Complies
EV-03 EVIDENCE

Compliance evidence collection: gather once, reuse everywhere

Screenshots, exports, and policies collected on a schedule, tied to controls, owned by named people. The 120 engineer-hours an audit usually eats become a tracked, delegated list.

See pricing

Compliance evidence collection is the work of gathering the screenshots, configuration exports, policies, and logs that prove your controls actually operate, and it is where audit preparation quietly burns the most time: roughly 120 engineer-hours per audit cycle for a typical mid-size team. Complies turns that scramble into a managed pipeline. Every control lists exactly what evidence it needs, each evidence item has a named owner and a due date, and integrations with AWS, GitHub, Google Workspace, Okta, and Jira pull much of it automatically on a schedule. Evidence is collected once and reused everywhere it applies: an access review attached to one control counts for SOC 2 and ISO 27001 simultaneously, and last cycle's items stay organized as the starting reference for the next one. Evidence collection with owners and due dates is included in the Growth plan at $199 per month billed yearly, $2,388 for the year, against the $10,000-plus a typical Vanta contract runs. One honest limitation: not everything automates. Some evidence, like a signed vendor review or a tabletop exercise writeup, still needs a human to produce it, and for those items Complies manages the owner, the deadline, and the reminder rather than the artifact itself.

It works alongside control mapping software and compliance reporting software, and plugs straight into soc 2 compliance software, iso 27001 compliance software on every plan from Growth up.

EV-03 EVIDENCE

What changes when it is in place

Collect once, reuse everywhere

An evidence item attached to a cross-mapped control counts in every framework that control satisfies, and stays organized for the next audit cycle. Nothing gets screenshotted twice for two auditors.

Named owners and real due dates

Every evidence request routes to one person with a deadline and a Slack reminder. The night-before scramble through email threads for who has the pentest report ends.

Automated pulls from your stack

AWS configs, GitHub branch protection, Okta access logs, and Google Workspace settings are collected on a schedule through integrations, so recurring evidence arrives without anyone being asked.

120 engineer-hours, accounted for

The evidence work an audit cycle usually eats becomes a visible, delegated list with progress you can watch, instead of an invisible tax on whoever the auditor emails first.

QUESTIONS

Common questions

Anything that proves a control operates: access review exports, branch protection screenshots, encryption configuration, signed policies, onboarding and offboarding records, pentest reports, incident postmortems. Complies lists the expected evidence per control with examples of what auditors typically accept, so engineers produce the right artifact the first time instead of iterating with the auditor.

Evidence that lives in connected systems is pulled automatically on a schedule from AWS, GitHub, Google Workspace, Okta, Azure, Slack, and Jira, and for a typical cloud-native stack that covers most recurring items. Evidence that requires human work, like a vendor review or a tabletop exercise, is tracked with an owner, a due date, and reminders. Complies is honest about which is which per control.

Yes, and Complies tracks that too. Auditors expect evidence from the audit period, so a screenshot from two years ago does not demonstrate a control operates today. Each item carries a freshness window based on its cadence, quarterly for access reviews, annual for policies, and the compliance calendar schedules recollection before anything goes stale.

Put evidence collection on autopilot

All plans include it. Prices are public. Start today.