Skip to content
AuditFetch

A local-first evidence automation runtime

Automate compliance without compromising security. AuditFetch continuously collects, validates, and maps readiness evidence for SOC 2, HIPAA, and ISO 27001 directly from AWS, GitHub, Okta, and the rest of your stack*. It delivers auditor-ready exports while running strictly inside your environment, ensuring your credentials and raw data never leave your control.

Currently supported evidence sources: GitHub, AWS, Okta, Google Workspace, Jira, Linear, Datadog, WorkOS — all read-only. Browser-based capture, included in every plan, covers sources without a usable API.

Local vs. Cloud

Hosted convenience when you want it. Local control when you need it.

AuditFetch Local

  • Runs in your environment
  • Evidence stays local
  • Local credentials
  • Internal systems supported
  • Best for security-sensitive teams

AuditFetch Cloud

  • Managed hosting
  • Faster setup
  • Managed scheduling
  • Team collaboration
  • Best for convenience-first teams

Custom Evidence Automation

Automate the last mile without turning compliance into custom integration work.

Built-in collectors cover common workflows. Custom Evidence Automation securely adapts reviewed read-only operations for AWS and GitHub—then sends the result through the same governed evidence lifecycle as built-in collection.

Find the last-mile gap

See which missing or manual requirement can be supported by a governed collector.

Choose a reviewed template

Start from an approved read-only operation for a supported provider—not a blank API request.

Set your scope

Set the supported resource scope for the reviewed AWS and GitHub template before testing.

Preview and test

Verify access and inspect a bounded, sanitized result before anything is enabled.

Enable deliberately

Promote the tested version only when the source, permissions, and scope are understood.

Reuse governed evidence

The artifact keeps its source, timestamp, mapping, and audit history across compatible controls and frameworks.

Designed for safe, reviewable collection

Automations use existing integration credentials and read-only scopes. With AuditFetch Local, secrets stay in your environment; hosted deployments use their configured secret store. Tests are audited, and evidence remains subject to the same provenance, review, retention, and export controls as built-in collection.

Read the practical automation guide

Provenance is the product

Every artifact is independently verifiable: content-hashed, signed, carrying a trusted timestamp of when it was captured, and anchored to a tamper-evident audit log. An auditor can verify your evidence is genuine and correctly dated without having to trust AuditFetch.

CC6.1✓ Verified

aws_iam_users_mfa

hash
sha256:9f2a7c1e
captured
2026-06-20
CC8.1✓ Verified

github_branch_protection

hash
sha256:3d5e8b02
captured
2026-06-19

What you get

Evidence vault

A searchable, hash-verified library of every artifact with full chain of custody.

Control mapping

SOC 2, HIPAA, and ISO 27001 controls linked to the evidence that satisfies them — one artifact, many controls.

Gap & freshness detection

A live view of which controls are covered and which need attention, before audit week.

Drift alerts

Get notified when a previously-passing configuration changes. (Team and up.)

Reviewer workflow

Human sign-off on sensitive mappings before they land in a packet. (Team and up.)

Auditor-ready packets

PDF / ZIP / CSV / JSON exports, generated on demand, or pushed to Drive or your GRC platform.

What it connects to

Engineering

  • GitHub GA
  • Jira Preview
  • Linear Preview

Cloud & Infrastructure

  • AWS GA
  • Datadog Preview

Identity & Access

  • Google Workspace Preview
  • Okta Preview
  • WorkOS Preview

Browser capture

  • Browser playbooks Preview

Evaluator only

  • Disposable sample workspace Test only

Compliance Destinations

  • PDF GA
  • ZIP GA
  • CSV GA
  • JSON GA
  • Vanta Preview
  • Drata Preview

Already connected to one of the reviewed providers (AWS and GitHub)? Read how to automate the last mile of compliance evidence with a reviewed, read-only template.

Evidence from the tools that have no API

API integrations cover the easy ~80% of evidence. The hard ~20% lives in admin consoles with no API. AuditFetch handles it with approved, read-only browser playbooks: declarative, approved routes only, timestamp overlay, navigation trail, redaction, same content-hash provenance as API artifacts. API evidence first, screenshots only where the API can’t prove it.

Approved browser playbooks

Available as part of the local runtime. Playbooks are declarative and deterministic — never a free-form “click anything” mode. Structured exports are stronger, easier to validate, and harder to manipulate, so we prefer them, and use playbooks only where they’re the only way to get the proof.

Ready to stop chasing audit screenshots?

See AuditFetch pricing and get started with local-first evidence automation for SOC 2, HIPAA, and ISO 27001.

Get product updates instead: