Compliance
Machine identity evidence across frameworks
Avistar maps machine identity findings to the controls your assessors use. This is evidence from your cloud tenant, not a claim about Avistar's own certifications.
Our own security posture
Review Avistar’s security policies, trust documentation, and compliance posture in one place.
Frameworks we map machine identity findings to
The frameworks below are the ones Avistar scans for and produces evidence against. Each mapping is scoped to machine identity lifecycle, least privilege, and continuous monitoring, not a claim that Avistar is certified to that standard.





| Framework | Relevant controls | Machine identity evidence |
|---|---|---|
| ISO 27001 | A.5.16, A.5.18, A.8.2, A.8.9 | Identity inventory with owners, privilege review records, credential lifecycle log |
| SOC 2 | CC6.1, CC6.2, CC6.3, CC7.2 | Continuous monitoring of logical access for machine identities and remediation history |
| NIST 800-53 | AC-2, AC-6, IA-5, CA-7 | Account management, least privilege, authenticator management, continuous assessment |
| FedRAMP | AC-2, IA-5, CA-7 | Inventory and monitoring artifacts for service and workload identities |
| HIPAA Security Rule | §164.308(a)(4), §164.312(a)(1), §164.312(d) | Access authorization, unique identification, and authentication management for system accounts |
Bring machine identities into your control narrative
See how machine identity findings map to the frameworks in your scope.