Core workflows

Use the Evidence Vault as your single source of truth

Upload once, tag once, reuse across risks, controls, audits, Trust Center and buyer questionnaires. Never chase a screenshot again.

6 min read · updated July 2026

Step-by-step

  1. 1

    Open the Evidence Vault

    Everything you've uploaded, filterable by type, owner, control and expiry.

    Open the Evidence Vault
  2. 2

    Upload with metadata

    Drop a file. Tag it with type (Policy, Report, Screenshot, Log), owner, effective date and expiry. Optional: link controls and risks now.

  3. 3

    Reuse everywhere

    The same artifact appears wherever it's linked — no duplicates, no version drift.

  4. 4

    Share to Trust Center

    Toggle 'Publish to Trust Center' on any artifact. Buyers with a Trust Center token see it immediately.

What corporate buyers look for
  • "Can you share evidence of MFA enforcement, backup restore tests and vulnerability scans?"
  • "Is your evidence current (typically within 90 days)?"
  • "How is evidence protected in storage and transit?"

What this workflow produces: A curated evidence pack shared through Trust Center often shortens buyer due diligence from weeks to hours.

FAQ

Where is evidence stored?

In encrypted object storage inside your workspace. Only workspace members with the right role can read it.

What file types are supported?

PDF, DOCX, XLSX, PNG, JPG, CSV, TXT, and Markdown. Total per-file limit is 25 MB.

Ready to run this in your workspace?

Start free — the workspace comes pre-loaded with the frameworks, policies and templates you need to follow this guide today.

Related

ISO 27001 aligned
Controls mapped to Annex A
Encryption in transit & at rest
TLS 1.3 · AES-256
MFA enforced
TOTP required for all admins
GDPR & UK GDPR
DPA on request · EU/UK data
SOC 2 ready posture
Audit-grade logging
RLS-isolated tenants
Row-level data separation