Evidence
A central, audit-ready store for the proof that your controls are actually working.
Evidence is where you keep the artefacts that demonstrate your compliance programme in action: a screenshot of a configuration, a supplier's certificate, an access review log, a penetration test report. Instead of hunting through email and shared drives at audit time, you upload each item once, describe it, and link it to everything it supports.
What an evidence item holds
- The file — a screenshot, certificate, log export, PDF report or similar.
- Type — so you can tell a policy sign-off from a scan result at a glance.
- Collected date — when the evidence was captured, so you can prove it is current.
- Owner — the person accountable for keeping it up to date.
The power is in linking
A single piece of evidence rarely stands alone. Attach it to the controls, risks, incidents and vendors it supports, so when an auditor says "show me", it is one click away — and each of those records shows exactly what backs it up.
Upload the evidence
Add the file, choose a type, set the collected date and assign an owner.
Link it to what it proves
Attach the item to the controls, risks, incidents or vendors it supports.
Retrieve it on demand
When an auditor asks, open the record and produce the proof in one click.
Works with
- Controls — show the implementation evidence behind each control.
- Audits — hand evidence straight to your auditor.
- Risk Register — back up mitigations with proof they are in place.
- Third Parties — store supplier certificates and assurance reports.