Compliance Evidence
Every audit run produces a tamper-evident evidence package that can be handed directly to an external auditor.
| Artifact | Description |
|---|---|
| Audit output files | Raw and normalised findings per control check |
| Configuration snapshots | System state at time of audit |
| SHA-256 checksums | Integrity verification for every artifact |
| MANIFEST.json | Structured index of all package contents |
| SHA256SUMS.txt | Flat checksum file for auditor verification |
| Framework mapping | Findings organised by PCI-DSS, SOC 2, NIST, CIS references |
| Digital signature | Package signing for chain-of-custody |
| README for auditors | Human-readable guide to package structure |
Cyber insurance renewals and supply chain security questionnaires increasingly require evidence that endpoint detection and response tools are installed, current, and active across your estate. AuditToolkit validates EDR health as part of the compliance audit and includes the results in evidence packages.
Each validation check maps to the relevant compliance controls — CIS, NIST, and cyber insurance policy requirements — and is included automatically in the evidence package for the assessment run.