Skip to content

Compliance overview

The compliance area brings together the pieces of Sencai that exist to answer one question: can you prove what your infrastructure looked like, who changed it, and why, at any point in time? That’s the evidence auditors, procurement teams, and regulators under frameworks like NIS2 and GDPR actually ask for.

Sencai helps you produce evidence for your own compliance program - it does not certify your organization as compliant with anything. Guardrail policies, a compliance score, an immutable audit trail, and exportable evidence packs are tools you use as part of demonstrating compliance to your own auditors or regulators. Whether your organization is compliant with NIS2, GDPR, or any other regulation is a legal determination that depends on far more than infrastructure tooling, and it’s not one Sencai makes for you.

PageWhat it covers
PoliciesThe guardrail policy engine - built-in and custom rules that check resources against conditions, either warning or blocking a provisioning action
NIS2 evidenceThe continuous, immutable audit trail of inventory actions, and how to export it as an evidence pack
EU AI ActThe AI system risk-review queue and what it does and doesn’t do today
InventoryThe managed-resource backbone that everything else in this section reads from - discovery, tagging, drift
ApprovalsThe approval queue for high-blast-radius actions before they execute
Privacy & dataThe privacy portal - data export, right to erasure, cookie consent, and (Enterprise) a GDPR Art.30 processing register
AgreementsSigning your Data Processing Agreement and Master Service Agreement in-app

Day-to-day, this section is for whoever owns security, compliance, or infrastructure governance at your organization - often the same person who owns DevOps. Most pages are reachable by any Member, but the actions that change your compliance posture (creating a custom policy, signing agreements, requesting account erasure) generally require Admin or Owner. Where a page has a stricter requirement, that page says so.

Auditor is worth calling out specifically: it’s a read-oriented role, positioned below Admin in the role hierarchy, meant for someone - an internal compliance officer or an external auditor - who needs to see your compliance posture and audit trail without being able to change infrastructure. If you need to give someone read-only access to exactly this section, Auditor is the role built for that.

Two pieces of this section are tier-gated rather than available to every organization:

  • The policy engine and NIS2 evidence reporting (guardrail policies beyond the built-in set, the compliance score, and the evidence timeline) are part of the Business plan and above.
  • Records of Processing Activities (GDPR Art.30) - the structured register under Privacy & data - is an Enterprise feature.

Everything else in this section (approvals, agreements, the core inventory, privacy self- service actions like data export and account erasure) is available on every plan, since those are rights and mechanics that apply regardless of tier. See sencai.space/pricing for exact plan comparisons.

It helps to see how these pages feed each other, because none of them work in isolation:

  • Inventory is the foundation - every cloud resource Sencai knows about, discovered from your connected providers or reported by the fleet agent, lives here with its tags and ownership state.
  • Policies evaluate against that inventory (and against every new provisioning request) and produce a compliance score with per-resource findings.
  • Every action taken anywhere in this loop - a scan, an ownership change, a tag update, an acknowledged drift event - is written to Sencai’s append-only, hash-chained audit log. The NIS2 evidence page is a read-only window into that log, scoped to your organization.
  • Approvals gate specific high-risk actions before they execute, and the approval decision itself becomes part of the same audit trail.
  • Privacy & data and Agreements sit slightly apart - they’re about your organization’s and your users’ own rights and legal standing with Sencai, rather than about your cloud resources - but they draw on the same audit infrastructure for evidence.
  • Policies - start here if you want to understand what gets checked and when
  • Inventory - the resource backbone everything else reads from
  • NIS2 evidence - generating an evidence pack for an audit
  • Getting started: roles - the full role hierarchy referenced above