Compliance Evidence

Compliance evidence that auditors accept. Generated automatically. Every run.

What the evidence package contains

Every audit run produces a tamper-evident evidence package that can be handed directly to an external auditor.

Artifact Description
Audit output files Raw and normalised findings per control check
Configuration snapshots System state at time of audit
SHA-256 checksums Integrity verification for every artifact
MANIFEST.json Structured index of all package contents
SHA256SUMS.txt Flat checksum file for auditor verification
Framework mapping Findings organised by PCI-DSS, SOC 2, NIST, CIS references
Digital signature Package signing for chain-of-custody
README for auditors Human-readable guide to package structure

Trend and trajectory reporting

Framework coverage

Single execution, multiple frameworks. A single audit run produces evidence mapped across every framework simultaneously — no double-running, no manual cross-referencing. One evidence package covers every framework your organisation reports against.

Remediation evidence

EDR & endpoint protection validation

Cyber insurance renewals and supply chain security questionnaires increasingly require evidence that endpoint detection and response tools are installed, current, and active across your estate. AuditToolkit validates EDR health as part of the compliance audit and includes the results in evidence packages.

Each validation check maps to the relevant compliance controls — CIS, NIST, and cyber insurance policy requirements — and is included automatically in the evidence package for the assessment run.

API endpoints for evidence automation