Security & architecture
Designed so assessment credentials stay at the collection boundary while evidence, metadata and audit history can be governed centrally.
Integrity
SHA-256 identities and manifests for evidence and packages.
Access roles
Read-only auditor access plus restricted contributor/approver and assessor/admin roles.
Secret handling
Sanitization/redaction for command and support artifacts; secret material is not intentionally rendered into proof outputs.
Retention & legal hold
Retention controls and legal hold preserve evidence when deletion should be blocked.
Immutable revisions
Frozen audit packages create new revisions rather than silently mutating prior state.
Database isolation
Managed PostgreSQL remains server-side; assessor clients interact through the API layer.
Audit logging
Evidence lifecycle and auditor-package exports are recorded without logging evidence contents or secrets.
Privacy-first support
Support bundles are sanitized locally and do not automatically transmit client evidence or credentials.
Professional procurement notes
IT Audit Factory is an assessment and evidence platform, not a certification authority. Final certification, attestation, authorization and legal applicability remain with the organization and the applicable qualified assessor or certification body.
Authentication boundary
Current MSP access is based on client-scoped API-key metadata and role-aware authorization. Interactive OIDC/SAML SSO should not be represented as available until implemented and validated.
Integration boundary
The integration registry can describe supported platforms and reuse existing collectors, but each new third-party authentication/collection adapter still requires its vendor-specific implementation and credentials.