Supported frameworks
SOC 2 (TSC 2017 + 2026 AI addendum). ISO 42001. EU AI Act. EU CRA. Custom mappings via /admin/compliance.
Format
Signed zip; verifiable offline using standard Ed25519 + JCS tooling. Auditor doesn't need to contact us.
Generation
/admin/evidence-packs → New → choose framework + period → generate. Background job; ready in ~10 minutes for typical orgs.
Auditor acceptance
In our experience, most auditors accept the signed receipt-based evidence pack. The 1-page "how to verify" doc gets unfamiliar auditors oriented in 15 minutes.