Evidences
An evidence is anything that substantiates a claim: a policy export, a screenshot, a configuration dump, a signed approval, a link to a ticket or a monitoring dashboard. Evidence is the connective tissue between what a framework asks and what your organisation actually does — and because one record can back many requirements at once, a single penetration-test report can satisfy the equivalent clause in every framework you are audited against, with no duplication.
Where to find it
Section titled “Where to find it”Compliance → Evidences in the sidebar. The list shows Name, Domain, Owner, Status, Updated at, Labels and the Applied controls each evidence backs, and can be filtered by domain, status, owner and label.
What an evidence holds
Section titled “What an evidence holds”| Field | Notes |
|---|---|
| Name and Description | What the proof is, and why it proves it |
| Domain | Drives who can see it |
| Owner | The actor accountable for keeping it current |
| Status | Draft, Missing, In review, Approved, Rejected, Expired |
| Expiry date | For proof with a shelf life — a yearly report, a certificate |
| Attachment | The uploaded file |
| Link | An external URL, as an alternative or a complement to the file |
| Labels | Free-form tags for grouping and filtering |
Missing is a deliberately useful status: create the record before the file exists so the gap shows up in reports instead of hiding as an absence.
Attaching evidence to your work
Section titled “Attaching evidence to your work”Evidence is the shared substantiation surface, so the same record can be linked from several places at once:
- Requirement assessments — proof that a specific compliance requirement is met. Link it from the requirement’s page, or inline from Table mode.
- Applied controls — proof that the control is in place and operating. See Applied controls.
- Findings and findings binders — proof attached to an issue or its remediation.
- Audits as a whole — cross-cutting evidence that belongs to the assessment rather than to one requirement.
- Security exceptions, contracts and timeline entries.
Links are reciprocal: open an evidence and you can see everything it substantiates, which is what makes coverage questions answerable — “what would break if this file were wrong?”
Pasting from the clipboard
Section titled “Pasting from the clipboard”The Attachment field accepts a paste. With a screenshot on your clipboard, select the field and paste — the image becomes the attachment directly, with no intermediate file on disk. It is the fastest route from seeing the proof on screen to having the proof in the audit. See Evidences from clipboard.
Revisions
Section titled “Revisions”Evidence is not attached once and forgotten. Replacing an attachment does not overwrite the previous file — it creates a new revision under the same evidence record, and the evidence keeps its identity and all its links. Each revision carries:
- A version number that increments automatically.
- The attachment or the link for that version.
- A SHA-256 hash of the attachment, computed on upload and used for integrity checks.
- An observation explaining what changed.
- An optional back-link to the task occurrence that produced it, when a recurring task generated the file.
The evidence page always shows the latest revision, and the Revisions tab lists the whole chain. This is what lets you answer an assessor asking what proof did you hold on this date? — the historical version is still there, hash included.
Related
Section titled “Related”- Audits — where the requirement links come from.
- Exports — the bundle export ships every attached file alongside the report.
- Applied controls — the other side of most evidence links.
- Policies — published documents that often double as evidence.
