Skip to Content
GuidesGenerate Compliance Reports

Generate Compliance Reports

CodeStax maps repository scan evidence to enabled compliance frameworks and produces a point-in-time report of the resulting posture. The report supports control review and audit preparation; it is not a certification or independent compliance opinion.

Available Frameworks

Enable built-in frameworks under Settings → Policies. Create custom frameworks from the Compliance dashboard.

Generate a Repository Report

PDF Contents

  • Repository and report provenance
  • Executive posture and control totals
  • Framework-by-framework scores and pass/partial/fail counts
  • Action-needed controls and available evidence
  • Coverage, freshness, exclusions, and interpretation notes
  • Repeating headers, page numbers, and confidentiality footer

Other Export Formats

  • JSON preserves structured framework data for GRC or internal tooling.
  • CSV provides a compact spreadsheet-ready framework summary.
  • HTML provides a lightweight browser-readable summary.

Use JSON when a downstream process needs the structured evidence. Use PDF for human review and retain both when preparing a formal evidence package.

Best Practices

  1. Scan the repository before generating the report.
  2. Verify that required frameworks and controls are enabled.
  3. Review failed and partial controls instead of relying only on the headline score.
  4. Record evidence and approved overrides with clear owners and reasons.
  5. Retain source-provider, policy approval, remediation, and deployment evidence separately where the control requires it.