Security & architecture
Designed so assessment credentials stay at the collection boundary while evidence, metadata and audit history can be governed centrally.
Integrity
SHA-256 identities and manifests for evidence and packages.
Access roles
Read-only auditor access plus restricted contributor/approver and assessor/admin roles.
Secret handling
Sanitization/redaction for command and support artifacts; secret material is not intentionally rendered into proof outputs.
Retention & legal hold
Retention controls and legal hold preserve evidence when deletion should be blocked.
Immutable revisions
Frozen audit packages create new revisions rather than silently mutating prior state.
Database isolation
Managed PostgreSQL remains server-side; assessor clients interact through the API layer.
Audit logging
Evidence lifecycle and auditor-package exports are recorded without logging evidence contents or secrets.
Privacy-first support
Support bundles are sanitized locally and do not automatically transmit client evidence or credentials.
Evaluation and review boundaries
IT Audit Factory is an assessment and evidence platform, not a certification authority. Final certification, attestation, authorization and legal applicability remain with the organization and the applicable qualified assessor or certification body.
Authentication boundary
Current MSP access is based on client-scoped API-key metadata and role-aware authorization. Interactive OIDC/SAML single sign-on is not currently available.
Integration boundary
An entry in the integration registry does not by itself enable collection. Available adapters need the supported platform, connection permissions and configured credentials; check the guide for the installed version.