Architecture
AuditToolkit runs on a producer-consumer architecture. Specialised tools collect data from every layer of your infrastructure and deliver it to a central platform that correlates, remediates, and reports — without any of that data leaving your environment.
Cloud platforms, on-premises servers, network devices, and endpoints are discovered automatically across 40+ vendor connectors — SSH, WinRM, SNMP, NETCONF, and REST API. No manual asset lists to maintain.
Six repos work together here: the AuditToolkit core platform plus five purpose-built producers — Aldian, Taldian, Findian, Ladian, and the Sothian — each covering a distinct infrastructure layer and delivering normalised findings under a shared data contract. This is the architecture, not the licence: Taldian feeds the platform but is an independent product and is not covered by the AuditToolkit Platform licence.
The Sothian executes PowerShell and shell audit scripts across any SSH- or WinRM-accessible host. Every result is wrapped in an HMAC-signed, SHA-256 verified evidence bundle before it leaves the host — integrity guaranteed from point of collection.
All producer data arrives at the central AuditToolkit platform, is normalised to a common schema, correlated across sources into unified host records, and automatically mapped to CIS Benchmarks, PCI-DSS, SOC 2, NIST SP 800-53, and ISO 27001 controls — in a single pass.
Dashboards show current compliance posture across every audited host. Differential reports compare any two assessment runs. 30/60/90-day trend analysis tracks improvement across the estate — and surfaces regressions before they become audit findings.
Tamper-evident evidence packages are assembled and signed on demand — SHA-256 checksums on every artifact, provenance metadata on every finding, a MANIFEST.json auditors can verify independently. What used to take weeks to assemble takes minutes.
Every collection run is compared against the prior baseline. Regressions surface automatically. Findings flow to your SIEM, tickets open in your ITSM, and alerts land in Slack or Teams — so the rest of the organisation stays in the loop without changing how they work.
Platform Architecture
The Control Plane orchestrates specialised tools that operate independently across your infrastructure. Each tool collects from a distinct layer — discovery, audit, network, asset inventory — and feeds findings into the central platform for correlation, remediation, and evidence generation. The diagram shows how the tools interoperate; it is not a statement of licence coverage.
Architecture Model
Each satellite producer operates independently and can be deployed where it has the best access to its target infrastructure. The central platform sees everything — regardless of which producers are active or how many are running.
Aldian · Sothian · Taldian · Findian · Ladian
Ingest · Normalise · Correlate · Remediate · Report · Package evidence
producer-output.schema.json). The central platform and every producer negotiate a schema version on delivery —
preventing silent data corruption across upgrades.
Deployment
Every deployment path keeps data in your environment. No cloud dependency. No telemetry by default.
| Mode | How it deploys | Best for |
|---|---|---|
| Linux server (native) | Application installed directly on Ubuntu, Debian, or RHEL — PostgreSQL + Redis + Nginx | Production deployments with full control over the host stack |
| VM appliance | Ready-to-import OVF, OVA (VMware), or VHDX (Hyper-V) — boot and configure | Rapid enterprise deployment to existing virtualisation infrastructure |
| Docker Compose | Container stack for test and staging environments | Evaluation, development, and pre-production validation |
| Agent-based (air-gap) | HTTPS push agents on endpoints — agent initiates outbound connection, no inbound firewall rules required. Offline MSI available. | Restricted networks, air-gapped environments, endpoints without SSH or WinRM |
Platform Security
AuditToolkit holds credentials, configuration data, and compliance findings. The platform is built to the same security standard it applies to the systems it audits.
The Community tier covers one host at no cost. Or contact us to design the right deployment path for your estate.