Execution & Assurance Evidence
Verifiable, tamper-evident audit evidence at fleet scale. Sothian dispatches audit scripts across large host inventories in parallel, validates the results against a defined contract, and signs them into structured evidence bundles — a defensible chain of custody for compliance and third-party audit.
Sothian produces verifiable, tamper-evident audit evidence. Its value is assurance: not just running audits, but generating signed evidence bundles that prove what was audited, when, and that the results have not been altered since collection — a defensible chain of custody for compliance, governance and third-party audit.
Sothian supports the suite; it does not replace any part of it. It coordinates execution and packages assurance evidence. It does not run audits on the host itself — the agents do — and it does not own reporting, compliance scoring, asset inventory, scheduling or role administration, which belong to AuditToolkit. It receives jobs from the control plane and returns signed evidence; it never supersedes it.
For the layering in full, see Suite Architecture →
Evidence Flow
| Item | Detail |
|---|---|
| Current version | v1.2.3 |
| Deployment modes | An integrated execution tier under AuditToolkit, or a standalone service with local licence validation |
| Execution | Shell and PowerShell dispatched to target hosts through transport-neutral adapters |
| Output | Validated results signed into structured evidence bundles with a chain of custody |
| Operator console | Focused on coordination and assurance, deliberately not on platform features |
| Documentation | Overview, deployment, execution adapters, evidence and integrity, operations, security |
Sothian is one of the products carried by the AuditToolkit Platform Suite licence. It is not sold separately: a Platform Suite subscription covers it, priced by host capacity rather than per node.
It can also run as a standalone service with local licence validation, which is how segmented and air-gapped estates operate it where the control plane cannot be reached directly.