Every control mapped to its Trust Services Criteria. Every artifact stamped with its source system and collection timestamp — not a dashboard screenshot. Nothing summarised past the point where you’d need to ask where it came from.
This is the auditor access section of our product demo, not a bespoke auditor walkthrough — see the full demo.
A Circinova customer’s evidence is organized around 19 SOC 2 Trust Services Criteria controls, covering the Common Criteria series (CC1 through CC9) — logical access, authentication, change management, incident response, vendor risk, and the rest of the Security category.
Every piece of evidence is attached to the specific control it supports — e.g. CC6.2 (Authentication/MFA) or CC8.1 (Change management) — not left to be inferred from a folder name.
Each record carries the exact integration it was pulled from — AWS IAM, GitHub branch protection, Azure AD MFA registration — so you can go back to the source, not just Circinova’s summary of it.
Every item is stamped with when it was collected, and the org’s full observation period (earliest to latest evidence) is shown alongside the control results — not just a single "as of" date.
Evidence pulled automatically from a connected system and evidence uploaded by hand are tagged differently at the record level. A manual attestation is never presented as if an API produced it.
Most evidence is pulled directly from the client’s own connected systems on a fixed schedule — no one is taking screenshots. The schedule depends on the client’s plan: daily for the free tier, every 6 hours on Starter, hourly on Growth.
Cloud & infrastructure
AWS · Google Cloud · Azure · Terraform Cloud
Source control & CI
GitHub · GitLab · Bitbucket · CircleCI
Identity & directory
Okta · Azure AD · Google Workspace · JumpCloud · Duo
Endpoint & MDM
Jamf · Kandji · Mosyle · CrowdStrike · SentinelOne
HR
Rippling · Gusto · BambooHR · Workday
Security scanning
Snyk · Wiz · Tenable · Qualys · SonarQube · Veracode · Lacework
Not everything has an API. Where a control depends on something without a connected system — a signed acknowledgement, a physical security attestation, anything the client has to assert rather than a tool can report — that evidence is uploaded manually by the client and recorded with a source: manual tag, distinct from anything collected automatically. We don’t blend the two into a single undifferentiated evidence stream.
The client issues you a single read-only portal link — there’s no account to create and nothing to install.
Access is a single hashed, time-limited token (14 days by default, client-configurable and revocable at any time). It opens a read-only report — no write access to anything exists on the other side of that link, and every access is timestamped.
Control-by-control results with status and evaluation date, any formally accepted risk exceptions with reason and expiry, the org’s legal details, recent evidence entries (type, source system, collection date), and the client’s AI-drafted security policies.
The full report prints directly to PDF from the browser. Individual policies download as plain text files. There’s no separate CSV/API export built for auditors today — if that’s a blocker for your workflow, tell me and I’ll factor it into what gets built next.
You don’t need a Circinova account, a password, or a seat on the client’s org to view any of this. The link is the credential, and the client can cut it off unilaterally at any time.
Circinova collects and organizes evidence. The audit itself — testing, sampling, professional judgment — is yours to perform.
Nothing in the product produces an attestation, a Type I or Type II report, or any statement of assurance. That determination is exclusively the auditor’s.
Circinova is billed to the client as a compliance tool subscription. We have no financial relationship with the audit engagement itself.
Email me directly — I read and reply myself, no sales team in between.
abdel.elbouhy@circinova.com