IT Audit Factory — evidence-first audit & compliance operations
Free • Professional • MSP — Enterprise Edition
Trust Center

Security, privacy and procurement confidence.

A buyer-oriented summary of architecture, evidence handling and operational controls.

Security model

Authenticated encryption and defensible evidence handling.

AES-256-GCM at rest

Application-managed sensitive artifacts use authenticated encryption with protected key material.

Evidence lineage

Hashes, manifests, command provenance, screenshots, run context and revision history preserve where evidence came from and how it was used.

Privacy-first support

Support uses local sanitization and explicit Send confirmation; no client evidence or credentials are transmitted automatically.

Evidence integritySHA-256
Client scopeIsolated
Support handoffExplicit
Database pathServer-side

Customer-controlled evidence

MSP centralizes evidence and metadata without compiling a direct PostgreSQL data path into the assessor client.

Role-aware access

Client-scoped API access and restricted role patterns support separation of duties.

Secret redaction

Command and support artifacts sanitize passwords, tokens, API keys, client secrets and embedded credentials.

Evidence integrity

SHA-256 hashes, manifests, versioned evidence and verification support defensible evidence handling.

Retention & legal hold

Retention policy and legal hold can preserve evidence versions where deletion should be blocked.

Immutable audit revisions

Frozen audit packages create new revisions instead of silently changing prior exported state.

Data lifecycle

Client removal is treated as a data-lifecycle operation.

The current Build Fix 10 direction adds centralized client deletion together with cleanup of the evidence/data associated with that client. Production implementation should keep destructive actions explicit, auditable and compatible with retention/legal-hold rules.

Explicit destructive action

Client removal should require a clear administrative action rather than occurring implicitly.

Associated evidence cleanup

Remove client-scoped evidence/data to avoid orphaned records after the client is deleted.

Retention boundary

Legal hold and retention policy remain higher-priority preservation controls where applicable.

Architecture boundaries

Authorized Windows clients perform collection and retain the assessment credential boundary. The MSP server provides HTTPS/API services, client scoping, evidence storage, readiness and package operations. Managed PostgreSQL remains server-side.

Support privacy

Current support workflows generate a locally sanitized support request/bundle. No assessment evidence, credentials, secrets or report contents are transmitted automatically.

Procurement pack

Security, architecture, licensing, support and sample auditor materials.

Download ZIP