# UprootSecurity: Security-First Compliance Automation > https://www.uprootsecurity.com llms-full.txt UprootSecurity is a security-first compliance platform built for engineering teams. It continuously reads a company's real infrastructure — cloud, identity, code, endpoints, data, and vendors — through 140+ deep API integrations, running tests every 15 minutes to produce a live security posture. On top of that posture it layers 22+ compliance frameworks, where a control mapped once satisfies every framework requiring it. An AI agent executes the program end to end, and autonomous offensive testing attacks the running system so the evidence reflects effective security, not just configured settings. The entire platform is exposed as MCP tools, so the agent operates inside a customer's own stack. Category: Security-first compliance automation Also known as: Uproot, Uproot Security Legal name: UprootSecurity, Inc. Website: https://www.uprootsecurity.com > Note on figures. Two kinds of number appear in this file, and they carry > different weight: > - **Architectural** — integration counts, test cadence, MCP tool counts. These > describe Uproot's own product. > - **Regulatory** — control and criteria counts belonging to external standards. > These appear only in the Compliance frameworks section, where each is cited > with its version or governing instrument and a last-verified date. > Outcome and customer metrics are deliberately excluded pending verification, and > should not be inferred from this file. ## The architecture in one line A real-time posture engine (140+ deep integrations → 1,200+ tests every 15 minutes → signed evidence) with compliance frameworks plugged in on top, where a control mapped once satisfies every framework that needs it — and an MCP server that exposes the whole engine to the customer's own agents. ## Two classes of evidence The distinction matters and Uproot draws it explicitly: - **Attested evidence** — a deep API read from the system of record, hashed and signed. Proves the *configured* state. Every product produces this by default. - **Offensive evidence** — an agent attacks the running system, and the attack artifacts (payload, request, blast radius, the fix that closed it) become the signed record. Proves the *effective* state. Not every artifact is attack-derived. Offensive evidence is the class produced by the pentesting product. ## Positioning "Security at the core. Compliance by design." A security platform that also passes audits, rather than a checklist tool that reports on configuration. The arguments Uproot makes: 1. **Compliance theater is a security liability.** A passed audit is not the same as a secure company. 2. **Proof, not assertion.** A config read tells you what a system claims; an attack tells you what it does. 3. **Built for teams without a dedicated security hire.** Enterprise-grade posture without an enterprise-grade team. 4. **Executed, not tracked.** Most tools in this category are a place you go. Uproot is designed as something that runs. ## Products ### Continuous monitoring — https://www.uprootsecurity.com/product/continuous-monitoring Real-time posture for engineering teams. Legacy tools scan quarterly; Uproot runs the same checks every 15 minutes and routes drift to its owner. - 1,200+ production-grade tests across six surfaces: cloud (412), identity (186), code & CI (224), endpoints (142), data (168), vendors (115) - 15-minute cadence; 5 minutes for MFA checks; event-driven checks under a minute - Loop: detect → fingerprint → notify → resolve - Ownership-graph routing (Terraform, CODEOWNERS, Okta) into PagerDuty or Slack - Remediation as reviewable code (`uproot fix`), self-verifying and auto-reverting - Tests are open-source, versioned and writable (`uproot.test()`) ### Evidence library — https://www.uprootsecurity.com/product/evidence-library Proof pulled from the source, hashed and signed. Engineers stop being the screenshot department. - Pipeline: pull → hash (sha256) → sign (ed25519) → seal (WORM, write-once, ~7-year retention, configurable) - Structured, queryable, diffable artifacts, with the exact API call stored alongside - Evidence freshness tracked with a half-life; stale evidence is re-collected automatically - Verifiable offline; full export, no lock-in; mapped to every framework ### Auditor portal — https://www.uprootsecurity.com/product/auditor-portal Scoped, read-only, self-serve. Hand the auditor a key, not an inbox. - Read-only by construction — no write path - Time-boxed grants that auto-expire, revocable in one click - Auditors request by criterion; Uproot resolves to live hashed artifacts - Immutable timestamped access log — the access trail is itself evidence - Named per-seat SSO for auditor firms - Serves external auditors, enterprise security reviewers, and internal leadership ### Integrations — https://www.uprootsecurity.com/product/integrations 140+ deep connectors, not