IT Audit Factory — evidence-first audit & compliance operations
Free • Professional • MSP
Platform / Security

Security & architecture

Designed so assessment credentials stay at the collection boundary while evidence, metadata and audit history can be governed centrally.

Collection boundaryAuthorized Windows assessor workstation • local credentials • read-only collection where supported
→
MSP HTTPS APIClient scoping • API-key roles • request authorization • portfolio services
→
Server data planePostgreSQL metadata • Evidence storage • retention • backups • audit trail
SHA

Integrity

SHA-256 identities and manifests for evidence and packages.

RBAC

Access roles

Read-only auditor access plus restricted contributor/approver and assessor/admin roles.

SAFE

Secret handling

Sanitization/redaction for command and support artifacts; secret material is not intentionally rendered into proof outputs.

HOLD

Retention & legal hold

Retention controls and legal hold preserve evidence when deletion should be blocked.

FREEZE

Immutable revisions

Frozen audit packages create new revisions rather than silently mutating prior state.

DB

Database isolation

Managed PostgreSQL remains server-side; assessor clients interact through the API layer.

LOG

Audit logging

Evidence lifecycle and auditor-package exports are recorded without logging evidence contents or secrets.

SUP

Privacy-first support

Support bundles are sanitized locally and do not automatically transmit client evidence or credentials.

Evaluation and review boundaries

IT Audit Factory is an assessment and evidence platform, not a certification authority. Final certification, attestation, authorization and legal applicability remain with the organization and the applicable qualified assessor or certification body.

Authentication boundary

Current MSP access is based on client-scoped API-key metadata and role-aware authorization. Interactive OIDC/SAML single sign-on is not currently available.

Integration boundary

An entry in the integration registry does not by itself enable collection. Available adapters need the supported platform, connection permissions and configured credentials; check the guide for the installed version.