Evidence library

Proof, not checkboxes.

Collect the evidence once and reuse it everywhere. Every framework, questionnaire and renewal asks for versions of the same twenty things — Sentinel keeps them in one library, each item with an owner, a status and an expiry date, so a lapsed penetration test is flagged there before an auditor finds it.

Self-service signup opens shortly — we will set you up in the meantime

EvidenceSentinel interface, reproduced

Evidence status

26 controls
  • Accepted41
  • Needs Review2
  • Pending1
  • Expired1
  • Missing1

Register

Expiring first
  • Backup restore test report — Q3 2026
    Control
    A.8.13
    Owner
    Jordan Blake
    Status
    Missing
    Validity
    Due 30 Sep 2026
  • Penetration test report — external (2025)
    Control
    A.8.8
    Owner
    Priya Raman
    Status
    Expired
    Validity
    Expired 20 Jul 2026
  • Privileged account inventory
    Control
    A.8.2
    Owner
    Priya Raman
    Status
    Needs Review
    Validity
    Uploaded 4 Sep 2026
  • + 3 more in the workspace

The evidence register, expiring first. Figures are from the example workspace used across this site — Northstar Manufacturing Ltd. is fictional.

7
Evidence statuses, used identically everywhere in the product
4
Frameworks one item can answer at once
Per item
Owner, status and expiry date on every piece of proof
ca-central-1
Evidence stored in Canada

A control without evidence is only a claim.

An auditor, an underwriter and a customer's security team are all asking the same thing in different words: show me that this operated, and show me when. A folder of documents cannot answer that on demand, however complete it is.

The problem

Nobody loses their evidence. They lose track of whether it is still true.

The proof almost always exists somewhere. What has gone is the record of what it was for, who owned it, and when it stopped counting. That is not a filing problem — it is what makes a security review take three weeks instead of three days.

Four things every reader has personally seen

  1. 01

    A folder called “Audit 2024”

    Three levels into somebody else’s drive. They left in March, and the drive went with their licence. The contents were fine. Nobody can reach them.

  2. 02

    The same PDF, five times

    Attached to an ISO request, a SOC 2 request and three customer questionnaires. The policy has since been revised, and four of the five copies are the old one.

  3. 03

    A penetration test from 2023

    Still being sent to prospects. Nobody looked at the date on the cover page, including the people sending it.

  4. 04

    A screenshot you cannot reproduce

    MFA was enforced the day the screenshot was taken. The exception list has grown since. The screenshot has not.

Status

Seven words, used the same way every time.

A status is only useful if everybody in the building reads it identically. These seven are the ones Sentinel uses — on the item, on the control register, in the gap list and in the reporting. Not a maturity ladder, and not a score. Seven words.

The seven evidence statuses Sentinel uses, what each means, and what each is worth when evidence is requested
StatusWhat it meansWhat it is worth when somebody asks
AcceptedA named reviewer agreed this item evidences this control, and the date they agreed is on the record.Full. This is the only state that means somebody with authority looked.
ApprovedThe same decision recorded on the document itself — a policy signed off by whoever is allowed to sign it.Full, for the document. The control still needs proof that it operated.
Under ReviewThe item exists and is with a reviewer. Nobody has agreed yet that it does the job.Nothing yet. It is work in progress, and it is visible as work in progress.
PendingRequested and expected, not yet supplied. The control already knows what it is waiting for.Nothing yet. But the gap has a name and an owner rather than being an empty cell.
DraftWritten and not approved. The annual review was started and never signed.Nothing. A draft policy is a draft policy however good the drafting is.
ExpiredPast its expiry date. Somebody had this, and it lapsed.Nothing — and it is the more embarrassing kind of nothing, because it used to be there.
MissingThe control needs proof and there is none on file.Nothing. It sits on the register as a named item with an owner, not as a blank.

The mix, in the example workspace

26 controls, 26 expected items.

  • Accepted41
  • Needs Review2
  • Pending1
  • Expired1
  • Missing1

1 expired and 1 missing — 2 of 26. A quarter of the library would fail on the day somebody asked, and the point of the bar is that you can see which quarter.

Missing and Expired are not shaded politely

An expired policy and a missing policy are worth the same to the person asking: nothing. A tool that renders Expired in a gentler colour is being kind about the one that is more embarrassing, because somebody had it and let it go.

Expiry

A date on every item is the whole difference between a folder and a system.

