Generate Compliance Reports
CodeStax maps repository scan evidence to enabled compliance frameworks and produces a point-in-time report of the resulting posture. The report supports control review and audit preparation; it is not a certification or independent compliance opinion.
Available Frameworks
Enable built-in frameworks under Settings → Policies. Create custom frameworks from the Compliance dashboard.
Generate a Repository Report
PDF Contents
- Repository and report provenance
- Executive posture and control totals
- Framework-by-framework scores and pass/partial/fail counts
- Action-needed controls and available evidence
- Coverage, freshness, exclusions, and interpretation notes
- Repeating headers, page numbers, and confidentiality footer
Other Export Formats
- JSON preserves structured framework data for GRC or internal tooling.
- CSV provides a compact spreadsheet-ready framework summary.
- HTML provides a lightweight browser-readable summary.
Use JSON when a downstream process needs the structured evidence. Use PDF for human review and retain both when preparing a formal evidence package.
Best Practices
- Scan the repository before generating the report.
- Verify that required frameworks and controls are enabled.
- Review failed and partial controls instead of relying only on the headline score.
- Record evidence and approved overrides with clear owners and reasons.
- Retain source-provider, policy approval, remediation, and deployment evidence separately where the control requires it.