains responsible for its complete framework implementation, operating processes and assessment.

Can prevention support a compensating control?

Raven's prevention evidence can support that assessment. Acceptance depends on the framework's rules, documented constraints, control effectiveness and assessor review. Patching obligations still apply.

Can evidence stay inside our environment?

Yes. Raven supports on-premises deployment and fully offline operation, allowing customers to retain runtime evidence within their own environment.

Protect the application. Bring the evidence.

Show reviewers what ran, what protection operated and where work remains.
BOOK A DEMO