Assessment-ready
One command hands the assessor the whole evidence pack.
From the Compliance hub, a single command produces a timestamped, air-gap-friendly .zip assembled entirely from live state — no hand-collation the night before. Inside is the system security plan status, a live POA&M of open gaps, the responsibility matrix, the asset inventory and the audit log, all under a signed manifest. Alongside it, an append-only, hash-linked audit chain lets you prove nothing was edited after the fact.
- One command, one pack — a timestamped .zip built from live state, suitable for a disconnected site, with no manual assembly.
- Everything an assessor asks for — SSP control status, a live POA&M of gaps, the responsibility matrix, the asset register and the audit log.
- Signed manifest — a SHA-256 hash of every file plus a detached signature, so the pack proves it wasn't altered after export.
- Tamper-evident audit chain — an append-only, hash-linked, signed log that detects after-the-fact modification cryptographically (tamper-evident — not WORM, not immutable).