A shared drive holds the same files. What it cannot do is know that the restore test is due on 30 September, which control rests on it, and that it is flagged in the library once it lapses, not found during fieldwork.

  • Every item carries an expirya validity date, not a filename with a year in it
  • Sorted by what fails firstthe register opens on the items closest to their date
  • Renewal is dated workan action with an owner, not a reminder in one person’s calendar
  • The superseded item is keptso the period it covered is still on the record

See how a lapse becomes owned work

Register — expiring first

Example data
  • Backup restore test report — Q3 2026
    Control
    A.8.13
    Owner
    Jordan Blake
    Status
    Missing
    Validity
    Due 30 Sep 2026
  • Penetration test report — external (2025)
    Control
    A.8.8
    Owner
    Priya Raman
    Status
    Expired
    Validity
    Expired 20 Jul 2026
  • Privileged account inventory
    Control
    A.8.2
    Owner
    Priya Raman
    Status
    Needs Review
    Validity
    Uploaded 4 Sep 2026
  • + 3 more in the workspace

One requirement, traced

Follow one line all the way through.

A spreadsheet can hold every one of these rows. What it cannot do is know that the A.8.13 backup evidence expired in February, that the evidence library flags it, and that somebody needs to run a restore test before the renewal.

Six records, one link each. Break any link and you are back to a claim.

CyberWave diagram · one requirement, traced

  1. Requirement
    ISO/IEC 27001:2022 · A.8.13
    Information backup
  2. Control
    Backups immutable and offline
    Operating
  3. Owner
    M. Delacroix
    Accountable
  4. Evidence
    Backup restore test — Q4
    Expired 18 Feb 2026
  5. Gap
    Restore test out of date
    Open, awaiting retest
  6. Action
    Run and document restore test
    Due 15 Apr 2026

Reuse

One item, every framework that asks for it.

Frameworks overlap far more than their numbering suggests. The library is organised around the proof, not around whichever audit asked for it first — so the fourth questionnaire of the year is an afternoon rather than a fortnight.

ISO/IEC 27001:2022
MFA enforcement export
A.5.16 Identity management
Backup restore test
A.8.13 Information backup
Awareness training completion
A.6.3 Awareness, education and training
Supplier security reviews
A.5.19 Supplier relationships
SOC 2
MFA enforcement export
Logical access (CC6)
Backup restore test
Availability (A1)
Awareness training completion
Control environment (CC1)
Supplier security reviews
Risk mitigation (CC9)
NIST CSF 2.0
MFA enforcement export
PR.AA — Identity management, authentication and access control
Backup restore test
PR.DS — Data security
Awareness training completion
PR.AT — Awareness and training
Supplier security reviews
GV.SC — Cybersecurity supply chain risk management
CIS Controls v8.1
MFA enforcement export
Control 6 — Access control management
Backup restore test
Control 11 — Data recovery
Awareness training completion
Control 14 — Security awareness and skills training
Supplier security reviews
Control 15 — Service provider management
Insurer questionnaire
MFA enforcement export
Question 1 — MFA on email, remote access and admin
Backup restore test
Question 3 — backups immutable, offline and restore-tested
Awareness training completion
Question 7 — training and phishing simulations
Supplier security reviews
Question 8 — critical vendor and third-party reviews

Because the item exists once, the expiry date exists once. Renewing the restore test updates the ISO control, the SOC 2 criterion, the CIS safeguard and the insurer answer together — rather than four copies of one document drifting apart over a year.

Sentinel supports readiness, governance, assessment, evidence organisation and control management. CyberWave does not certify compliance, issue audit opinions, guarantee compliance, or replace independent auditors, certification bodies or legal counsel. Framework references are informational readiness mappings.

Gaps

A gap list is a work list, not a percentage.

“73% evidence coverage” is a number people argue about in a meeting. “The restore test expired in February and the supplier reviews have no owner” is a number of afternoons.

1
Expired

Items past their date. Somebody had these, and they lapsed.

1
Missing

Controls that need proof and have none on file.

2
Unowned

Controls with nobody’s name against them, of 26.

The same figures, as rows to work

Example data · anything not Accepted
  • Backup restore test report — Q3 2026
    Control
    A.8.13
    Owner
    Jordan Blake
    Status
    Missing
    Validity
    Due 30 Sep 2026
  • Penetration test report — external (2025)
    Control
    A.8.8
    Owner
    Priya Raman
    Status
    Expired
    Validity
    Expired 20 Jul 2026
  • Privileged account inventory
    Control
    A.8.2
    Owner
    Priya Raman
    Status
    Needs Review
    Validity
    Uploaded 4 Sep 2026
  • + 1 more in the workspace

It works in the other direction too. When a document turns up that nobody requested, it can be filed against the controls it happens to cover — which is how the useful half of an old audit folder gets rescued instead of re-created.

