9
collected
0
pending
1
needs review
0
expired
Add Evidence
Submit via POST /api/trust-ops/evidence-upload with metadata JSON.
| ID | Title | Type | Linked Controls | Owner | Status | Collected | Review Due |
|---|---|---|---|---|---|---|---|
| EVD-001 | Information Security Policy Document Internal documentation — content/security/security… | document | CTL-001CTL-014 | Engineering Lead | collected | 2026-02-01 | 2027-02-01 |
| EVD-002 | RBAC Role Definition Export Admin console role export / Supabase admin dashboa… | configuration export | CTL-002CTL-013 | Engineering | collected | 2026-03-01 | 2026-09-01 |
| EVD-003 | Audit Log Sample — 30-Day Export audit_events table — exported via /api/audit/expor… | log export | CTL-004CTL-013 | Engineering | collected | 2026-04-01 | 2026-07-01 |
| EVD-004 | Infrastructure Encryption Attestation — Supabase & Vercel Supabase Security Documentation / Vercel SSL docum… | attestation | CTL-005CTL-006 | Engineering | collected | 2026-01-15 | 2027-01-15 |
| EVD-005 | Incident Response Plan content/security/incident-response-program.md… | document | CTL-007 | Engineering Lead | collected | 2026-02-15 | 2027-02-15 |
| EVD-006 | Business Continuity Summary content/security/business-continuity-summary.md… | document | CTL-008 | Engineering Lead | needs review | 2026-02-15 | 2026-08-15 |
| EVD-007 | Data Retention and Deletion Standard content/security/data-retention-deletion-standard.… | document | CTL-009 | Engineering | collected | 2026-03-01 | 2027-03-01 |
| EVD-008 | Subprocessor List content/security/subprocessors.md… | document | CTL-010 | Engineering | collected | 2026-01-01 | 2027-01-01 |
| EVD-009 | CI/CD Pipeline Configuration GitHub Actions / Vercel deployment configuration… | configuration export | CTL-011CTL-012 | Engineering | collected | 2026-03-15 | 2026-09-15 |
| EVD-010 | DPA Template content/legal/dpa.md… | document | CTL-015 | Legal | collected | 2026-01-01 | 2027-01-01 |