proofaudit.ai

Security and control

How ProofAudit protects the integrity of the evidence record, and an honest compliance status.

ProofAudit is designed to record evidence and verification outcomes for high-stakes decisions. It is not an auditor, law firm, or compliance sign-off.

Document hashing

Uploaded or referenced documents can be hashed and versioned so verification status reflects a specific artifact, not a folder label.

Attributable approvals

Approvals are recorded with role, action, and timestamp so export packs show who acted, not anonymous system events.

Append-style event log

Decision events are designed to append in order — capture, verification, approval, export — rather than silently overwrite prior state.

Separation of duties

Capture, verify, and approve can map to different roles so one person cannot unilaterally export a package without the checks your program requires.

Production data handling — retention, residency, subprocessors, and what content is stored versus referenced — is scoped in the customer agreement.

SOC 2

In readiness

Readiness work is underway. No SOC 2 report has been issued.

ISO 27001

Not certified

No ISO 27001 certification is claimed.

Penetration test

By request

No penetration-test summary is published. Security questionnaires and architecture reviews are handled with qualified teams under NDA.

Responsible disclosure

Report security concerns to security@stratedgeworkflow.com. Security questionnaires and architecture reviews are handled with qualified teams under NDA.

Privacy policy