Use the approved 4.1.0 installer for your edition and confirm the version shown in the installed application. Published package availability is shown in Downloads & beta access.
Security & Communications
Secure Communication profiles configure actual IT Audit Factory MSP client/server transport and authentication behavior. The top-right status indicator reflects the effective server-reported state after validation rather than the selected setting alone.
Secure Communication profiles
| Profile | Runtime controls |
|---|---|
| OFF | Application functionality remains available. HTTP is permitted. The persistent indicator is Secure Communication: OFF. |
| Standard | HTTPS using TLS 1.2/1.3 with server-certificate validation. |
| Enhanced | Standard controls plus certificate-revocation checking and HMAC-signed API requests using timestamp/nonce replay protection. |
| High Assurance | TLS 1.3, revocation checking, signed requests and required mutual TLS (mTLS) client authentication. |
| DoD-Aligned | High Assurance plus the IT Audit Factory validation gates for Windows FIPS policy, CA-chain client trust and a valid non-self-signed server certificate chain. This is an alignment profile and does not claim formal government, DoD, FedRAMP or FIPS certification. |
Certificate options
The Server Administration console supports public/customer-purchased certificates, enterprise/private-CA certificates, explicitly trusted self-signed certificates, PFX/P12 import and trusted-CA import. High Assurance deployments can use an imported/selected mTLS client certificate; the client can also generate a local client-auth certificate for explicit-thumbprint High Assurance deployments. DoD-Aligned requires CA-chain trust rather than a locally self-signed client certificate.
Validation
Use Test Security Configuration in Server Administration and Test Secure Connection in the assessor client. The client queries /api/security/status and displays the effective profile and active controls. Selecting a stronger profile is not sufficient for the indicator to report that profile if required controls are not active.
Private Evidence Mode
When enabled, auditor export requires an explicit one-time approval on every export. The approval is not persisted. Support bundles remain sanitized and do not automatically transmit client evidence, reports or secrets.
Evidence integrity
Evidence versions, SHA-256 hashes, frozen audit snapshots, package revisions, command provenance and export manifests are retained according to configured policy.