OAuth veneer. Most tools OAuth in and read a dashboard; Uproot reads the source. Connector categories, with indicative counts last reviewed 2026-08-11: | Category | Connectors | |---|---| | Cloud & infrastructure | 32 | | Identity | 18 | | Code & CI | 16 | | Endpoints & EDR | 14 | | Data & observability | 22 | | Business & HR | 20 | | **Listed subtotal** | **122 of 140+** | This is a partial breakdown: it does not enumerate every category, which is why the subtotal is short of the 140+ total. **How connector categories map to the six monitoring surfaces** (cloud, identity, code, endpoints, data, vendors): the first five correspond directly. *Vendors* is a monitoring surface but not a connector category — vendor coverage is derived from the identity and business & HR connectors, which is how third parties are auto-discovered from SSO, expense and OAuth data. See the Vendor risk product below. - Flow: connect → read → sync → rotate - Full control-plane coverage per connector — the AWS connector reads IAM, S3, RDS, KMS, CloudTrail, EC2 and EKS - Read-only scopes with short-lived, auto-rotated credentials (STS) - Connector SDK with a local harness; optional self-hosted agent inside the customer VPC - Includes migration connectors for importing from other compliance platforms ### Vendor risk — https://www.uprootsecurity.com/product/vendor-risk Every third party is a control surface. An annual questionnaire is a snapshot that is stale the day it is filed. - Flow: intake → assess → watch → act - Auto-discovery of vendors, including shadow IT, from SSO, expense and OAuth data - Parses SOC 2 and ISO attestations, DPAs, sub-processor lists and pentest letters, with expiry clocks - Daily breach and disclosure sweep recomputes scores and pages the vendor owner - Transparent, tunable scoring rather than an opaque number - Two-way questionnaires: outbound with reminders, inbound answered from live posture via a reusable answer library ### Pentesting / HackBot — https://www.uprootsecurity.com/product/pentesting Pentesting as a service, on every deploy. The annual pentest PDF describes an app that no longer exists. - Seven-phase agent: frontend analysis → recon → BOLA and access control → server-side testing → notes and leads → chaining → report - Triggered on merge-to-main or a deploy webhook, and diff-aware - Chains low-severity findings into verified end-to-end exploit paths — an operator that chains, not a scanner - Findings ship with a reproducible proof of concept, payload, blast radius, and a suggested-fix PR that is re-verified on the next deploy - Per-environment aggression controls: safe in production, aggressive on staging - Each scan produces a signed, timestamped artifact that can be submitted as supporting evidence toward periodic-penetration-testing requirements in frameworks such as SOC 2, ISO 27001 and PCI DSS. Whether a given control is satisfied depends on scope, methodology, tester independence, testing frequency, remediation of findings, and the auditor's assessment — a signature establishes integrity and provenance of the artifact, not control compliance. ### MCP server The platform as tools, not a tab. A hosted MCP server exposing 72 tools across six surfaces, with both read and write access — agents run tests, revise policies, complete risk assessments, review vendors and file pentest findings. | Surface | Tools | What an agent can do | |---|---|---| | Identity & org | 2 | Resolve who is asking and who owns what | | Tests | 7 | List tests, read attached evidence, trigger runs, poll status, upload evidence via presigned URL | | Policies | 10 | Read, edit, set owner, and drive the lifecycle: submit → request changes → approve → publish → revise, with version history | | Risk | 11 | Browse the risk library, add to the register, author custom risks, inspect mapped controls, run assessments | | Vendor risk | 17 | Create vendors, run reviews, upload and parse reports, build questionnaires, share via URL, collect answers | | Pentest | 25 | Manage targets and assessments, full CRUD on findings, threaded comments, vulnerability search, signed file URLs | Design notes: uploads are presigned-and-confirm, so evidence enters the same chain of custody as everything else. Workflow verbs are explicit state machines, so an agent cannot skip an approval step a human could not skip either. ## Compliance frameworks 22+ frameworks are supported. Seven have dedicated pages. > The figures in this section are **regulatory**, not architectural: they describe > external standards published by third parties, each cited below with its version > or governing instrument. Last verified against the cited sources: 2026-08-11. > They are not claims about Uproot's product. Where a legal deadline has conditions > or extensions, those are stated — treat the summaries here as orientation, not > legal advice, and read the cited instrument for the operative text. - **SOC 