Compliance profiles

Switch SafeWeave to a compliance profile such as SOC 2, PCI-DSS or HIPAA to apply stricter rules and thresholds.

What it is

A compliance profile changes which scanners run, which rules apply and how strict the thresholds are, to match a standard your project has to meet.

Who gets it

Cloud and Cloud Plus.

Profiles

Profile Use it for
Standard (default) Balanced security for most projects. Covers the most common vulnerability classes.
Hardened Stricter rules for security-sensitive apps. Blocks AGPL-3.0 licensed dependencies.
OWASP Web apps, focused on the OWASP Top 10, with live web checks.
SOC 2 SOC 2 Type II. Requires non-root containers and flags vulnerabilities from CVSS 5.0.
PCI-DSS Apps that handle card payments. Blocks latest base images, requires non-root containers, flags vulnerabilities from CVSS 4.0.
HIPAA Apps that handle health data. Focused on encryption and access control.

How to use it

In your editor with SafeWeave set up, ask your assistant:

Switch to the SOC 2 compliance profile

Then scan again. To go back, ask it to switch to the Standard profile.

Limits

A profile helps you find problems that matter for a standard. It isn't a certification or an audit.