Docs / Compliance
Compliance
Seventeen plain-English questions. Some tested, some yours to answer.
Ryvx Compliance turns a scan of your website into a plain-English status board, not a page of control IDs. It is built on the same finding engine as Ryvx Strike, so every row that Ryvx tests is backed by the same PoC-or-it-didn't-happen rule the rest of the product runs on. It is a checklist and evidence report, not a certification body: Ryvx does not certify PCI DSS or Cyber Essentials Plus compliance, and this page says plainly which of the seventeen questions Ryvx can answer for you.
Where the questions come from
Twelve questions are plain-English paraphrases of the twelve top-level requirements in PCI DSS v4.0. Five more come from Cyber Essentials Plus's five broad technical control themes (firewalls, secure configuration, user access control, malware protection, and security update management). Two questions overlap word for word between the two frameworks (a firewall, and antivirus on your own machines), so answering one settles both, leaving seventeen unique questions in total.
What Ryvx tests directly
Six of the twelve PCI questions, and three of the five Cyber Essentials themes, can be answered by scanning your website: whether known security holes are fixed, whether your site is properly encrypted, whether only the right people can see customer data, whether everyone has their own login, whether you test your security regularly, and whether default passwords and settings have been changed. Each finding behind a row carries a compliance tag mapping its underlying weakness to the specific PCI DSS requirement or Cyber Essentials Plus theme it falls under, alongside SOC 2, CIS Controls v8, NIST CSF, ISO 27001:2022 and, where relevant, HIPAA technical safeguards. A row with a critical or high finding shows "Needs fixing"; any other finding shows "Worth a look"; no matching finding on a checked site shows "Checked, passed."
What you answer yourself
The remaining rows, physical security, paper records, antivirus on your own machines, your written security policy, whether your payment provider handles card numbers instead of you, can only ever come from the business, not from scanning a website. Ryvx never guesses at these: an unanswered row reads plainly as "you need to answer this," never a green tick, and a "yes" answer is recorded as "declared by the business," not "checked by Ryvx", on the certificate and in the emailed report alike.
Checking a website
Checking a site is read-only: Ryvx reads it the way a browser would, over HTTP(S), the same domain-control verification every Ryvx product requires before touching a live target. Nothing is submitted, no forms, no login attempts, no exploitation, unless you separately buy and turn on Strike's exploitation testing for that scan. A site is added to your Compliance plan automatically the first time you check it, and re-checked on the schedule you set from Continuous Monitoring.
Reports and certificates
Every check produces a certificate you can hand to an insurer, a bank, or a customer who asks for one. You keep every certificate already issued, including after cancelling. The certificate is a record of what was found and what was declared, on the date it was issued, not an ongoing guarantee.
← Back to Docs