Compliance scoring, evidence states, and framework scope
Understand what evidence readiness means, which frameworks apply, and why Tutela evidence is not a customer assurance claim.
Prerequisites
- Compliance frameworks loaded
What the score means
- Scores summarize compliance evidence coverage for governed AI traffic and Tutela deployment controls.
- Tutela does not certify the full customer environment for SOC 2, HIPAA, GDPR, PCI DSS, NIST AI RMF, EU AI Act, OWASP LLM Top 10, or OWASP Agentic AI by itself.
- Controls marked not applicable are excluded from score calculations. Controls marked not configured or no evidence count against coverage.
Evidence states
- Pass means Tutela has enough platform, configuration, or observed-traffic evidence for the mapped check.
- Partial means evidence exists but is incomplete or below the pass threshold.
- Fail means evidence exists and shows the control is not meeting the configured requirement.
- No evidence means the governed route or metric has not produced evidence yet.
- Not configured means a required source, policy, integration, or framework scope confirmation is missing.
Validate
- Applicable framework scope confirmed
- Evidence state understood for each control
- Not-applicable controls excluded from score
- Exports reviewed for unsupported overclaims
Next steps
- Confirm framework scope
- Fix controls marked not configured or no evidence
- Generate a scoped evidence report