IT Audit Factory — evidence-first audit & compliance operations
Free • Professional • MSP — Enterprise Edition
Platform / Security

Security & architecture

Designed so assessment credentials stay at the collection boundary while evidence, metadata and audit history can be governed centrally.

Collection boundaryAuthorized Windows assessor workstation • local credentials • read-only collection where supported
→
MSP HTTPS APIClient scoping • API-key roles • request authorization • portfolio services
→
Server data planePostgreSQL metadata • Evidence Vault • retention • backups • audit trail
SHA

Integrity

SHA-256 identities and manifests for evidence and packages.

RBAC

Access roles

Read-only auditor access plus restricted contributor/approver and assessor/admin roles.

SAFE

Secret handling

Sanitization/redaction for command and support artifacts; secret material is not intentionally rendered into proof outputs.

HOLD

Retention & legal hold

Retention controls and legal hold preserve evidence when deletion should be blocked.

FREEZE

Immutable revisions

Frozen audit packages create new revisions rather than silently mutating prior state.

DB

Database isolation

Managed PostgreSQL remains server-side; assessor clients interact through the API layer.

LOG

Audit logging

Evidence lifecycle and auditor-package exports are recorded without logging evidence contents or secrets.

SUP

Privacy-first support

Support bundles are sanitized locally and do not automatically transmit client evidence or credentials.

Professional procurement notes

IT Audit Factory is an assessment and evidence platform, not a certification authority. Final certification, attestation, authorization and legal applicability remain with the organization and the applicable qualified assessor or certification body.

Authentication boundary

Current MSP access is based on client-scoped API-key metadata and role-aware authorization. Interactive OIDC/SAML SSO should not be represented as available until implemented and validated.

Integration boundary

The integration registry can describe supported platforms and reuse existing collectors, but each new third-party authentication/collection adapter still requires its vendor-specific implementation and credentials.