Complies
EV-03 EVIDENCE

Compliance evidence collection: gather once, reuse everywhere

Screenshots, exports, and policies collected on a schedule, tied to controls, owned by named people. The 120 engineer-hours an audit usually eats become a tracked, delegated list.

See pricing

Compliance evidence collection is the work of gathering the screenshots, configuration exports, policies, and logs that prove your controls actually operate, and it is where audit preparation quietly burns the most time: roughly 120 engineer-hours per audit cycle for a typical mid-size team. Complies turns that scramble into a managed pipeline. Every control lists exactly what evidence it needs, each evidence item has a named owner and a due date, and integrations with AWS, GitHub, Google Workspace, Okta, and Jira pull much of it automatically on a schedule. Evidence is collected once and reused everywhere it applies: an access review attached to one control counts for SOC 2 and ISO 27001 simultaneously, and last cycle's items stay organized as the starting reference for the next one. Evidence collection with owners and due dates is included in the Growth plan at $199 per month billed yearly, $2,388 for the year, against the $20,000 median Vanta year Vendr reported in February 2026. One honest limitation: not everything automates. Some evidence, like a signed vendor review or a tabletop exercise writeup, still needs a human to produce it, and for those items Complies manages the owner, the deadline, and the reminder rather than the artifact itself.

It works alongside control mapping software and compliance reporting software, and plugs straight into soc 2 compliance software, iso 27001 compliance software on every plan from Growth up.

EV-03 EVIDENCE

What changes when it is in place

Collect once, reuse everywhere

An evidence item attached to a cross-mapped control counts in every framework that control satisfies, and stays organized for the next audit cycle. Nothing gets screenshotted twice for two auditors.

Named owners and real due dates

Every evidence request routes to one person with a deadline and a Slack reminder. The night-before scramble through email threads for who has the pentest report ends.

Automated pulls from your stack

AWS configs, GitHub branch protection, Okta access logs, and Google Workspace settings are collected on a schedule through integrations, so recurring evidence arrives without anyone being asked.

120 engineer-hours, accounted for

The evidence work an audit cycle usually eats becomes a visible, delegated list with progress you can watch, instead of an invisible tax on whoever the auditor emails first.

QUESTIONS

Common questions

Anything that proves a control operates: access review exports, branch protection screenshots, encryption configuration, signed policies, onboarding and offboarding records, pentest reports, incident postmortems. Complies lists the expected evidence per control with examples of what auditors typically accept, so engineers produce the right artifact the first time instead of iterating with the auditor.

Evidence that lives in connected systems is pulled automatically on a schedule from AWS, GitHub, Google Workspace, Okta, Azure, Slack, and Jira, and for a typical cloud-native stack that covers most recurring items. Evidence that requires human work, like a vendor review or a tabletop exercise, is tracked with an owner, a due date, and reminders. Complies is honest about which is which per control.

Yes, and Complies tracks that too. Auditors expect evidence from the audit period, so a screenshot from two years ago does not demonstrate a control operates today. Each item carries a freshness window based on its cadence, quarterly for access reviews, annual for policies, and the compliance calendar schedules recollection before anything goes stale.

Compliance evidence is any artifact that proves a control actually operated during the audit period, rather than merely existing on paper. In practice it falls into four groups: configuration proof (encryption settings, branch protection rules, logging configuration), process records (access reviews, onboarding and offboarding tickets, change approvals), signed documents (policies with named approvers, vendor agreements, training attestations), and point-in-time reports (penetration tests, incident postmortems, tabletop exercise writeups). An auditor is checking two things about each one: that it covers the period under review, and that it demonstrates the control operated consistently, not once.

Automated evidence collection means the platform pulls proof directly from your systems on a schedule instead of asking a person to screenshot it. Complies connects to AWS, Azure, GitHub, Google Workspace, Okta, Slack, and Jira, then collects the relevant configuration and access data on the cadence each control requires, timestamps it, and attaches it to every control it satisfies. For a typical cloud-native stack that covers most recurring items. The honest boundary is that evidence created by humans, a signed vendor review or a tabletop writeup, cannot be automated, so Complies tracks the owner, the due date, and the reminder for those instead of pretending to generate the artifact.

Three things do most of the work. Automate anything that lives in a connected system, so recurring items arrive without being requested. Give every manual item one named owner and a real due date, because evidence assigned to a team is evidence nobody produces. And collect against cross-mapped controls so a single artifact counts in every framework it satisfies, which is what stops teams screenshotting the same access review twice for two auditors. Evidence work commonly runs to roughly 120 engineer-hours per audit cycle for a mid-size team; the goal is to make that a tracked, delegated list rather than a scramble in the final two weeks.

Put evidence collection on autopilot

All plans include it. Prices are public. Start today.