AuditPrep

Questions people actually ask

We organize evidence. We do not certify.

Does AuditPrep make us SOC 2 compliant?

No. AuditPrep organizes evidence; it does not certify anything and it is not an audit firm. It collects and dates the evidence a real auditor will ask you for, so that the fieldwork is about your controls rather than about chasing you for files. You still hire an audit firm, and they still decide.

What does a collector actually do?

It runs on a schedule you choose, asks one system one question, and files the answer in your vault with the date it was collected, the source it came from, and a SHA-256 of exactly the bytes stored. Today there are four: website response headers, SPF/DMARC/MX records, GitHub organisation membership, and a reminder for evidence only a person can gather.

What happens when a collector cannot see something?

It records unknown and explains why, in the filed evidence itself. For example, GitHub only reports each member's two-factor state when the organisation enforces two-factor authentication; without that, the field is not knowable from the API. AuditPrep writes unknown rather than false, because false would be a finding against somebody who may well have it switched on.

How does the auditor get the evidence?

You create a link scoped to a date range. It needs no account, expires on its own, and you can revoke it in one click. From it they can read every item or download a ZIP containing a manifest with a hash per file, so they can check the bundle without trusting us or coming back to the site.

Can we delete something we uploaded by mistake?

Yes, and it leaves a tombstone: the title, the hash, the collection date, who removed it and a required reason. The file is genuinely gone. A vault that cannot delete gets replaced by a folder that can, the first time somebody uploads a screenshot with a live key in it — and a gap in a bundle should be explainable rather than mysterious.

Can evidence be edited after it is filed?

No. The database refuses any change to an item's bytes, hash, dates, source, kind or title. A reviewer's note can still be added, because a note is not the evidence. This protects against a well-meant feature added later that quietly rewrites what an auditor already saw; it is not a claim about what somebody with our database credentials could do.

What does it cost?

Nothing is being charged today. There is no card form and no trial counting down. The intended price is $29 per month per workspace when billing is switched on, and this page will change before that happens.

Where is our evidence stored?

In a PostgreSQL database on a server in Germany, in a database only this application's role can open — proven against the other applications on the same server rather than assumed. Evidence lives in the database rather than in a separate file store, so the nightly encrypted backup carries the evidence itself and not just a list of filenames.

Start free