Designed for sensitive evidence, not casual screenshots.
AuditFetch treats evidence as sensitive security data. The local runtime is designed around least privilege, local credential storage, audit logs, artifact hashing, and explicit user-controlled exports.
How we handle your data
Local-first, customer-controlled
Evidence, credentials, and audit logs stay in your environment. AuditFetch Cloud is used only for licensing, updates, connector templates, and optional telemetry you can switch off.
Least-privilege, read-only access
Connector credentials are scoped and read-only, and every collector method is validated read-only before it ships. AuditFetch never writes to your systems.
Tenant-isolated storage
Database row-level security isolates every tenant, enforced in the database itself rather than in application code, alongside role-based access control. Connector credentials are encrypted at rest under a key only you hold.
Verifiable chain of custody
Every artifact is content-hashed and signed with an Ed25519 key held only by your deployment. Exports carry each signature plus the public key that made it, so an auditor verifies the evidence against a fingerprint you publish — not against anything AuditFetch asserts. The audit log is hash-chained, and its Merkle root is signed into external write-once storage, so tampering is detectable even by someone with full database access.
Local audit log
An append-only, hash-chained record of collection, review, and export actions, plus evidence redaction support and customer-owned deletion controls.
Approved browser playbooks
Only declarative, approved routes with an outbound host allowlist. No free-form browser roaming. Navigation trail and redaction rules are recorded with the evidence.
Our trust boundary
Local-first, always
Evidence and credentials stay in your environment by default. AuditFetch Cloud never sees your raw evidence.
Read-only, always
Never writes, remediates, or changes access to your systems.
Avoids PHI
Proves safeguards exist — it doesn’t ingest patient data or raw logs that might contain it.
Provenance is the product
Every artifact is hashed, signed, timestamped, and anchored to a tamper-evident log.
- Never your card data — payments run through Stripe; we store no card numbers.
- AI is non-authoritative — it assists, humans decide, and AuditFetch never certifies compliance.
- Optional telemetry, off by default — no raw evidence sent to the cloud unless you enable it.
Ready to stop chasing audit screenshots?
See AuditFetch pricing and get started with local-first evidence automation for SOC 2, HIPAA, and ISO 27001.
Get product updates instead: