UprootSecurity
Book a demo

Read-only access · scoped + time-boxed

PRODUCT

Hand the auditor a key, not an inbox.

A scoped, read-only, time-boxed window into your live evidence. Auditors pull exactly the artifacts mapped to the criteria they’re testing hashes attached. You answer nothing twice, and every view is logged as part of the record.

Start free trialSee a sample portal
3 daysMedian fieldwork
0Email attachments
100%Access logged
audit.uproot.security · /soc2-2026Live
Prescott & Hale LLP · read-only auditor sessionexpires in 11d
Evidence requests · SOC 2 Type II
period 2025-06-01 → 2026-05-31 · 64 controls
78%
fulfilled
CC6.1 · Logical access & MFA
14 artifacts resolved
CC7.2 · Monitoring of controls
9 artifacts resolved
CC8.1 · Change management
22 artifacts resolved
A.8.24 · Use of cryptography
6 artifacts resolved
CC1.4 · Background checks
requesting HR export…
How an audit runs on Uproot

Grant once. They self-serve. You're barely in the loop.

The back-and-forth that turns a two-week audit into a two-month one disappears. The auditor works directly against live, mapped, hashed evidence and you watch progress instead of answering tickets.

01Scope

Define exactly what they can see.

Pick the framework, the audit period, and the control set. The grant is read-only, time-boxed, and revocable in one click. Nothing outside scope is reachable.

Access read-only
02Request

They ask for criteria, not files.

The auditor selects the criteria they’re testing. Uproot resolves each to the live artifacts that back it already mapped, no fetching on your side.

Mapping automatic
03Fulfill

Answered from the library, instantly.

Artifacts arrive with their hash, signature, source, and timestamp. Where evidence is fresh and complete, the request fulfills itself with no human touch.

Median seconds
04Log

Every view becomes part of the record.

Who looked at what, and when, is captured immutably. The access trail is itself an artifact useful to you, and reassuring to the next auditor.

Trail immutable
What the portal gives each side

Self-serve for the auditor. Quiet for your team.

The portal is the same evidence your engineers already produce, presented in the auditor's language criteria, periods, and provenance without a single file changing hands by email.

PH
Prescott & Hale LLP
auditor session · 3 named seats
Framework
SOC 2 Type II
Period
Jun 25 – May 26
Access
Read-only
Expires
in 11 days
SSO enforcedNo data exportRevocable
Scoped, time-boxed access

The narrowest door that still gets the audit done.

An auditor session sees one framework, one period, one control set and nothing else. No production access, no standing credentials, no copy of your data leaving the boundary. Revoke the instant fieldwork ends.

Read-only by construction the portal has no write path

Auto-expiring grants with a visible countdown for both sides

SSO for auditor firms; per-seat, named, individually revocable

Read the access model
Criterion
CC6.1
Logical access controls
Criterion
A.5.16
Identity management
Artifact
okta/user-mfa-state
312 users · 1m ago
Artifact
aws/iam-policy
142 policies · 4m ago
Artifact
github/branch-rules
84 repos · 12m ago
Criteria, resolved to proof

They click a criterion. The evidence is already there.

Because every artifact is mapped to the controls it backs, a request resolves instantly to the right set hash and source attached. No scavenger hunt, no "which screenshot was this again."

Each criterion shows its backing artifacts, live and dated

Drill from a control to the exact API response that satisfies it

Gaps are visible to you first flagged before the auditor asks

See control mapping
Auditor access trail
session ph-2026-soc2 · live
Logging
14:02:11
PH
Opened CC6.1
viewed 14 artifacts · 0 questions
14:09:48
PH
Verified hash on okta/user-mfa-state
signature valid · ed25519
14:21:30
PH
Filed a note on CC8.1
"confirm 2-reviewer rule on hotfix branch"
14:24:02
PH
Marked CC7.2 satisfied
9 artifacts accepted
The access trail is evidence too

You can see exactly what the auditor saw.

Every artifact view, export attempt, and criterion opened is logged immutably to the same library. It’s reassurance for you, a clean handoff for the next audit, and a control in its own right.

Immutable, timestamped access log per session

Notifications when a new criterion is opened or a question is filed

The trail exports with the rest of your evidence at year-end

Inspect the audit trail

What the portal does to audit timelines.

3d
Median fieldwork, down from a typical 3–4 weeks of email
71%
Of evidence requests fulfilled with zero human involvement
0
Files emailed, uploaded to a shared drive, or re-sent
One portal, three audiences

Built for everyone who'd otherwise be in the email thread.

The same scoped, read-only window serves external auditors, enterprise security reviewers, and your own leadership each seeing exactly their slice.

PH
External auditorsSOC 2 · ISO

Run fieldwork directly against live evidence. Request by criterion, verify by hash, file notes inline no shared drives.

Per-criterion artifact resolutionlive
Offline-verifiable signaturesed25519
Inline notes & sampling requestslogged
EN
Enterprise reviewersSecurity questionnaires

Hand a prospect's security team a scoped trust view instead of a 300-row spreadsheet. Answer once, share the proof live.

Trust-center style read viewscoped
NDA-gated document accessgated
Reusable across deals
UP
Your leadershipInternal

Give the CISO and board a read-only posture view readiness, open gaps, audit progress without giving them the admin console.

Readiness & gap rollupslive
Audit progress trackinglive
No write access requiredread-only

When we evaluated our options for compliance and securing our systems, we found that UprootSecurity's compliance and security model aligned perfectly with our needs. It gave our team real-time visibility into the end-to-end process, saving our engineers hundreds of hours of manual effort.

YN
Yogesh NarayanCTO
3d
Fieldwork, down from three weeks the prior year
Common questions

What teams ask before granting access.

Granting an outside firm a window into your evidence raises obvious questions. Here's how the boundary holds.

Can an auditor reach anything outside the agreed scope?+

No. A session is bound to one framework, one period, and one control set at grant time. There's no navigation path to production, other frameworks, or unmapped artifacts the portal simply doesn't render them.

Is there any write access at all?+

The portal has no write path to your systems. Auditors can view artifacts, verify hashes, and file notes or sampling requests all of which land in Uproot, never in your infrastructure.

What does the auditor's firm need to set up?+

Named seats with SSO. Each auditor logs in individually; access is per-person and revocable, so you can pull a seat the moment someone rolls off the engagement.

Can we use this for enterprise security reviews too?+

Yes same mechanism, different scope. Grant a prospect's security team a read-only trust view gated behind your NDA, and answer their questionnaire by pointing at live proof instead of filling a spreadsheet.

What happens to the access log?+

It's written immutably to your evidence library and exports with everything else. The trail of who-saw-what is itself a control many frameworks require so the portal produces that evidence just by being used.

Give your auditor a login, not a to-do list.

Scope a session, send one link, and watch the requests fulfill themselves. Revoke when fieldwork's done.

Start free trialBook a demo

Scoped & revocable

One framework, one period gone in a click.

No attachments

Auditors read live evidence; nothing leaves by email.

Self-fulfilling requests

Mapped, hashed evidence answers most requests automatically.

Every view logged

The access trail becomes part of your record.