For heads of GRC and GRC analysts
Audit week without the scramble.
Patchflare keeps the evidence as the work happens: the finding, the fix, the build and test output, the rescan, the approver and the SLA outcome, in one record you can export for any period.
The problem in your words
What the patch queue costs you today.
Evidence is rebuilt by hand
Tickets, PR links, scan screenshots and timestamps, collected one by one, every cycle, for every framework.
SLA conformance is asserted, not shown
The policy says seven days. Showing that it happened across four hundred findings means a spreadsheet nobody trusts.
Exceptions have no owner
Risk acceptances were agreed somewhere, by someone, for some period. Listing them with reasons is a project.
Frameworks ask the same question five ways
SOC 2, ISO 27001, PCI DSS and the customer questionnaire all want proof that vulnerabilities are remediated within policy.
Reports
Pick a period. Download the evidence.
Choose the dates, the repositories and whether to include exceptions. Patchflare replays the event history to reconstruct what was open, fixed and reopened, and produces a PDF for the auditor, an XLSX for you and a CSV for tooling.
- Posture and activityOpen at period end, fixed in period, SLA met versus breached, exceptions granted, known-exploited status.
- Detail rows with referencesRef, CVE, severity with its CVSS source, detected, fixed, days to remediate, SLA outcome, verification, approver.
- Framework mappingColumn notes map to SOC 2 CC7, ISO 27001 A.8.8 and PCI DSS 6.3 evidence expectations. Names describe use cases, not certifications we hold.
Every row links to the finding's evidence: scan, PR, build and test output, rescan, approver.
CVE-2022-23529
GHSA-27h2-hvpr-p74q · jsonwebtoken 8.5.1SLA and exceptions
Policy with a version. Exceptions with an expiry.
The SLA policy is versioned, so a report shows which policy applied when. Exceptions record the actor, reason, kind and expiry, pause the clock while in force, and reappear in the queue when they lapse.
- Conformity score and bandsA to D over the trailing ninety days, overall and per repository.
- No silent state changesEvery transition is an append-only event with a timestamp and actor, including automatic ones.
- Verified, not just mergedA fix counts when the post-merge rescan confirms the advisory is gone.
Proof
The record behind one reference.
This is what the auditor sees when they pick a row in the report and ask for the evidence.
Questions
What people in your role ask
Answers to the questions that come up in the first conversation.
security@patchflare.com for anything not answered here.
Which frameworks does the report support?
The report is evidence, not a certification. It is organised to answer SOC 2 vulnerability management and change control, ISO 27001 A.8.8, PCI DSS 6.3 and customer questionnaire items about remediation timelines and verification.
Can we generate a report for last quarter?
Yes. Reports replay the event history, so any period since the repository was enrolled can be reconstructed exactly, including the policy version in force at the time.
How are exceptions shown?
As their own rows and counts: kind, actor, reason, granted date, expiry, and whether the finding was later fixed anyway. Reports can include or exclude them.
Can the auditor get read-only access?
Yes. Invite them with the member role scoped to the repositories in question, or hand them the PDF and the XLSX. Download links expire after ten minutes and every download is logged.
Bring last quarter's evidence request.
We will show you the report that answers it, generated live, in thirty minutes.