Evidence library (Improve)

Centralize evidence attached to your processing activities, controls, and measures: screenshots, contracts, emails, certifications. Essential for audits and investigations.

2 min read

Why a dedicated Evidence module?

A compliance program is only as strong as the evidence it can produce. The Evidence module (Improve > Evidence) centralizes all artifacts that demonstrate your policies are actually applied: configuration screenshots, signed contracts (DPA, NDA), validation emails, sub-processor certifications (SOC 2, ISO 27001), log exports, review minutes. Instead of scattering these files across emails or shared drives, you attach them directly to the element they relate to.

Attaching an evidence

From any record (processing activity, security measure, sub-processor, PIA, incident), click "Add evidence". Upload a file (PDF, image, Office document) or paste an external link (SharePoint, Google Drive). Provide the evidence type (contract, screenshot, certification, email, other), a short description, and an expiry date if applicable (e.g., SOC 2 certification renewed annually). The evidence then appears in the "Evidence" panel of the record and in the central library.

Attaching an evidence

Attaching an evidence

Central library and search

The library (Improve > Evidence) lists all evidence in your tenant, filterable by type, source module, owner, or expiry date. Full-text search covers file names and descriptions. This view is particularly useful when preparing for an audit: you can export in a few clicks all evidence attached to a processing activity, a control, or a given period.

Expiry dates and alerts

Evidence with an expiry date (certifications, attestations, annual audits) triggers automatic alerts 60, 30, and 7 days before expiration. Expired evidence is flagged on the source record and counts negatively against the health score of the relevant module. This avoids surprises during external audits.

Tip

Always attach the signed DPA to each sub-processor and the latest certification (SOC 2, ISO 27001) with its expiry date: Conformaze will remind you to renew them before they lapse.

Traceability and exports

Every evidence carries the identity of who uploaded it, the upload date, and an access log. PDF exports of the ROPA registry and PIAs include in appendix the list of associated evidence with links to their location. This traceability is what turns a theoretical file into legally defensible proof.

    Evidence library (Improve) — Conformaze Help Center | Conformaze