Evidence Vault & Auditor Portal
Paths: /reports (Evidence) · /portal/[id] (Auditor Portal) · Sidebar: Reporting
For audits and incident reviews, apPosture produces immutable, citable evidence and a read-only portal you can share with an auditor - without giving them access to the platform.
Evidence packages
Generate a self-contained package for a finding, application or scope, containing:
- the proof-of-exploit (PoC request/response) or precise code location,
- the control mapping (which OWASP/PCI/ISO/NIST/SOC2/HIPAA/GDPR clauses),
- remediation status, owner and timeline,
- the audit trail of who did what, when.
Evidence is privacy-aware - PII / credentials are masked in reports and AI output.
Auditor Portal
A scoped, read-only share link (/portal/[id]) lets an external auditor see
exactly the evidence you choose - findings, posture, compliance coverage and the
immutable trail - with no login to the main app and no ability to change anything.
- Scoped - share a single app, a compliance scope, or a report.
- Time-boxed - links can expire.
- Tamper-evident - the underlying audit log is append-only.
Why it matters
Audits usually mean screenshots and spreadsheets. The Evidence Vault makes the answer to "prove you tested this and fixed it" a one-click, defensible package - backed by real proof, not assertions. Pair it with Compliance & Maturity for the framework view and Scorecards for the grade.