getting started

Your first audit

Hand your auditor the evidence ZIP and the executive summary PDF.

Every evidence run produces two artifacts: a PDF executive summary and a ZIP of raw evidence JSON. Both are downloadable from the Reports page and signed with a SHA-256 manifest.

What auditors look for

  • Run was triggered within the audit window
  • Evidence covers every in-scope subscription
  • Failing controls have documented remediation