The artifact · sample download

The pack your auditor accepts.

Seven sections. One PDF. Signed and hash-verifiable. Built for the auditor's review, not the vendor's pitch. Sample is the real format, with realistic synthetic data.

Telemetry surfaces included with every Evidence purchase · observation-only by default

PDF 9 pages SHA-256 signed ISO 42001 variant

01 / Anatomy

Seven sections. Built for the auditor's read.

Every section earns its place. Auditors asked for it during interviews. Nothing is here to look impressive on a deck.

Section 01 · Cover

The page your auditor sees first.

Organization name, framework + version, period covered, generated-at timestamp, SHA-256 of the underlying event log, and the signing identity. No marketing. No logo larger than the framework name.

Organization: Acme Holdings, Inc. Framework: ISO/IEC 42001:2023 Period: 2026-04-01 to 2026-06-30 Generated: 2026-05-21T14:02:33Z SHA-256: 7b32fc4e91d83a9e02c6 b5d419af8e7c3d0a51f4 6e2f7a8b9c0d1e2f3a4b Signed by: CN=Northbeams Evidence v1, O=Northbeam Pte Ltd

Section 02 · Scope

What we're claiming. What we're not.

Surfaces observed (browser, desktop, CLI, MCP). Agents and users covered. Explicit out-of-scope: services accessed via API tokens that bypass the browser and desktop, on-prem inference that never leaves the network, and any usage not captured by an installed Northbeams client. Honesty up front. Auditors trust scoping more than blanket claims.

Section 03 · Control mapping

Every control, with status and underlying evidence.

For each control in the framework: AUTO-evidenced (Northbeams telemetry alone proves it) / ATTESTed (someone signed off, with timestamp + actor) / scoped-out (with reason). Each row links to the query and the sampled events in the appendix.

A.6.2.6 AI system monitoring AUTO 142,318 events A.8.4 Reporting concerns ATTEST j.tanaka 2026-05-12 A.10.2 Allocation of responsibilities ATTEST CISO 2026-04-30 A.6.2.4 Verification and validation SCOPED Out: on-prem inference

Section 04 · Evidence appendix

Sampled events. The auditor's drilldown.

For each AUTO control, the top-N high-risk tool calls, blocked actions, and attested controls with timestamps and actors. Argument hashes, never argument values (the values stay on the user's device by design). Auditors get enough to verify the AUTO claim without needing the raw data.

Section 05 · Exceptions & gaps

Where we don't satisfy a control. With a name attached.

Controls not satisfied. Each one carries a reason ("compensating control X covers this," "remediation in flight," "explicitly out of scope") and a remediation owner with a deadline. This is the section auditors flip to first to test honesty.

Section 06 · Methodology

How the data was collected. How long it was kept.

Collection model (browser extension, desktop app, MCP Gateway in-path). Retention defaults per tier. Integrity claim: append-only event log, hash-chained, every batch's hash committed to the next batch's header. The pack carries the chain's tail hash so an auditor can verify integrity end-to-end.

Section 07 · Signatures

The customer's attestation and ours.

An owner attestation block (the customer's compliance officer or vCISO signs). A cryptographic signature over the document from Northbeams. HMAC v1 today; X.509 v2 within 90 days; optional customer-side key escrow on Enterprise. Verifiable at /trust/verify.

02 / Integrity

Three things make a pack auditor-credible.

Auditors do not trust vendor PDFs. They trust verifiable claims. The pack is engineered to be verifiable, even if Northbeams is offline.

01 · Signature

SHA-256 + detached signature.

Every pack carries a hash of its underlying event log and a detached cryptographic signature. Re-hash the file; compare to the cover. Paste the hash at /trust/verify.

02 · Hash chain

Append-only, hash-chained events.

Each daily event batch carries the hash of the previous batch in its header. Tampering with history breaks the chain. The pack carries the chain's tail hash for end-to-end verification.

03 · Scope honesty

Out-of-scope is named, not hidden.

The scope statement lists what we don't see (API-token usage, on-prem inference, off-network devices). Auditors trust packs that admit limits over packs that claim everything.

03 / Cadence

On-demand, scheduled, or webhook-driven.

Generate one before a vendor questionnaire. Schedule one a month. Wire your GRC platform to pull a fresh pack on every control-status change.

On-demand

Click "Generate Evidence Pack" in the dashboard. Pick framework + period. Pack lands in under a minute. Stored under /orgs/{org}/evidencePacks/, downloadable forever.

Monthly schedule

A scheduled Firebase function runs at month-end, generates the pack, emails it to nominated recipients (compliance officer, vCISO, your auditor's shared mailbox), and pushes evidence to the linked GRC integrations.

Webhook-driven

Register a webhook on the Evidence API. Whenever a control flips status (AUTO → gap, ATTEST expired, sampled exception found), the webhook fires. Your GRC platform pulls a fresh delta pack on event.

04 / Variants

One generator. Four framework mappings.

Same anatomy. Same integrity model. The Control Mapping section differs per framework, because the controls do. Pick a framework to see how the section looks.

ISO/IEC 42001:2023 · 38 Annex A controls

14 AUTO, 19 ATTEST, 5 scoped-out by default. Customer can re-classify any row with a written reason.

ControlTitleStatusEvidence source
A.6.2.6AI system monitoringAUTOContinuous event log across 4 surfaces
A.6.2.4Verification and validationATTESTQuarterly attestation by Head of AI
A.7.4Quality of dataATTESTData steward attestation
A.8.4Reporting concernsAUTOIn-product report channel + log
A.9.3Objectives of responsible AI useATTESTAnnual policy attestation
A.10.2Allocation of responsibilitiesATTESTRACI document signed off
A.10.3Supplier relationshipsSCOPEDProcurement system, not Northbeams

05 / Pricing

Annual. Flat. Per-framework or all-in.

The pack is included on the Compliance tier. Annual fee, flat, no per-seat math. Three options sized for what you actually need.

Starter

$12,000 / yr

1 framework. Monthly pack. 1 GRC integration. 90-day retention.

Pro

$36,000 / yr

All frameworks. On-demand + scheduled. All integrations. 1-year retention.

Enterprise

$72,000+ / yr

SSO, custom controls, 7-year retention, dedicated CSM, SLAs.

Forward the pack to your auditor. Reply with what's missing.

The sample is the real format with synthetic data. Reply with anything the auditor flags and we'll iterate together. Build partners are how we got the format right; we want more.