Compliance guidance
Evidence, coverage, and limitations
Understand what SiteWall evidence represents, how provenance is preserved, and what it cannot establish alone.
Last reviewed September 12, 2026
Compliance evidence overview
SiteWall evidence combines time- and project-scoped observations with recorded human decisions such as authorization, justification, acknowledgement, and remediation. Requirement views organize those records and generated reports package them for review. Organizational evidence maintained outside SiteWall remains part of a complete handoff.
What to review
Use the following table to understand how each area supports the task.
| Area | How to use it |
|---|---|
| Runtime records | Open a representative session and record its page, time, browser context, and observed resources. Use it to establish that the behavior occurred in that captured journey, not that it occurred for every visitor. |
| Decisions | Follow the indicator to its source records and preserve the project, monitored pages, observation period, generation time, reviewer, and known gaps. Keep SiteWall’s browser-side evidence separate from organizational evidence and the reviewer’s compliance conclusion. |
| Actions | Follow the indicator to its source records and preserve the project, monitored pages, observation period, generation time, reviewer, and known gaps. Keep SiteWall’s browser-side evidence separate from organizational evidence and the reviewer’s compliance conclusion. |
| Exports | Follow the indicator to its source records and preserve the project, monitored pages, observation period, generation time, reviewer, and known gaps. Keep SiteWall’s browser-side evidence separate from organizational evidence and the reviewer’s compliance conclusion. |
| Human evidence | Preserve source, time, project, and transformation context and separate the technical record from the reviewer’s conclusion. |
Evidence model and provenance
Every evidence item should retain its source, project, monitored page or resource, observation time, generation time, and any transformation applied for display or export. Review freshness and gaps before reuse. A report is a point-in-time representation, not a continuously valid conclusion.
What to review
Use the following table to understand how each area supports the task.
| Area | How to use it |
|---|---|
| Source | Follow the indicator to its source records and preserve the project, monitored pages, observation period, generation time, reviewer, and known gaps. Keep SiteWall’s browser-side evidence separate from organizational evidence and the reviewer’s compliance conclusion. |
| Time | Compare the first, last, and event timestamps with the investigation or reporting window. These values describe SiteWall observations for the active project and do not establish activity outside the captured period. |
| Project | Follow the indicator to its source records and preserve the project, monitored pages, observation period, generation time, reviewer, and known gaps. Keep SiteWall’s browser-side evidence separate from organizational evidence and the reviewer’s compliance conclusion. |
| Scope | Keep the selected project, monitored pages, traffic paths, and observation period attached to the result. |
| Transformations | Follow the indicator to its source records and preserve the project, monitored pages, observation period, generation time, reviewer, and known gaps. Keep SiteWall’s browser-side evidence separate from organizational evidence and the reviewer’s compliance conclusion. |
| Limitations | Follow the indicator to its source records and preserve the project, monitored pages, observation period, generation time, reviewer, and known gaps. Keep SiteWall’s browser-side evidence separate from organizational evidence and the reviewer’s compliance conclusion. |
Legal & Compliance overview
Legal & Compliance is the entry point for SiteWall’s supported framework views: PCI DSS v4.0.1, GDPR, and ISO/IEC 27001:2022. Open a framework to review requirement or control status, script records, third-party assessments, configuration, scoped evidence, actions, and report options.
What to review
Use the following table to understand how each area supports the task.
| Area | How to use it |
|---|---|
| Framework list | Follow the indicator to its source records and preserve the project, monitored pages, observation period, generation time, reviewer, and known gaps. Keep SiteWall’s browser-side evidence separate from organizational evidence and the reviewer’s compliance conclusion. |
| Status | Read the state together with its timestamps and owner action; a workflow state does not erase the original observation. |
| Entry points | Follow the indicator to its source records and preserve the project, monitored pages, observation period, generation time, reviewer, and known gaps. Keep SiteWall’s browser-side evidence separate from organizational evidence and the reviewer’s compliance conclusion. |