IT Audit Factory · Evidence-first audit operationsFree · Professional · MSP
Documentation

Private evidence and security

Handle sensitive evidence, controlled sharing and credential/privacy boundaries.

MSP4.1.0
All documentation / MSP / 4.1.0
This reference is bundled with the 4.1.0 engine and may retain earlier UI terminology. Use the current 4.1.0 installation/security guides for the new wizard and activation steps. Its procedures apply to MSP; use the separate Free or Professional guide for those editions.

Use the approved 4.1.0 installer for your edition and confirm the version shown in the installed application. Published package availability is shown in Downloads & beta access.

Security & Communications

Secure Communication profiles configure actual IT Audit Factory MSP client/server transport and authentication behavior. The top-right status indicator reflects the effective server-reported state after validation rather than the selected setting alone.

Secure Communication profiles

ProfileRuntime controls
OFFApplication functionality remains available. HTTP is permitted. The persistent indicator is Secure Communication: OFF.
StandardHTTPS using TLS 1.2/1.3 with server-certificate validation.
EnhancedStandard controls plus certificate-revocation checking and HMAC-signed API requests using timestamp/nonce replay protection.
High AssuranceTLS 1.3, revocation checking, signed requests and required mutual TLS (mTLS) client authentication.
DoD-AlignedHigh Assurance plus the IT Audit Factory validation gates for Windows FIPS policy, CA-chain client trust and a valid non-self-signed server certificate chain. This is an alignment profile and does not claim formal government, DoD, FedRAMP or FIPS certification.

Certificate options

The Server Administration console supports public/customer-purchased certificates, enterprise/private-CA certificates, explicitly trusted self-signed certificates, PFX/P12 import and trusted-CA import. High Assurance deployments can use an imported/selected mTLS client certificate; the client can also generate a local client-auth certificate for explicit-thumbprint High Assurance deployments. DoD-Aligned requires CA-chain trust rather than a locally self-signed client certificate.

Validation

Use Test Security Configuration in Server Administration and Test Secure Connection in the assessor client. The client queries /api/security/status and displays the effective profile and active controls. Selecting a stronger profile is not sufficient for the indicator to report that profile if required controls are not active.

Private Evidence Mode

When enabled, auditor export requires an explicit one-time approval on every export. The approval is not persisted. Support bundles remain sanitized and do not automatically transmit client evidence, reports or secrets.

Evidence integrity

Evidence versions, SHA-256 hashes, frozen audit snapshots, package revisions, command provenance and export manifests are retained according to configured policy.