Compliance evidence
Access reviews, signed audit exports and evidence by framework that quotes your workspace's own numbers. Evidence for your auditor, not a certification.
Compliance in the console collects evidence from your workspace. It does not certify you, and nothing on it says a framework is met.
Access reviews
Start review snapshots every role grant, for people and machine identities: who, which role, where. Leave the name empty to use the current quarter's, for example Q3 2026 access review, numbered (2) when a review already has that name.
Confirm or revoke each grant. Revoke access removes the grant at once and is final for that review. You can't revoke your own grant, only an owner revokes another owner's, and the workspace's last owner stays.
A machine identity's grant is its role. Revoke access on its row opens the identity: revoke it there, which also revokes its credentials. Back in the review, Revoke access then records the grant as revoked.
Close and seal unlocks once nothing is left to decide. We hash the result and sign it.
| Action | Needs |
|---|---|
| View reviews and evidence by framework | audit:read |
| Start, decide, close | member:role_assign |
| Download a record or an audit export | audit:export |
Signed exports
A closed review (Download signed record) and a period of the audit log (Export signed evidence, the current quarter by default; the end date is not included) download as one JSON file. A period holds up to 50,000 entries. Each file holds body, the exact bytes we sealed, and seal.
seal field | Content |
|---|---|
digest | SHA-256 of body, hex |
signature | Ed25519 over the digest string, base64. null when the deployment holds no evidence key |
keyId | First 16 bytes of the SHA-256 of the public key, hex |
publicKeyPem | The key to verify with |
Verify a file with jq and OpenSSL 3:
jq -j .body evidence.json | sha256sum # equals .seal.digest
jq -j .seal.digest evidence.json > digest.txt
jq -r .seal.signature evidence.json | base64 -d > sig.bin
jq -r .seal.publicKeyPem evidence.json > key.pem
openssl pkeyutl -verify -pubin -inkey key.pem -rawin -in digest.txt -sigfile sig.binEach export writes its own audit entry: access_review.exported or audit.evidence_exported.
Evidence by framework
One tab each for SOC 2, ISO/IEC 27001, POPIA and NDPA lists the controls we can show evidence for. We read every number when you open the page.
| Evidence | What it quotes |
|---|---|
| Two-factor | Active members with an authenticator app or a passkey, whether the workspace requires one, and whether sign-in goes through your identity provider |
| Access reviews | When the last review closed, and whether its export is signed |
| Machine identities | Live identities; revoked ones are left out (SOC 2 only) |
| Change management | Environments that require a second approver, and write-only environments |
| Logging | Your plan's audit retention |
| Encryption | A fixed statement of how we seal values, not a reading |
Hand them to your auditor beside the signed exports.
Plans
Enterprise, or Pro with the Compliance evidence add-on (plans). Without it you can't start a review or export a period, but reviews already opened stay listed: you can finish them and download their records.
The audit log
We record every secret, credential, member, billing and configuration action as an append-only entry that nobody in your workspace can edit or delete.
Secret scanning
We scan your connected GitHub repositories daily for committed credentials. We store where each one sits and a keyed hash, never the credential.