A local-first evidence automation runtime
Automate compliance without compromising security. AuditFetch continuously collects, validates, and maps readiness evidence for SOC 2, HIPAA, and ISO 27001 directly from AWS, GitHub, Okta, and the rest of your stack*. It delivers auditor-ready exports while running strictly inside your environment, ensuring your credentials and raw data never leave your control.
Currently supported evidence sources: GitHub, AWS, Okta, Google Workspace, Jira, Linear, Datadog, WorkOS — all read-only. Browser-based capture, included in every plan, covers sources without a usable API.
Local vs. Cloud
Hosted convenience when you want it. Local control when you need it.
AuditFetch Local
- Runs in your environment
- Evidence stays local
- Local credentials
- Internal systems supported
- Best for security-sensitive teams
AuditFetch Cloud
- Managed hosting
- Faster setup
- Managed scheduling
- Team collaboration
- Best for convenience-first teams
Custom Evidence Automation
Automate the last mile without turning compliance into custom integration work.
Built-in collectors cover common workflows. Custom Evidence Automation securely adapts reviewed read-only operations for AWS and GitHub—then sends the result through the same governed evidence lifecycle as built-in collection.
Find the last-mile gap
See which missing or manual requirement can be supported by a governed collector.
Choose a reviewed template
Start from an approved read-only operation for a supported provider—not a blank API request.
Set your scope
Set the supported resource scope for the reviewed AWS and GitHub template before testing.
Preview and test
Verify access and inspect a bounded, sanitized result before anything is enabled.
Enable deliberately
Promote the tested version only when the source, permissions, and scope are understood.
Reuse governed evidence
The artifact keeps its source, timestamp, mapping, and audit history across compatible controls and frameworks.
Designed for safe, reviewable collection
Automations use existing integration credentials and read-only scopes. With AuditFetch Local, secrets stay in your environment; hosted deployments use their configured secret store. Tests are audited, and evidence remains subject to the same provenance, review, retention, and export controls as built-in collection.
Read the practical automation guideProvenance is the product
Every artifact is independently verifiable: content-hashed, signed, carrying a trusted timestamp of when it was captured, and anchored to a tamper-evident audit log. An auditor can verify your evidence is genuine and correctly dated without having to trust AuditFetch.
aws_iam_users_mfa
- hash
- sha256:9f2a7c1e…
- captured
- 2026-06-20
github_branch_protection
- hash
- sha256:3d5e8b02…
- captured
- 2026-06-19
What you get
Evidence vault
A searchable, hash-verified library of every artifact with full chain of custody.
Control mapping
SOC 2, HIPAA, and ISO 27001 controls linked to the evidence that satisfies them — one artifact, many controls.
Gap & freshness detection
A live view of which controls are covered and which need attention, before audit week.
Drift alerts
Get notified when a previously-passing configuration changes. (Team and up.)
Reviewer workflow
Human sign-off on sensitive mappings before they land in a packet. (Team and up.)
Auditor-ready packets
PDF / ZIP / CSV / JSON exports, generated on demand, or pushed to Drive or your GRC platform.
What it connects to
Engineering
- GitHub GA
- Jira Preview
- Linear Preview
Cloud & Infrastructure
- AWS GA
- Datadog Preview
Identity & Access
- Google Workspace Preview
- Okta Preview
- WorkOS Preview
Browser capture
- Browser playbooks Preview
Evaluator only
- Disposable sample workspace Test only
Compliance Destinations
- PDF GA
- ZIP GA
- CSV GA
- JSON GA
- Vanta Preview
- Drata Preview
Already connected to one of the reviewed providers (AWS and GitHub)? Read how to automate the last mile of compliance evidence with a reviewed, read-only template.
Evidence from the tools that have no API
API integrations cover the easy ~80% of evidence. The hard ~20% lives in admin consoles with no API. AuditFetch handles it with approved, read-only browser playbooks: declarative, approved routes only, timestamp overlay, navigation trail, redaction, same content-hash provenance as API artifacts. API evidence first, screenshots only where the API can’t prove it.
Approved browser playbooks
Available as part of the local runtime. Playbooks are declarative and deterministic — never a free-form “click anything” mode. Structured exports are stronger, easier to validate, and harder to manipulate, so we prefer them, and use playbooks only where they’re the only way to get the proof.
Ready to stop chasing audit screenshots?
See AuditFetch pricing and get started with local-first evidence automation for SOC 2, HIPAA, and ISO 27001.
Get product updates instead: