Skip to content

Evidence Capture Log

Purpose. The running chain of custody for every artefact filed in the evidence store: what it proves, who captured it, when, how, and its SHA-256 so integrity can be re-verified at any time. Written automatically by tools/evidence.pydo not edit rows by hand; the hash is the point.

Artefacts live in s3://soon-isms-evidence (account 404379474355, Object Lock 3 years). This log is the index. Together with CloudTrail data events they answer "who did what, when" without any database — see Evidence Collection & Management §4.7.

Captured (UTC) Control SOC 2 Description Method Captured by SHA-256 S3 key