Protect · Compliance & Audit
The audit evidence builds itself while you work.
Every detection, approval, baseline change and segmentation check already produces evidence. Synaptic OT maps it to the controls your regulator asks about and packages it for the auditor.
Why it matters
Audits stop being projects
Generate a per-framework evidence pack on demand instead of collecting screenshots for weeks.
Records nobody can quietly edit
The audit log is HMAC-chained row by row. A changed or deleted row breaks the chain at verification.
Retention set by regulation
Retention windows follow NERC CIP-007-6, NIST 800-92 and ISO 27001 by default, with per-site overrides such as five years for water utilities.
framework IEC 62443-3-3 SR 3.3 security functionality verification compliant SR 5.2 zone boundary protection partial 2 open violations SR 6.1 audit log accessibility compliant SR 2.8 auditable events attested by plant manager
Illustrative values
Capabilities
What's included
Compliance & Audit is part of the full Synaptic OT suite. One licence covers every capability on this site.
Seven frameworks mapped
NESA (UAE IA), IEC 62443-3-2, IEC 62443-3-3, IEC 61511, NERC CIP, NIST SP 800-82r3 and NIS2.
Live control scorecard
Each control is bound to the evidence the platform already keeps: logic diffs, conduit violations, maintenance records, audit logs, asset inventory and human attestations.
Auditor evidence pack
Executive summary, control scorecard, forensic manifests, signed violations and the asset register in one bundle with a Merkle root.
Tamper-evident audit log
HMAC-chained per tenant, with a verification endpoint and viewer for administrators.
Automatic retention
A daily worker applies retention by data type and logs every deletion. Audit evidence is never cascade-deleted.
Watermarked exports
Every exported report carries a tenant hash and timestamp, so forwarded copies can be traced.
Questions
Asked by OT and security teams
Does using Synaptic OT make us compliant?
No product can make you compliant on its own. Synaptic OT produces the monitoring, records and evidence these frameworks ask for, and maps them to controls so your assessor can review them quickly.
Which regulations do you support in the Gulf and India?
NESA (UAE IA) is mapped today. IEC 62443 mappings are commonly used alongside national frameworks such as NCA OTCC and CERT-In requirements; tell us which you report against.
Works with
See it on your own traffic.
Request an evaluation licence and run Synaptic OT on a mirror port or a PCAP from your plant. Fully offline if you need it to be.