Overview
Evidence proves that your controls are implemented and working. Matproof collects evidence automatically from connected tools and lets you upload manual evidence when needed.Automated evidence
Connect your existing tools to collect evidence automatically:| Tool | Evidence collected |
|---|---|
| GitHub | Code review requirements, branch protection, access logs |
| Google Workspace | User access lists, MFA status, admin audit logs |
| Jira | Incident tickets, change records, approval workflows |
| AWS | IAM configurations, encryption settings, access logs |
| Azure AD | User provisioning, access reviews, MFA enforcement |
| Slack | (Coming soon) Communication audit logs |
Connecting integrations
- Go to Settings → Integrations
- Click Connect next to your tool
- Authorize via OAuth or API key
- Matproof begins collecting evidence immediately
Manual evidence
For controls that can’t be automated, upload evidence manually:- Go to Controls → select a control → Add evidence
- Upload PDF, image, CSV, or any file type
- Add a description and expiry date
- Assign to the relevant control
Evidence expiry
All evidence has an expiry date. Matproof sends alerts 30 days before evidence expires so you can collect fresh evidence before it becomes stale. Default expiry periods:- Access reviews: 6 months
- Penetration test reports: 12 months
- Policy acknowledgements: 12 months
- Security training: 12 months
- Vendor assessments: 12 months
Bulk evidence upload
For initial setup or annual evidence refreshes, use bulk upload:- Go to Evidence → Bulk upload
- Download the evidence mapping template
- Fill in evidence files and their control mappings
- Upload the ZIP file