Evidence

Audit-ready proof,
next to its control.

Upload a document, or link a policy section, an asset or a risk you already track. Then map it to the control it satisfies, recorded with who linked it and when, so when an auditor asks for proof of a control, it’s already attached, not hunted down across tools.

Start for freeBook a conversation
++++
app.devguard.ch / evidence
linked to controls
342
artifacts this month
By source
GitHub148
GitLab76
Jira & Slack86
Manual32
Recent artifacts
PR #4821 merged
GitHub · acme-app/web
A.8.28just now
MR !1190 merged
GitLab · billing-svc
A.8.2514m ago
SEC-1043 approved
Jira · platform
A.5.242h ago
change approved
Slack · #security
A.5.41d ago
pentest-report-q2.pdf
Manual upload · Security
A.8.293d ago
Every framework
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
ISO/IEC 27001ISO/IEC 27002SOC 2SOC 1GDPRHIPAAPCI DSS v4.0.1NIST CSF 2.0EU AI ActNIS2 DirectiveDORAOWASPISO/IEC 42001CIS ControlsCloud Controls MatrixISO/IEC 27017 & 27018ISO/IEC 27701ISO 9001ISO 14001ISO 45001Swiss nFADP
  • ISO/IEC 27001
  • ISO/IEC 27002
  • SOC 2
  • SOC 1
  • GDPR
  • HIPAA
  • PCI DSS v4.0.1
  • NIST CSF 2.0
  • EU AI Act
  • NIS2 Directive
  • DORA
  • OWASP
  • ISO/IEC 42001
  • CIS Controls
  • Cloud Controls Matrix
  • ISO/IEC 27017 & 27018
  • ISO/IEC 27701
  • ISO 9001
  • ISO 14001
  • ISO 45001
  • Swiss nFADP
How it works

Add the proof, map the control.

Evidence is a document you upload or a policy, asset or risk you link, then it’s mapped to the control it proves.

01

Upload a document or link a record

Upload a file directly, like a pentest report, a screenshot or a signed policy, or link a record you already keep in devguard, like a policy section, an asset or a risk.

02

Map it to the control it satisfies

Attach each upload or linked record to the control it proves, recorded with who made the link and when. The file or record stops sitting in a folder and becomes proof connected to a specific control.

Mapped to the control it satisfies

You map evidence to a control yourself: devguard stores your upload or records the link to a policy, asset or risk. It doesn’t reach into your cloud and collect anything for you, so every link is honest about where the proof came from.

03

Hand the auditor the proof

When a control comes up in an audit or a report, its evidence is already attached and timestamped. You point at the control and the proof is there, rather than reassembling it from chat, drives and email.

Why it’s built this way

Proof attached, not scattered.

Four choices behind how evidence works here — each one you can check, not an adjective.

01

Upload a document

A pentest report, a screenshot, a signed policy: upload it directly and map it to the control it proves.

02

Or link what you already track

Point a policy section, an asset or a risk at the control it satisfies, so existing records double as proof.

03

Every link maps to a control

Each upload or link is attached to the control it satisfies and recorded with who made the link and when.

04

You link the evidence, you map it

You upload or link each piece of evidence and map it to the control yourself, or let the devguard CLI keep a record current from your pipeline. Cloud auto-collection is on the roadmap.

Swiss-hosted, yours to export.

Hosted in Switzerland by default, in German and English, with on-premise possible. Export your records to CSV and your reports to PDF; your data is yours, with no lock-in.

See the full feature comparison

One module of the platform

Where evidence connects.

Evidence is only useful attached to something — the control it proves, the audit that checks it, the vendor it covers and the report that exports it.

ISO 27001SOC 2GDPRNIST CSF

Frameworks & controls

Map each artifact to the control it satisfies.

Internal audit00:42
Access controls
Backup & recovery
Incident response

Audits

Work through audit checks against the evidence behind them.

AWAWSReviewed
CFCloudflareReviewed
StStripe

Vendors

Attach questionnaires and evidence files to the vendor they cover.

86%
Shared with
JDAKMR+3

Reports

Export evidence and posture as a PDF for the auditor.

FAQ

The questions evaluators ask.

How is evidence collected?

You upload a document, or link a policy section, an asset or a risk you already track, then map it to the control it satisfies. The devguard CLI can also push command output, like a scanner report, into an evidence record on a schedule. Cloud auto-collection is on the roadmap; you decide what counts as proof.

Which integrations are live today?

GitHub, GitLab, Jira and Slack. They create an outbound ticket or Slack message and sync that ticket’s status back, so remediation work is tracked. They do not pull an artifact in as control evidence. Evidence is a document you upload, a record you link, or a file the devguard CLI pushes from your pipeline, mapped to the control.

What counts as evidence?

A document you upload, like a pentest report, a screenshot or a signed policy, or a local record you link, like a policy section, an asset or a risk. Each one is mapped to the control it satisfies and recorded with who linked it and when.

How is this different from a shared drive or another GRC tool?

In a shared drive, a file’s link to a control lives in your head or a spreadsheet, and proof is reassembled before every audit. Here, each upload or linked record is mapped to the control it satisfies, recorded with who linked it and when, and already attached when that control comes up in an audit or report. You decide what counts as proof, so what you hand an auditor is exactly what you put there.

Where’s the data hosted, and can I export it?

Swiss-hosted by default, in German and English, with on-premise possible. Export your records to CSV and your reports to PDF; your data is yours, with no lock-in.

Keep every artifact mapped to its control.

Upload a document or link a policy, asset or risk, then map it to the control it satisfies, so the proof is attached before the auditor asks, not scrambled for after.

Start for freeBook a conversation
Sign in
Start for free
Book a conversationStart for free