Underwriting

A package a broker can forward without editing it.

An insurer’s security questionnaire is an evidence request with a deadline attached. The answers are already in the library. The work is assembling them into something an underwriter can read in order.

  • Answered from the register

    Each answer carries the item it came from and the date that item was accepted — rather than an assertion typed into a form by whoever had the tab open.

  • An index the underwriter can follow

    What is attached, what it evidences, when it was accepted and when it expires. A reviewer sees the shape of the programme without opening every file.

  • The gaps, before they are found

    Anything Missing or Expired is visible to you first. Knowing about a gap and having a dated plan for it is a different conversation from being asked about it cold.

  • The same pack, next renewal

    The library persists and the items carry dates, so next year is an update rather than a rebuild.

Prepare for a renewal

Cyber Insurance Submission Pack

A reviewed, broker-ready evidence and questionnaire package assembled from your workspace.

$499one-time

Assembled and reviewed by CyberWave from your own workspace. Arranged with us rather than bought at a checkout, because the scope depends on what your renewal asks for.

CyberWave helps you prepare for underwriting and security questions, organise evidence, identify possible gaps and plan remediation. CyberWave is not an insurer or an insurance broker, does not bind coverage, does not interpret policy coverage as legal advice, and does not guarantee coverage, premium reduction, claim payment or insurer acceptance. You remain responsible for complete and truthful representations to your insurer or broker.

Questions

What buyers ask about the evidence library.

Including the three nobody volunteers: who accepts an item, where the files sit, and whether we grade proof by how strong it is.

The evidence library is included from Essentials upwards, at $99 per month. Broker and underwriter evidence packages are part of Full Platform.

Compare plans
Can one evidence item count towards more than one framework?
That is the point of a library rather than a folder per audit. An MFA configuration export can satisfy an access control requirement in ISO 27001, a criterion in SOC 2, a safeguard in CIS Controls and question one of an insurer’s form. You attach it once and it appears against all of them, with one expiry date that everybody is working from.
Do you rate evidence by how strong the proof is — self-declared, attested, independently tested?
No, and it would be easy to imply otherwise. Sentinel uses the seven statuses on this page: Accepted, Approved, Under Review, Pending, Draft, Expired and Missing. There is no tiered trust model in the product, so there is none on this page. A layered model is a sensible idea and if it ships we will show it then — describing it now would put a capability in front of you that you cannot use.
Does Sentinel collect evidence from our systems on its own?
Evidence is attached by the people who own the control, because they are the only ones who know whether an export actually shows what it appears to show. When you upload a document, Sentinel pulls out its text, sorts it by document type and notes which common frameworks it names — and the item stays in Needs Review until someone on your side accepts it.
Who decides an item is Accepted?
You do. Acceptance is a named person in your organisation agreeing that this item evidences this control, on a date. CyberWave does not verify your evidence, certify compliance or issue an opinion on it — an auditor, a certification body and an underwriter each form their own view, and they will ask for the underlying item, not for our status label.
Where is our evidence stored, and who can reach it?
Documents and records are stored in Supabase in Canada (ca-central-1) and scoped to your own workspace. The application runs on Vercel in the United States, and AI requests are processed by Anthropic in the United States. The security page sets out the detail, including what leaves the tenant and what does not.
We already have hundreds of documents. Is this a migration project?
Start with the requirement that is actually due — one framework, or the insurer’s questionnaire — and attach the proof for those controls. The rest of the drive can stay where it is until something asks for it. A library covering the twenty controls somebody is about to ask about beats a complete index nobody finished.

Start with the twenty documents somebody is about to ask for.

Not a full index of the drive. One framework or one renewal, the controls it touches, and the proof attached to them with a date on it. The rest builds itself from there.

Book a walkthrough

Self-service signup opens shortly — we will set you up in the meantime

  • Published pricing — no quote-on-request tier
  • No credit card required for the trial
  • No automatic charge when a trial ends
  • Tenant-isolated architecture, data stored in Canada
  • Clear data-processing terms
  • No compliance guarantee — human judgement still required