Compliance Reporting & Gap Analysis
LimaCharlie's compliance toolkit maps seven major frameworks, including SOC 2, PCI DSS, HIPAA, ISO 27001, NIST 800-53, CMMC, and CIS v8, directly onto your deployed sensors, detections, and case queue. Evidence production runs continuously instead of being assembled in the weeks before an audit.
Deploy the baseline
Each framework ships with a control-to-capability mapping and a deployable rule baseline covering detection, file integrity, artifact collection, and exfiltration rules across Windows, Linux, and macOS. Pushing the full baseline into a tenant is one guided step.
Classify continuously
A case-reviewer agent runs inside the organization and fires on every new case, classifying it against the relevant control citations and writing audit-grade documentation directly into the case record. The evidence auditors rely on accumulates as a byproduct of normal operations.
Answer control questions
When an auditor or customer asks how a specific control is covered, the control lookup skill answers from the framework mapping and your actual deployment rather than from a spreadsheet maintained by hand.
Find gaps before the audit
The gap analysis skill compares a tenant against the framework's recommended baseline and produces an engineering punch list of what's missing, so remediation happens before the auditor arrives instead of during the finding response.
Open and inspectable
The toolkit is delivered as an open-source Claude Code plugin from the lc-ai repository under an Apache 2.0 license, so every framework mapping and rule is inspectable and forkable rather than sealed inside a product.
Deploy your first sensor on the free community tier, or walk through it with a solutions engineer.
Start freeBook a demo