For Auditors

Evidence you can trace, not evidence you take on faith

Every control mapped to its Trust Services Criteria. Every artifact stamped with its source system and collection timestamp — not a dashboard screenshot. Nothing summarised past the point where you’d need to ask where it came from.

This is the auditor access section of our product demo, not a bespoke auditor walkthrough — see the full demo.

What’s in an evidence pack

A Circinova customer’s evidence is organized around 19 SOC 2 Trust Services Criteria controls, covering the Common Criteria series (CC1 through CC9) — logical access, authentication, change management, incident response, vendor risk, and the rest of the Security category.

Control mapping

Every piece of evidence is attached to the specific control it supports — e.g. CC6.2 (Authentication/MFA) or CC8.1 (Change management) — not left to be inferred from a folder name.

Source system

Each record carries the exact integration it was pulled from — AWS IAM, GitHub branch protection, Azure AD MFA registration — so you can go back to the source, not just Circinova’s summary of it.

Collection timestamp

Every item is stamped with when it was collected, and the org’s full observation period (earliest to latest evidence) is shown alongside the control results — not just a single "as of" date.

Automated vs. manual, labelled

Evidence pulled automatically from a connected system and evidence uploaded by hand are tagged differently at the record level. A manual attestation is never presented as if an API produced it.

How the evidence is collected

Most evidence is pulled directly from the client’s own connected systems on a fixed schedule — no one is taking screenshots. The schedule depends on the client’s plan: daily for the free tier, every 6 hours on Starter, hourly on Growth.

Cloud & infrastructure

AWS · Google Cloud · Azure · Terraform Cloud

Source control & CI

GitHub · GitLab · Bitbucket · CircleCI

Identity & directory

Okta · Azure AD · Google Workspace · JumpCloud · Duo

Endpoint & MDM

Jamf · Kandji · Mosyle · CrowdStrike · SentinelOne

HR

Rippling · Gusto · BambooHR · Workday

Security scanning

Snyk · Wiz · Tenable · Qualys · SonarQube · Veracode · Lacework

What isn’t automated

Not everything has an API. Where a control depends on something without a connected system — a signed acknowledgement, a physical security attestation, anything the client has to assert rather than a tool can report — that evidence is uploaded manually by the client and recorded with a source: manual tag, distinct from anything collected automatically. We don’t blend the two into a single undifferentiated evidence stream.

How you get access

The client issues you a single read-only portal link — there’s no account to create and nothing to install.

Token-based, read-only

Access is a single hashed, time-limited token (14 days by default, client-configurable and revocable at any time). It opens a read-only report — no write access to anything exists on the other side of that link, and every access is timestamped.

What the portal shows

Control-by-control results with status and evaluation date, any formally accepted risk exceptions with reason and expiry, the org’s legal details, recent evidence entries (type, source system, collection date), and the client’s AI-drafted security policies.

Export formats

The full report prints directly to PDF from the browser. Individual policies download as plain text files. There’s no separate CSV/API export built for auditors today — if that’s a blocker for your workflow, tell me and I’ll factor it into what gets built next.

No login, no seat

You don’t need a Circinova account, a password, or a seat on the client’s org to view any of this. The link is the credential, and the client can cut it off unilaterally at any time.

What Circinova deliberately doesn’t do

We do not perform the audit

Circinova collects and organizes evidence. The audit itself — testing, sampling, professional judgment — is yours to perform.

We do not issue opinions

Nothing in the product produces an attestation, a Type I or Type II report, or any statement of assurance. That determination is exclusively the auditor’s.

We do not touch the audit fee

Circinova is billed to the client as a compliance tool subscription. We have no financial relationship with the audit engagement itself.

Questions about any of this?

Email me directly — I read and reply myself, no sales team in between.

abdel.elbouhy@circinova.com