Assurance & evidence
Turn findings and decisions into continuous, audit-ready proof.
Assurance is what separates TraceGuard from a scanner: it turns the work you do (scans, triage, VEX, decisions) into evidence you can hand to an auditor or regulator at any time.
Assurance log
The assurance log is an append-only record of what happened and when — uploads, scans, decisions, and VEX assertions — so you can always show how you reached a given posture, not just the current state.
Snapshots
A snapshot captures your posture at a point in time. Snapshots are useful for release gates ("here's exactly what we shipped and knew on this date") and for showing change over time.
Evidence bundles
An evidence bundle is an exportable package — findings, decisions, VEX, and snapshots — assembled for a specific audience (an auditor, a customer security review, a regulator). Generate one from the Evidence view.
Audit log
Underpinning all of this is a tamper-evident audit log of administrative and security-relevant actions. You can export it, inspect individual entries, and the UI surfaces a banner if tamper-evidence checks ever fail.
For regulated and public-sector buyers, this is usually the headline feature: continuous, verifiable evidence rather than a point-in-time PDF.
Next
Keep your team informed automatically with Notifications & reports.