Penv Cloud
Start free
Docs
Conceptsince cloud@2026-09-25

Compliance evidence

Access reviews, signed audit exports and evidence by framework that quotes your workspace's own numbers. Evidence for your auditor, not a certification.

Compliance in the console collects evidence from your workspace. It does not certify you, and nothing on it says a framework is met.

Access reviews

Start review snapshots every role grant, for people and machine identities: who, which role, where. Leave the name empty to use the current quarter's, for example Q3 2026 access review, numbered (2) when a review already has that name.

Confirm or revoke each grant. Revoke access removes the grant at once and is final for that review. You can't revoke your own grant, only an owner revokes another owner's, and the workspace's last owner stays.

A machine identity's grant is its role. Revoke access on its row opens the identity: revoke it there, which also revokes its credentials. Back in the review, Revoke access then records the grant as revoked.

Close and seal unlocks once nothing is left to decide. We hash the result and sign it.

ActionNeeds
View reviews and evidence by frameworkaudit:read
Start, decide, closemember:role_assign
Download a record or an audit exportaudit:export

Signed exports

A closed review (Download signed record) and a period of the audit log (Export signed evidence, the current quarter by default; the end date is not included) download as one JSON file. A period holds up to 50,000 entries. Each file holds body, the exact bytes we sealed, and seal.

seal fieldContent
digestSHA-256 of body, hex
signatureEd25519 over the digest string, base64. null when the deployment holds no evidence key
keyIdFirst 16 bytes of the SHA-256 of the public key, hex
publicKeyPemThe key to verify with

Verify a file with jq and OpenSSL 3:

jq -j .body evidence.json | sha256sum          # equals .seal.digest
jq -j .seal.digest evidence.json > digest.txt
jq -r .seal.signature evidence.json | base64 -d > sig.bin
jq -r .seal.publicKeyPem evidence.json > key.pem
openssl pkeyutl -verify -pubin -inkey key.pem -rawin -in digest.txt -sigfile sig.bin

Each export writes its own audit entry: access_review.exported or audit.evidence_exported.

Evidence by framework

One tab each for SOC 2, ISO/IEC 27001, POPIA and NDPA lists the controls we can show evidence for. We read every number when you open the page.

EvidenceWhat it quotes
Two-factorActive members with an authenticator app or a passkey, whether the workspace requires one, and whether sign-in goes through your identity provider
Access reviewsWhen the last review closed, and whether its export is signed
Machine identitiesLive identities; revoked ones are left out (SOC 2 only)
Change managementEnvironments that require a second approver, and write-only environments
LoggingYour plan's audit retention
EncryptionA fixed statement of how we seal values, not a reading

Hand them to your auditor beside the signed exports.

Plans

Enterprise, or Pro with the Compliance evidence add-on (plans). Without it you can't start a review or export a period, but reviews already opened stay listed: you can finish them and download their records.