Pages
Policy Catalog v2

Source: /pages/policy-catalog — c65 iteration: Config column dropped, policy rows expand instead (UxTableListExpandRow with rule, full framework mapping, and the config link inside)

Compliance frameworks

Active frameworks require policies — an unmet requirement is a gap that degrades posture.

58% · 7 / 12 policies

8 policies mapped · 5 would need enabling

6 policies mapped · 2 would need enabling

6 policies mapped · 1 would need enabling

10 policies mapped · 4 would need enabling

2 policies mapped · 0 would need enabling

10 policies mapped · 4 would need enabling

8 policies mapped · 3 would need enabling

80% · 8 / 10 policies

7 policies mapped · 4 would need enabling

67% · 4 / 6 policies

5 policies mapped · 2 would need enabling

Security posture

68%

across active frameworks

Active frameworks

3 / 12

toggled globally, org-wide

Active policies

10 / 17

pre-defined, individually configured

Open gaps

6

required by an active framework, off

Policies

Activate with the toggle; expand a row for the definition and its config.

DescriptionActive Compliance Frameworks Requiring this Policy
Identity & Access2 of 3 active

Agents must be registered and monitored before they run.

SOC 2HIPAA

Agents run under org-issued identity, not personal accounts or static keys.

SOC 2HIPAA Required

Agents may not execute with root or admin privileges.

OWASP LLMSOC 2
Action & Autonomy2 of 4 active

Consequential tool calls require a human approval before agents proceed.

OWASP LLMSOC 2

Agents may only invoke tools on the approved list.

OWASP LLMSOC 2 Required

Agents may only connect to approved MCP servers.

3 mapped frameworks — none active

Agent code execution is confined to a sandbox at or above the required level.

OWASP LLMSOC 2
Data Protection3 of 4 active

Secrets and credential files stay out of model context.

OWASP LLMSOC 2HIPAA

Sensitive content is detected and redacted in prompts and responses.

OWASP LLMHIPAA Required

Agent traffic may only reach approved destinations.

OWASP LLMSOC 2HIPAA

Connections below the TLS baseline are refused.

SOC 2HIPAA
Input & Output Integrity0 of 3 active

Inbound prompts are scanned for injection patterns — detect & contain.

OWASP LLM Required

Agent output is checked before it reaches downstream tools.

OWASP LLM Required

Models and tools must match pinned, verified sources.

OWASP LLM Required
Cost & Consumption3 of 3 active

Fleet and per-agent spend stays under explicit ceilings.

OWASP LLM

Agents respect provider quotas instead of burning through them.

OWASP LLM

No agent operates below the minimum security-posture score.

SOC 2

Need something narrower than these? The flexible engine is still there — custom controls →

Qpoint Brand Style Guide