IP Library Granted Patent US 12694113
Granted Patent B1
US 12694113 · App. 17/898,294 · Granted Jul 28, 2026

Third party real-time security and compliance monitoring platform

Inventors: Brian S. Elmi (San Diego, CA); Ross W. Hosman (Colorado Springs, CO); Adam R. Markowitz (Carlsbad, CA); Daniel Zev Marashlian (San Diego, CA)
Assignee: DRATA INC.
G06F21/57G06F2221/2101G06F2221/2115
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12694113
App. No.
17/898,294
Granted
Jul 28, 2026
Kind
B1
Abstract

Third party real-time security and compliance monitoring including receiving, by a security and compliance monitor, a request from a vendor client for a security and compliance framework report for a vendor; generating, in real-time by the security and compliance monitor, the security and compliance framework report for the vendor, including: retrieving, by the security and compliance monitor, control status responses from a group of services providers of the vendor, wherein each control status response is associated with an element of the security and compliance framework report; and determining, by the security and compliance monitor based on the control status responses, a compliance status for the elements of the security and compliance framework report; and providing, to the vendor client by the security and compliance monitor, the security and compliance framework report generated in real-time.

Claims (37)

1 . A method of third party real-time security and compliance monitoring, the method comprising:

receiving, by a security and compliance monitor, a request from a vendor client for a security and compliance framework report for a vendor, wherein the security and compliance framework report comprises a plurality of elements indicative of a compliance status, wherein the vendor client and the vendor are separate entities, and wherein the vendor employs the security and compliance monitor to generate the security and compliance framework report on behalf of the vendor;

generating, by the security and compliance monitor in real-time dynamically upon receiving the request, the security and compliance framework report for the vendor, including:

retrieving, by the security and compliance monitor, control status responses from a group of services providers of the vendor, wherein each control status response describes a state of a particular control within a services provider from the group of services providers of the vendor and is associated with an element within the plurality of elements of the security and compliance framework report, and wherein retrieving the control status responses from the group of services providers of the vendor comprises issuing a control status request to the group of services providers and receiving, in response, the control status response; and

determining, by the security and compliance monitor based on the control status responses, the compliance status for each element within the plurality of elements of the security and compliance framework report; and

providing, to the vendor client by the security and compliance monitor, the security and compliance framework report generated in real-time.

2 . The method of claim 1 , further comprising:

detecting a change in compliance status for one element of the security and compliance framework report; and

updating the security and compliance framework report with the compliance status change, wherein the vendor client receives the updated security and compliance framework report in real-time.

3 . The method of claim 1 , wherein providing, to the vendor client, the security and compliance framework report generated in real-time comprises presenting a failed compliance status at a delay based on a service level agreement.

4 . The method of claim 1 , wherein retrieving the control status responses from the group of services providers of the vendor comprises receiving authorization from the vendor to access the group of services providers.

5 . The method of claim 1 , wherein receiving the request from a vendor client for the security and compliance framework report for a vendor comprises receiving authorization from the vendor to provide the security and compliance framework report to the vendor client.

6 . The method of claim 1 , wherein providing, to the vendor client, the security and compliance framework report generated in real-time comprises granting, to the vendor client, access to a storage location that includes the security and compliance framework report.

7 . The method of claim 1 , wherein generating, in real-time, the security and compliance framework report for the vendor further comprises retrieving the control status responses from the group of services providers of the vendor after receiving the request for the security and compliance framework report.

8 . The method of claim 1 , wherein the control status response comprises a state specification.

9 . The method of claim 1 , wherein the group of services providers comprise a cloud services provider.

10 . An apparatus for third party real-time security and compliance monitoring, the apparatus comprising a computer processor, a computer memory operatively coupled to the computer processor, the computer memory comprising computer program instructions that, when executed by the computer processor, cause the apparatus to carry out:

receiving a request from a vendor client for a security and compliance framework report for a vendor, wherein the security and compliance framework report comprises a plurality of elements indicative of a compliance status, wherein the vendor client and the vendor are separate entities, and wherein the vendor employs the security and compliance monitor to generate the security and compliance framework report on behalf of the vendor;

generating, in real-time dynamically upon receiving the request, the security and compliance framework report for the vendor, including:

retrieving control status responses from a group of services providers of the vendor, wherein each control status response describes a state of a particular control within a services provider from the group of services providers of the vendor and is associated with an element within the plurality of elements of the security and compliance framework report, and wherein retrieving the control status responses from the group of services providers of the vendor comprises issuing a control status request to the group of services providers and receiving, in response, the control status response; and

determining, based on the control status responses, the compliance status for each element within the plurality of elements of the security and compliance framework report; and

providing, to the vendor client, the security and compliance framework report generated in real-time.

11 . The apparatus of claim 10 , further comprising computer program instructions that, when executed by the computer processor, cause the apparatus to carry out:

detecting a change in compliance status for one element of the security and compliance framework report; and

updating the security and compliance framework report with the compliance status change, wherein the vendor client receives the updated security and compliance framework report in real-time.

12 . The apparatus of claim 10 , wherein providing, to the vendor client, the security and compliance framework report generated in real-time comprises presenting a failed compliance status at a delay based on a service level agreement.

13 . The apparatus of claim 10 , wherein retrieving the control status responses from the group of services providers of the vendor comprises receiving authorization from the vendor to access the group of services providers.

14 . The apparatus of claim 10 , wherein receiving the request from a vendor client for the security and compliance framework report for a vendor comprises receiving authorization from the vendor to provide the security and compliance framework report to the vendor client.

15 . The apparatus of claim 10 , wherein providing, to the vendor client, the security and compliance framework report generated in real-time comprises granting the vendor client access to a storage location that includes the security and compliance framework report.

16 . The apparatus of claim 10 , wherein generating, in real-time, the security and compliance framework report for the vendor further comprises retrieving the control status responses from the group of services providers of the vendor after receiving the request for the security and compliance framework report.

17 . The apparatus of claim 10 , wherein the control status response comprises a state specification.

18 . A computer program product for third party real-time security and compliance monitoring, the computer program product disposed upon a non-transitory computer readable medium, the computer program product comprising computer program instructions that, when executed, cause a computer to carry out:

receiving a request from a vendor client for a security and compliance framework report for a vendor, wherein the security and compliance framework report comprises a plurality of elements indicative of a compliance status, wherein the vendor client and the vendor are separate entities, and wherein the vendor employs the security and compliance monitor to generate the security and compliance framework report on behalf of the vendor;

generating, in real-time dynamically upon receiving the request, the security and compliance framework report for the vendor, including:

retrieving control status responses from a group of services providers of the vendor, wherein each control status response describes a state of a particular control within a services provider from the group of services providers of the vendor and is associated with an element within the plurality of elements of the security and compliance framework report, and wherein retrieving the control status responses from the group of services providers of the vendor comprises issuing a control status request to the group of services providers and receiving, in response, the control status response; and

determining, based on the control status responses, the compliance status for each element within the plurality of elements of the security and compliance framework report; and

providing, to the vendor client, the security and compliance framework report generated in real-time.