Solutions

Engineering controls, mapped to audit criteria.

The reliability criteria are the hardest part of the audit to evidence, because the proof is in code and in practice, and you own neither. Revelara collects it where it lives.

Compliance postureTeams view
Controlcheckoutpaymentsplatform
SLO-Tied AlertingRC-001 · detective2
Synthetic MonitoringRC-002 · detective1
Alert Noise ReductionRC-004 · corrective975
On-Call CoverageRC-005 · preventive2
Incident RunbooksRC-006 · preventive4

Example data. A lit row is one failure class that recurs across teams. A lit column is one team with many.

Coverage by criterion

A 70-control compliance matrix, mapped to Common Criteria and Availability. Each control shows its evidence status, for each team that owns a part of it.

PlanThe compliance matrix starts at the Plus plan. See pricing.

Evidence that names its scope

Evidence has four scope states: team, service, global, and unknown. Evidence from before scoping existed is marked unknown and queued for a new scope. It is never silently counted as organization-wide.
rvl — evidence
$ rvl evidence submit --control=RC-004 --team=checkout \
--type=document --name="Monthly alert review" …

Evidence carries a scope: team, service, or global. A control counts for the organization only when every team is covered.

What leaves the environment

The Revelara scanner and rvl CLI run entirely within your own environment. Your source code is analyzed locally and does not leave your infrastructure; only the risk findings you choose to share are transmitted. Source code never reaches Revelara’s infrastructure, and is never sent to third-party model providers.

The CLI is open source, so your reviewer can verify this in the code. Read the security page.

Readiness, not certification

Revelara supports readiness for the reliability criteria. Your auditor still issues the report.

Run your first scan free.

Install the CLI, scan a repo, and read the findings in your terminal. Your source code stays on your machine.