How it works
Four steps. None of them is an assessment, a score, or a readiness percentage — we organize evidence. we do not certify.
1. Point a collector at a system
Choose what to watch — a URL, a domain, a GitHub organisation — and how often. Anything that needs a credential takes a read-only one, stored encrypted.
2. Let it run, including the runs that fail
Every run is recorded: the ones that worked, the ones that failed, and the ones that came back with nothing. "Was this check running all year" is a question the run log answers and a list of successes does not.
3. Add the things no API can reach
A signed policy, a photo of a server-room door, a screenshot from a vendor console. Filed with the same provenance and marked as put there by a person rather than observed by a collector.
4. Hand your auditor one link
Scoped to a date range, expiring on its own, revocable in one click. They read the vault or take a ZIP with a hash per file.
What you end up with
A vault where every item says when it was observed, when it was filed, where it came from, and what its SHA-256 is — and an auditor who can check all of that without an account and without trusting us.
The word unknown
You will see it. It means a collector reached a system and that system does not report what was asked — for example, GitHub only reports each member's two-factor state when the organisation enforces two-factor authentication. Unknown is not a failure and it is not a pass. It is the true answer, and AuditPrep records it rather than rounding it to whichever reads better.