Skip to main content

Evidence Vault & Auditor Portal

Paths: /reports (Evidence) · /portal/[id] (Auditor Portal) · Sidebar: Reporting

For audits and incident reviews, apPosture produces immutable, citable evidence and a read-only portal you can share with an auditor - without giving them access to the platform.

Evidence packages

Generate a self-contained package for a finding, application or scope, containing:

  • the proof-of-exploit (PoC request/response) or precise code location,
  • the control mapping (which OWASP/PCI/ISO/NIST/SOC2/HIPAA/GDPR clauses),
  • remediation status, owner and timeline,
  • the audit trail of who did what, when.

Evidence is privacy-aware - PII / credentials are masked in reports and AI output.

Auditor Portal

A scoped, read-only share link (/portal/[id]) lets an external auditor see exactly the evidence you choose - findings, posture, compliance coverage and the immutable trail - with no login to the main app and no ability to change anything.

  • Scoped - share a single app, a compliance scope, or a report.
  • Time-boxed - links can expire.
  • Tamper-evident - the underlying audit log is append-only.

Why it matters

Audits usually mean screenshots and spreadsheets. The Evidence Vault makes the answer to "prove you tested this and fixed it" a one-click, defensible package - backed by real proof, not assertions. Pair it with Compliance & Maturity for the framework view and Scorecards for the grade.