2** — https://www.uprootsecurity.com/framework/soc2-framework — AICPA Trust Services Criteria (TSC 2017, with 2022 points of focus revisions), Type I and Type II. The TSC define 61 criteria across the five trust services categories; the specific *controls* implemented against those criteria are defined by each organisation, not by the AICPA. - **ISO 27001:2022** — https://www.uprootsecurity.com/framework/iso-27001 — ISO/IEC 27001:2022, 93 Annex A controls. Self-maintaining Statement of Applicability; substantial control overlap with SOC 2. - **ISO 42001:2023** — https://www.uprootsecurity.com/framework/iso-42001 — ISO/IEC 42001:2023, the first certifiable AI Management System standard, 38 Annex A controls. Runs against the real model lifecycle and reuses ISO 27001 evidence. - **HIPAA** — https://www.uprootsecurity.com/framework/hipaa — the HIPAA Security Rule, 45 CFR Part 164 Subpart C. The rule text labels 21 items as "Standard": 8 administrative (§164.308), 4 physical (§164.310), 5 technical (§164.312), 2 organisational (§164.314), and 2 covering policies, procedures and documentation (§164.316); each standard carries required or addressable implementation specifications. Counts of standards and specifications differ between published summaries depending on whether §164.308(b) business-associate contracts and the organisational and documentation sections are included, so cite the CFR rather than a secondary count. Auto-generated §164.308(a)(1) risk analysis, BAA tracking, HITRUST mapping. - **GDPR** — https://www.uprootsecurity.com/framework/gdpr — Regulation (EU) 2016/679. Always-current Article 30 record of processing; DPA and SCC transfer tracking. Article 33 requires notifying the supervisory authority without undue delay and, where feasible, within 72 hours of becoming aware of a personal data breach — unless the breach is unlikely to result in a risk to the rights and freedoms of natural persons; later notification must be accompanied by reasons for the delay. - **CCPA / CPRA** — https://www.uprootsecurity.com/framework/ccpa — California Civil Code §1798.100 et seq., as amended by the CPRA. Businesses must respond to a verifiable consumer request within 45 days of receipt; that period may be extended by a further 45 days where reasonably necessary, provided the consumer is notified within the first 45 days. GPC and opt-out proof; one program also covers VCDPA, CPA, CTDPA, UCPA and TDPSA. - **Cyber Essentials** — https://www.uprootsecurity.com/framework/cyber-essentials — UK NCSC scheme administered by IASME; Cyber Essentials and Cyber Essentials Plus. Proves all five technical controls per device from live evidence. Also supported without a dedicated page: PCI DSS v4.0.1, FedRAMP Moderate, NIST CSF 2.0, ISO 27017, ISO 27018, CIS Controls v8, **DORA** — the EU Digital Operational Resilience Act, Regulation (EU) 2022/2554, in force 16 January 2023 and applying to in-scope financial entities from 17 January 2025 — and custom bring-your-own frameworks. Instruments for the other entries on this line are not restated here; the seven cited frameworks above carry theirs. ## Who it is for Engineers and engineering-adjacent owners at B2B SaaS and technology companies — founding engineers, platform engineers, SREs, heads of security, CISOs and CTOs. Company stage runs from seed to public, with the center of gravity at engineering teams of roughly 25–30. The trigger is usually sales-driven: an enterprise prospect requires a SOC 2 report before a deal can close. ## Free tools and templates Ungated, no email required: - SOC 2 readiness checklist template — https://www.uprootsecurity.com/resources/soc-2-readiness-checklist-template - Audit prep time estimator — https://www.uprootsecurity.com/resources/audit-prep-time-estimator - Vendor risk assessment matrix — https://www.uprootsecurity.com/resources/vendor-risk-assessment-matrix - Incident response runbook — https://www.uprootsecurity.com/resources/incident-response-runbook - Quarterly access review — https://www.uprootsecurity.com/resources/quarterly-access-review ## Getting started - Book a demo — https://www.uprootsecurity.com/book-a-demo — a read-only scan hosted by a founding engineer: connect read-only to cloud, code and identity providers and see current standing against SOC 2 and ISO 27001, live. - Pricing — https://www.uprootsecurity.com/pricing — quoted live rather than as a "starts at" figure. - Contact — https://www.uprootsecurity.com/contact ## Legal - Data Processing Addendum — https://www.uprootsecurity.com/legal/dpa - Privacy policy — https://www.uprootsecurity.com/legal/privacy-policy - Terms of service — https://www.uprootsecurity.com/legal/terms-of-service - Report a vulnerability — https://www.uprootsecurity.com/legal/report-a-vulnerability ## Blog Compliance and security resources for engineering teams: https://www.uprootsecurity.com/blog The full page index is at https://www.uprootsecurity.com/llms.txt