IT Audit Factory · Evidence-first audit operationsFree · Professional · MSP

Historical guide. This document retains its original version. See the current release guide for current build, storage and installer information.

Focused release in development: C31 supports new ISO 27001, CMMC Level 2, NIST SP 800-171 Rev. 2/3, NIST CSF 2.0 and NIST SP 800-53, HIPAA Security, ITAF ransomware readiness and PCI DSS preparation assessments. Other framework packs and advanced automation are in development. C12 is the owner-confirmed working baseline; C31 acceptance is pending.

Archived guide — original release identity

This guide describes a previous release. Use the current 4.1.0 documentation for new installations.

Documentation

Private evidence and security

Handle sensitive evidence, controlled sharing and credential/privacy boundaries.

MSPR68 bundled reference
All documentation / MSP / R68 bundled reference
This reference is bundled with the R68 engine and may retain earlier UI terminology. Use the current R68 installation/security guides for the new wizard and activation steps. Its procedures apply to MSP; use the separate Free or Professional guide for those editions.

Security & Communications

Secure Communication profiles configure actual IT Audit Factory MSP client/server transport and authentication behavior. The top-right status indicator reflects the effective server-reported state after validation rather than the selected setting alone.

Secure Communication profiles

ProfileRuntime controls
OFFApplication functionality remains available. HTTP is permitted. The persistent indicator is Secure Communication: OFF.
StandardHTTPS using TLS 1.2/1.3 with server-certificate validation.
EnhancedStandard controls plus certificate-revocation checking and HMAC-signed API requests using timestamp/nonce replay protection.
High AssuranceTLS 1.3, revocation checking, signed requests and required mutual TLS (mTLS) client authentication.
DoD-AlignedHigh Assurance plus the IT Audit Factory validation gates for Windows FIPS policy, CA-chain client trust and a valid non-self-signed server certificate chain. This is an alignment profile and does not claim formal government, DoD, FedRAMP or FIPS certification.

Certificate options

The Server Administration console supports public/customer-purchased certificates, enterprise/private-CA certificates, explicitly trusted self-signed certificates, PFX/P12 import and trusted-CA import. High Assurance deployments can use an imported/selected mTLS client certificate; the client can also generate a local client-auth certificate for explicit-thumbprint High Assurance deployments. DoD-Aligned requires CA-chain trust rather than a locally self-signed client certificate.

Validation

Use Test Security Configuration in Server Administration and Test Secure Connection in the assessor client. The client queries /api/security/status and displays the effective profile and active controls. Selecting a stronger profile is not sufficient for the indicator to report that profile if required controls are not active.

Private Evidence Mode

When enabled, auditor export requires an explicit one-time approval on every export. The approval is not persisted. Support bundles remain sanitized and do not automatically transmit client evidence, reports or secrets.

Evidence integrity

Evidence versions, SHA-256 hashes, frozen audit snapshots, package revisions, command provenance and export manifests are retained according to configured policy.

Guide basis

R68 package: Security-Private-Evidence-Guide.html

Published as a website guide on 1 October 2026. Where a bundled reference is older, the version-specific guide and installed interface take precedence.