📋 Compliance
Overview

📋 Compliance

Prove compliance automatically. NAT generates audit-ready evidence mapped to industry security frameworks — no manual effort required.


Why NAT for compliance?

ApproachWhat it takes
Traditional complianceManual spreadsheets, screenshot evidence, weeks of prep before every audit
NAT complianceAutomated reports, real-time badge status, BGSTM audit trail — generated after every scan

What NAT provides

FeatureDescription
Framework CoverageOWASP API Top 10, PCI-DSS, HIPAA, SOC 2
Compliance ReportsAI-generated narrative reports mapped to each framework's requirements
Embeddable Badgesshields.io badges showing real-time compliance status
BGSTM Audit Trail6-phase evidence chain: Plan → Generate → Prepare → Execute → Analyze → Report

For compliance officers: You don't need to understand API testing to use NAT compliance reports. Each report explains findings in plain language, maps them to specific framework requirements, and provides actionable remediation guidance.

💡

For developers: Generate reports from the CLI with nat ai compliance-report --framework owasp. See AI Assistant → Compliance Reports for full CLI reference.


Quick start

  1. Run a security scan:

    nat scan --target https://your-api.com
  2. Generate a report:

    nat ai compliance-report --framework owasp --output report.pdf
  3. Embed a badge: copy the shields.io URL to your README (see Compliance Badges)


Plan availability

PlanWhat you get
FreeView compliance scores in dashboard
Pro5 compliance reports / month
TeamUnlimited reports + BGSTM audit trail export

In a hurry? See Quick Scans

Was this helpful?