What it is
A compliance profile changes which scanners run, which rules apply and how strict the thresholds are, to match a standard your project has to meet.
Who gets it
Cloud and Cloud Plus.
Profiles
| Profile | Use it for |
|---|---|
| Standard (default) | Balanced security for most projects. Covers the most common vulnerability classes. |
| Hardened | Stricter rules for security-sensitive apps. Blocks AGPL-3.0 licensed dependencies. |
| OWASP | Web apps, focused on the OWASP Top 10, with live web checks. |
| SOC 2 | SOC 2 Type II. Requires non-root containers and flags vulnerabilities from CVSS 5.0. |
| PCI-DSS | Apps that handle card payments. Blocks latest base images, requires non-root containers, flags vulnerabilities from CVSS 4.0. |
| HIPAA | Apps that handle health data. Focused on encryption and access control. |
How to use it
In your editor with SafeWeave set up, ask your assistant:
Switch to the SOC 2 compliance profile
Then scan again. To go back, ask it to switch to the Standard profile.
Limits
A profile helps you find problems that matter for a standard. It isn't a certification or an audit.