Compliance / PCI DSS 4.0
PCI DSS 4.0 requires defined methodology, internal and external penetration testing, segmentation testing, and remediation tracking — all evidenced. SecHive turns that list into a single auditable bundle.
The mapping is intentionally narrow. We list only the articles where SecHive produces a directly defensible artifact, and we name the artifact.
| Article / control | What it requires | SecHive artifact |
|---|---|---|
| 11.4.1 | Penetration testing methodology defined and followed. | SecHive methodology spine published per engagement; bound to proof pack. |
| 11.4.2 | Internal penetration testing performed at least annually. | Internal-mode runs with scope policy and approval checkpoints. |
| 11.4.3 | External penetration testing at least annually. | External-mode runs with redaction-safe report and retest tracker. |
| 11.4.4 | Exploitable vulnerabilities and security weaknesses corrected. | Per-finding remediation guidance, retest record, and re-attestation. |
| 11.4.5 | Segmentation testing — segmentation methods are operational and effective. | Cross-segment hypothesis testing with traversal evidence and refutation log. |
| 11.4.6 | Service providers — additional segmentation testing every 6 months. | SecHive supports cadence-based reruns of the same proof pack. |
| 6.4.x | Application-layer security testing for public-facing apps. | Web application run mode with API security and source candidate separation. |
What you can put in front of an auditor or a security review.
replay.sh per finding.SecHive renders an evidence matrix per engagement. Below is one row, redacted.
# evidence-row.yaml — redacted control: PCI 11.4.5 # effectiveness testing finding_id: VTX-RPL-0042 mode: black-box target: redacted target_ref: image@sha256:9c4e… # pinned artifact: path: artifacts/replay.sh sha256: 7c3a… signed: cosign:sechive-key disposition: reviewer: redacted-operator state: confirmed retest: status: fixed @ 2026-04-18 evidence: artifacts/retest-receipt.json
Bring the scope and the auditor's evidence list. We will produce the technical artifacts.