Is ARCO a certification tool?
No. ARCO supports audit-readiness and cloud security review. It does not certify compliance or guarantee auditor acceptance.
Product by ARCO
ARCO Governance
ARCO Governance helps teams connect AWS, scan cloud resources, evaluate security controls, track findings, collect evidence, and prepare SOC 2, HIPAA, and PCI DSS readiness reports without spreadsheet chaos.
Selected AWS teams receive guided onboarding, first-scan review, and a readiness walkthrough before workspace activation.

Built for AWS teams preparing for SOC 2, HIPAA, and PCI DSS
No AWS keys stored
Cross-account IAM role with External ID
Evidence and reports in one workspace
AWS accounts, regions, findings, evidence requests, and framework mappings are hard to manage manually. By the time an audit review starts, teams are chasing proof instead of working from a clear readiness record.
Screenshots, tickets, exports, and notes drift away from the control they support.
Teams can see activity, but not a clear audit trail across accounts and frameworks.
Findings, exceptions, and evidence requests need durable owners and status.
ARCO Governance tracks AWS accounts, resources, control evaluations, findings, evidence tasks, framework readiness, and auditor packet readiness from one command center.
No connected AWS account or scan means the workspace stays honest: awaiting first scan, not fake readiness.
Cross-account IAM role, External ID, and read-only scanner permissions.
Inventory cloud resources, evaluate controls, and surface AWS security findings.
Organize control status around SOC 2, HIPAA, and PCI DSS readiness views.
Keep evidence connected to controls and package reports when your plan allows.
See what needs attention.
Open findings, warnings, and not evaluated checks stay visible.
Track readiness by framework.
SOC 2, HIPAA, and PCI DSS views show where work remains.
Keep evidence connected to controls.
Evidence tasks stay tied to the requirements they support.
Prepare exports without chasing screenshots.
Reports and packets build from connected readiness data.
ARCO keeps readiness work continuous, explainable, and grounded in real AWS security posture management signals.
Cross-account IAM role with External ID. No customer AWS keys.
Discover resources and evaluate controls across AWS accounts.
See failed controls, warnings, not evaluated checks, and framework gaps.
Prepare audit-readiness reports, evidence tasks, and auditor packet exports.
Framework views help teams explain posture, gaps, and evidence without pretending the tool replaces auditors, counsel, or certification bodies.
Map AWS security posture to SOC 2 readiness conversations and evidence needs.
Review cloud safeguards, logging, access, and evidence for healthcare workloads.
Support payment environment reviews with resource, finding, and requirement context.
View readiness reports inside the workspace, then export CSV, PDF, or auditor packets when your plan allows.
Keep findings, requirements, evidence tasks, suppressions, and export-ready auditor packets connected to real AWS posture data for cloud audit readiness and AWS evidence collection.
CSV
ZIP
ARCO Governance uses a trust model designed for compliance-sensitive AWS teams: no long-lived customer keys, explicit role assumption, read-only scans, and tenant-scoped evidence boundaries.
Step 01
Customer-owned role grants scoped scanner access.
Step 02
Role assumption is protected against confused-deputy risk.
Step 03
Posture checks avoid write access to customer workloads.
Step 04
Readiness data and evidence boundaries stay isolated by tenant.
Step 05
Findings, tasks, exports, and exceptions support review history.
Choose the scan cadence, account coverage, and evidence workflow that fits your AWS compliance readiness program.
FOUNDING20
First 20 qualified customers get 25% off for 12 months with guided onboarding.
Single AWS account
For one AWS account moving compliance readiness out of spreadsheets.
Regular $199/mo
$149/mo
Launch pricing
Main readiness teams
For teams that need daily posture reviews and evidence packaging.
Regular $399/mo
$299/mo
Launch pricing
Multi-account teams
For multi-account teams operating continuous readiness programs.
Regular $799/mo
$599/mo
Launch pricing
Need a larger readiness program, procurement support, or custom onboarding?
Contact salesScan cadence, export volume, evidence ZIP access, and support increase as your AWS readiness program scales.
| Feature | Starter | Growth | Scale |
|---|---|---|---|
| AWS accounts | 1 | 5 | 20 |
| Scan frequency | Weekly | Daily | Every 6 hours |
| Manual rescan | 7 days | 24 hours | 6 hours |
| Report exports | 5/mo | 50/mo | 200/mo |
| Evidence ZIP | No | Yes | Yes |
| Scan history | 30 days | 90 days | 12 months |
| Support | Priority email | Priority onboarding |
Guided founding access
ARCO Governance is currently onboarding selected AWS teams through guided access. We help validate the account connection, scope the first scan, and review readiness outputs with your team.
These guides help teams understand AWS connection, scan behavior, evidence handling, and readiness reporting before applying for guided access.
Cross-account role setup, External ID protection, and read-only scanner access.
Open docs
AWS resources, security controls, findings, evidence tasks, and readiness indicators.
Open docs
How framework readiness views support audit preparation without claiming certification.
Open docs
How readiness reports, inventory exports, and evidence packages are organized.
Open docs
AWS access model, private evidence storage, tenant-scoped data, and export limits.
Open docs
Plan limits, founding access expectations, report exports, and assisted onboarding.
Open docs
ARCO is built to support AWS compliance readiness, not to overpromise certification outcomes.
No. ARCO supports audit-readiness and cloud security review. It does not certify compliance or guarantee auditor acceptance.
No. ARCO uses cross-account IAM roles and External ID. Customers do not provide long-lived AWS access keys.
Yes. Starter is designed for one AWS account with weekly scans and a focused export allowance.
Not yet. ARCO Governance is currently onboarding selected AWS teams through guided founding access so setup, first scans, and readiness outputs can be reviewed safely.
No. ARCO helps prepare findings, evidence, and reports for review, but it does not replace legal, compliance, or auditor judgment.
Request a guided walkthrough of ARCO Governance and see how your team can track findings, evidence, framework readiness, and reports before audit season.
Founding access is available for selected AWS teams after a guided demo and readiness walkthrough.