For heads of GRC and GRC analysts

Audit week without the scramble.

Patchflare keeps the evidence as the work happens: the finding, the fix, the build and test output, the rescan, the approver and the SLA outcome, in one record you can export for any period.

The problem in your words

What the patch queue costs you today.

Evidence is rebuilt by hand

Tickets, PR links, scan screenshots and timestamps, collected one by one, every cycle, for every framework.

SLA conformance is asserted, not shown

The policy says seven days. Showing that it happened across four hundred findings means a spreadsheet nobody trusts.

Exceptions have no owner

Risk acceptances were agreed somewhere, by someone, for some period. Listing them with reasons is a project.

Frameworks ask the same question five ways

SOC 2, ISO 27001, PCI DSS and the customer questionnaire all want proof that vulnerabilities are remediated within policy.

Reports

Pick a period. Download the evidence.

Choose the dates, the repositories and whether to include exceptions. Patchflare replays the event history to reconstruct what was open, fixed and reopened, and produces a PDF for the auditor, an XLSX for you and a CSV for tooling.

  • Posture and activityOpen at period end, fixed in period, SLA met versus breached, exceptions granted, known-exploited status.
  • Detail rows with referencesRef, CVE, severity with its CVSS source, detected, fixed, days to remediate, SLA outcome, verification, approver.
  • Framework mappingColumn notes map to SOC 2 CC7, ISO 27001 A.8.8 and PCI DSS 6.3 evidence expectations. Names describe use cases, not certifications we hold.
Compliance report· Q3 2026 · PDF, XLSX, CSVExample
Findings in period
418
14 repositories
Resolved
371
verified by rescan
SLA met
94%
policy v3 · critical 7d
Exceptions
9
with reason and expiry
RefFindingDetectedFixedSLA
PAY-142CVE-2022-23529 · jsonwebtoken · criticalSep 1Sep 3Met
WEB-61CVE-2026-31872 · fast-uri · highAug 12Aug 20Met
CHT-4CVE-2026-18871 · chromadb · criticalAug 3Exception

Every row links to the finding's evidence: scan, PR, build and test output, rescan, approver.

Finding PAY-142· acme / payments-apiExample
PAY-142

CVE-2022-23529

GHSA-27h2-hvpr-p74q · jsonwebtoken 8.5.1
Critical · CVSS 3.1 9.8Known exploitedEPSS 43% · p97SLA due in 5d
DetectedScheduled scan · Sep 1 · SLA clock started (critical: 7 days)Sep 1
PatchedPR #2841 opened · build, 184 tests, rescan cleanSep 2
MergedApproved by jmartin · post-merge rescan queuedSep 3
VerifiedRescan of main confirms the advisory is gone · SLA metSep 3
Exception: none · counts as actionableAdd exception

SLA and exceptions

Policy with a version. Exceptions with an expiry.

The SLA policy is versioned, so a report shows which policy applied when. Exceptions record the actor, reason, kind and expiry, pause the clock while in force, and reappear in the queue when they lapse.

  • Conformity score and bandsA to D over the trailing ninety days, overall and per repository.
  • No silent state changesEvery transition is an append-only event with a timestamp and actor, including automatic ones.
  • Verified, not just mergedA fix counts when the post-merge rescan confirms the advisory is gone.

Proof

The record behind one reference.

This is what the auditor sees when they pick a row in the report and ask for the evidence.

Sep 1 · 05:00
Detected — PAY-142Scheduled scan · CVE-2022-23529 · CVSS 3.1 9.8 (critical) · in CISA KEV since 2023-01 · SLA clock started, due Sep 8
Sep 2 · 09:14
Patched — PR #2841jsonwebtoken 8.5.1 → 9.0.2 · scope gate passed · build 2m14s · 184 tests · rescan clean
Sep 2 · 11:02
Reviewedjmartin asked for the 8.x line; agent moved to 9.0.0 · checks re-run · approved by jmartin
Sep 3 · 08:40
MergedMerged into main by jmartin · post-merge rescan queued
Sep 3 · 09:05
Verified fixedRescan of main: advisory absent · SLA outcome met (2 of 7 days) · record frozen

Questions

What people in your role ask

Answers to the questions that come up in the first conversation.

security@patchflare.com for anything not answered here.

Which frameworks does the report support?

The report is evidence, not a certification. It is organised to answer SOC 2 vulnerability management and change control, ISO 27001 A.8.8, PCI DSS 6.3 and customer questionnaire items about remediation timelines and verification.

Can we generate a report for last quarter?

Yes. Reports replay the event history, so any period since the repository was enrolled can be reconstructed exactly, including the policy version in force at the time.

How are exceptions shown?

As their own rows and counts: kind, actor, reason, granted date, expiry, and whether the finding was later fixed anyway. Reports can include or exclude them.

Can the auditor get read-only access?

Yes. Invite them with the member role scoped to the repositories in question, or hand them the PDF and the XLSX. Download links expire after ten minutes and every download is logged.

Bring last quarter's evidence request.

We will show you the report that answers it, generated live, in thirty minutes.