[frameworks]
Seven frameworks. One best-in-class review engine.
Autometric layers named framework enforcement onto the same review system already catching bugs, security flaws, performance regressions, style issues, and linked task gaps.
[framework evidence]
Review depth stays on. Framework evidence layers in.
SOC 2
CC6, CC7, CC8 review pack active
PCI DSS 4.0
Requirement 6 mapped to repository rules
FedRAMP
AU, CM, SI controls attached to findings
[what enforcement means]
Turn framework enforcement on only for the repositories that need it.
Mark a repository in scope and Autometric adds the relevant control mapping, evidence output, and stricter merge behavior for that framework. The core review engine for bugs, security, performance, and style still runs underneath it.
[what stays constant]
Best-in-class review stays on, with framework enforcement built into the same flow.
Autometric starts with a serious reviewer for bugs, security, performance, style, and risky data handling. Framework enforcement adds control mapping, evidence, and merge policy on top of that same review flow. Linked task context can stay attached to the same evidence chain when a PR references a bug or feature ticket.
CC7.2
SOC 2
Map review findings to trust-services-criteria controls without sacrificing general bug and security review quality.
6.2.4
PCI DSS 4.0
Catch risky payment-code changes with named PCI context while keeping the full review engine active.
164.312(b)
HIPAA
Bring technical-safeguard context into code review for systems that can expose PHI or patient workflows.
A.8.32
ISO 27001
Add ISO control awareness to review evidence without downgrading day-to-day engineering review quality.
Art. 25
GDPR
Use code review to reinforce privacy-by-design practices while still catching the broader engineering issues that create delivery risk.
SI-10
FedRAMP
Bring control-family enforcement to pull requests while preserving the review quality required for regulated federal workloads.
AU-6
NIST 800-53
Use control-family-aware code review without giving up broad engineering review for bugs, security, and reliability.