One audit.
Every cloud already covered.
Every cloud has its own console, its own drift, its own auditor screenshots. OnDuty maps CIS, PCI DSS, SOC 2, ISO 27001, HIPAA and NIST 800-53 to live resource state across AWS, Azure, GCP and OCI — so evidence is always current, not quarterly.



Six capabilities, one platform
Compliance, mapped
once. Proven always.
Unified multi-cloud control mapping
Every control in every framework mapped once, then evaluated continuously across AWS, Azure, GCP and OCI resources.
- Single control library
- Cross-cloud normalization
- No per-cloud rework
20+ built-in frameworks
CIS Benchmarks, PCI DSS, SOC 2, ISO 27001, HIPAA, NIST 800-53, GDPR and more — ready on day one.
- Framework crosswalks
- Custom control packs
- Shared-control dedupe
Continuous evidence collection
Every control check produces timestamped, exportable evidence — automatically, not once a quarter before an audit.
- Point-in-time snapshots
- Auditor-ready exports
- Evidence retention policies
Risk-weighted control scoring
Failing controls are ranked by real exposure and blast radius, so teams fix what actually threatens the audit outcome first.
- Exposure-weighted scoring
- Toxic combination detection
- Executive scorecards
Ownership & accountability
Every failing control routes to the team and resource owner responsible — with SLAs tracked to closure.
- Auto-routing by tag
- SLA tracking
- Jira & ServiceNow sync
Audit-day readiness
Generate a full evidence package for any framework, any date range, in minutes — not the week before the audit.
- One-click evidence export
- Historical compliance trend
- Auditor collaboration view
How the platform works
From spreadsheet chaos
to always-audit-ready.
One control library, every cloud.
Stop maintaining a separate SOC 2 workbook for AWS, another for Azure and a third for GCP. OnDuty maps every control once and evaluates it continuously against live resource state — the same rule, the same result, on every hyperscaler.
Map once
One control library
Timestamped proof, not quarterly screenshots.
Every control check produces exportable evidence with a timestamp, cloud, resource and framework citation — automatically. Auditors get proof, not a promise, and your team stops burning weeks on the screenshot marathon before every audit.
Evidence stream · today
LIVE · timestampedAuditor package generated · 12,438 evidence items
SOC 2 Type II · 01 Jan → 30 Jun · one click
Fix what threatens the audit, first.
Not every failing control is equal. OnDuty scores failures by real exposure, data sensitivity and blast radius — so the internet-facing bucket with PCI data outranks a dev sandbox missing a tag. Your team fixes what auditors will actually flag.
Ranked by audit blast radius
audit-blocking · fix firstPublic S3 with cardholder data · PCI DSS 3.4
Top of 847 open controls · fixes 3 frameworks
Route every failing control to its owner.
OnDuty ties each failing control to a resource, an owner and an SLA — then syncs it to Jira or ServiceNow. Compliance stops being a spreadsheet passed between teams and becomes a tracked ticket with a deadline.
CloudTrail retention < 90d
SOC 2 CC7.2 · cloudtrail://audit
Routed by tag
team:platform · owner: @alice
Jira ticket opened
PLAT-4218 · SLA 72h
Control passing
Retention 90d applied · evidence attached
AI that drafts the fix and the evidence.
OnDuty AI closes the loop between a failing control and a passing one. Ask which controls a change breaks and get an answer, not a query. Let AI draft the Terraform fix, generate the auditor narrative or map a custom control — so your team spends time on judgment, not paperwork.
AI Remediation
Terraform & policy fixes for failing controls
AI Discovery
Ask which changes break which controls
AI Evidence Narrative
Auditor-ready write-ups, generated
AI Control Mapping
Map custom controls across frameworks
The compliance lifecycle
From control mapping
to audit-ready.
Map
Map every control across CIS, PCI, SOC 2, ISO, HIPAA and NIST to live resources, once.
Evaluate
Continuously evaluate control status across AWS, Azure, GCP and OCI — no manual checks.
Prioritize
Rank failing controls by exposure and blast radius so teams fix what matters to the audit.
Prove
Export timestamped, audit-ready evidence for any framework and date range in minutes.
FAQ
Frequently asked questions.
Multi-cloud compliance is the discipline of proving that resources across every cloud you use — AWS, Azure, GCP, OCI — meet the same set of regulatory and framework controls (CIS, PCI DSS, SOC 2, ISO 27001, HIPAA, NIST 800-53 and more). Instead of running a separate audit workflow per cloud, you map controls once and evaluate them continuously against live resource state.
Related solutions
Explore the platform
OnDuty is one platform on a single graph. Here's where the rest of it connects.
Retire the screenshot marathon
See every control,
across every cloud.
See your real compliance posture, failing controls and auditor-ready evidence in a 30-min guided demo with our team.
- One control library across AWS, Azure, GCP & OCI
- 20+ built-in frameworks — CIS, PCI, SOC 2, ISO, HIPAA, NIST
- Continuous, timestamped evidence — no quarterly screenshots
- Risk-weighted scoring focuses fixes on audit blast radius
- One-click auditor exports for any framework, any date range