Profile Registry
Browse the reference types, profiles, and overlays published under the evidencepack/ namespace. Use these as starting points or reference implementations.
Types define artifact categories with metadata schemas. Use these to declare what kind of evidence an artifact represents.
evidencepack/soc2-report@v1
SOC 2 Report
evidencepack/pentest-report@v1
Penetration Test Report
evidencepack/cloud-config@v1
Cloud Provider Configuration
evidencepack/iam-summary@v1
IAM Security Posture
evidencepack/vcs-config@v1
Version Control Configuration
evidencepack/idp-config@v1
Identity Provider Configuration
evidencepack/vulnerability-scan@v1
Vulnerability Scan Report
evidencepack/security-policy@v1
Security Policy Document
evidencepack/baa-agreement@v1
Business Associate Agreement
evidencepack/architecture-diagram@v1
System Architecture Diagram
Profiles declare what artifacts a pack must contain. Choose a profile that matches your compliance needs.
evidencepack/baseline@v1
Baseline
Minimal base profile for overlay-only compositions. Use when no other base profile fits.
Requirements
No requirements. Apply overlays to add requirements.
evidencepack/soc2-basic@v1
SOC 2 Basic
Minimum evidence for a basic SOC 2 security review. Requires a SOC 2 Type II report and penetration test results.
Requirements
evidencepack/soc2-report@v1
evidencepack/pentest-report@v1
evidencepack/security-policy@v1
evidencepack/vendor-review@v1
Vendor Security Review
Standard evidence package for third-party vendor security assessments. Covers compliance attestation, security testing, and key security controls.
Requirements
evidencepack/soc2-report@v1
evidencepack/pentest-report@v1
evidencepack/vulnerability-scan@v1
evidencepack/security-policy@v1
evidencepack/architecture-diagram@v1
Overlays add or modify requirements on top of a base profile. Stack multiple overlays to compose requirements.
evidencepack/hipaa-overlay@v1
HIPAA Overlay
Additional requirements for HIPAA compliance. Apply on top of any base profile to add healthcare-specific evidence requirements.
Adds requirements
evidencepack/baa-agreement@v1
Modifies requirements
evidencepack/pentest-report@v1
evidencepack/vulnerability-scan@v1
evidencepack/cloud-posture-overlay@v1
Cloud Posture Overlay
Adds cloud infrastructure, identity, and development security requirements. Apply to any base profile to require technical cloud evidence.
Adds requirements
evidencepack/cloud-config@v1
evidencepack/iam-summary@v1
evidencepack/vcs-config@v1
evidencepack/idp-config@v1
Example: Composing overlays
Stack multiple overlays on a base profile to build exactly the requirements you need:
{
"profile": "evidencepack/vendor-review@v1",
"overlays": [
"evidencepack/cloud-posture-overlay@v1",
"evidencepack/hipaa-overlay@v1"
]
}
This gives you: SOC 2 + pentest (180 days) + cloud/IAM/VCS/IdP + BAA + required vuln scans (30 days).
Related