UprootSecurity
Book a demo

38,412 artifacts under chain of custody

PRODUCT

A screenshot is a story. Uproot stores the proof.

Evidence is pulled directly from your systems of record signed, sha256-hashed, timestamped, and versioned the moment it lands. Auditors stop asking for what you already have; engineers stop being the screenshot department.

Start free trialTour the library
38,412Artifacts stored
6 minMedian freshness
100%Hash-verified
app.uproot.security · /evidenceLive
Evidence library · production
collected from 140 sources · signed + hashed
38,412
Artifacts
Fresh < 1h
99.2%
of all evidence
Sources online
140 / 140
no gaps
Stale flagged
4
auto re-pull
Collecting now● Live
AW
aws/iam-policy-snapshot
GetPolicyVersion · v412 · 200 OK
Sealed
OK
okta/user-mfa-state
312 users · factor enrollment
Sealed
GH
github/pr-approvals
84 repos · reviewer trail
Sealed
Chain of custody
aws/iam-policy-snapshot · v412
Pulled
aws iam:GetPolicy · 02:14:02Z
Hashed
sha256:9f2a…c41e
Signed
uproot-evidence-key · ed25519
Sealed
immutable · WORM · 7y retention
How evidence gets collected

Pulled, hashed, signed, sealed. Without a human in the loop.

No upload forms. No screenshots. Every artifact arrives from the system that owns the truth, and carries a cryptographic record of exactly where it came from and when.

01Pull

Straight from the system of record.

IAM policies, MDM posture, merged PRs, on-call rosters, vendor DPAs read through the same API the source exposes to its own console.

Sources 140+
02Hash

A sha256 fingerprint at write-time.

The artifact's bytes are hashed the instant they land. Any later mutation is detectable; the hash is the artifact's identity in the library.

Digest sha256
03Sign

Provenance you can verify offline.

Each artifact is signed with an org-scoped ed25519 key. Anyone including your auditor can verify it was collected by Uproot and not altered since.

Key ed25519
04Seal

Versioned, immutable, retained.

Stored write-once with full version history and a retention clock that matches your framework. Nothing is overwritten; new state becomes a new version.

Storage WORM · 7y
What lives in the library

Proof that holds up to an auditor and to an attacker's lawyer.

Every artifact is connected to the control it satisfies, the framework that references it, and the exact moment it was true. The library is the single source the audit reads from.

aws/iam-policy-snapshot
v412 · collected 02:14:02Z · sha256:9f2a…c41e
AW
GetPolicyVersion · app-prod-rw200 OK · 142ms
{
  "PolicyName": "app-prod-rw",
  "VersionId": "v7",
  "CreateDate": "2026-05-30T02:14:02Z"
}
Evidence from systems of record

The artifact, not a picture of the artifact.

A screenshot proves someone saw a screen once. Uproot stores the API response itself the IAM policy JSON, the device record, the merge event with the request that produced it captured alongside.

Structured artifacts: JSON, config, logs queryable, diffable, exportable

The exact API call and parameters stored next to the result

Re-collected on a schedule, so the library never goes stale silently

See supported sources
Evidence freshness · by source
window-relative
AWS IAM
snapshots
4m ago
Okta MFA
user state
1m ago
GitHub PRs
approvals
12m ago
Kandji MDM
device posture
46m ago
Vendor DPAs
documents
today
Freshness, not folders

Evidence has an age. Uproot shows it.

Most tools treat evidence as a file you uploaded once. Uproot treats it as a measurement with a timestamp and a half-life when something ages past its window, it's flagged and re-pulled before an auditor notices.

Per-artifact freshness window, tuned to the control it backs

Stale evidence auto-queues for re-collection; you're never caught flat

Freshness rolls up per control, per framework, per audit period

How freshness windows work
CC6.1 · Logical access controls
14 artifacts · IAM, Okta, GitHub
Fulfilled
CC7.2 · Monitoring of controls
9 artifacts · Datadog, Uproot monitor
Fulfilled
A.8.24 · Use of cryptography
6 artifacts · KMS, RDS, TLS configs
Fulfilled
CC1.4 · Background checks
awaiting HR export · auto-pull queued
Pending
Handoff without attachments

Auditors read from the library. Nothing leaves by email.

Grant a scoped, read-only, time-boxed view. Auditors pull exactly the artifacts mapped to the criteria they’re testing hash and signature attached. No zip files, no shared drives, no "can you re-send that."

Scoped to a framework, a period, a set of controls revocable any time

Every artifact links to the live control it backs

Full access log: who viewed what, when part of the evidence itself

See the auditor portal

What the library replaces, measured at year one.

0
Screenshots requested by an auditor in the last 3 audit cycles
6m
Median evidence freshness across every connected source
38k
Artifacts under live chain of custody for a typical Series C
What gets collected, and how often

Every control's proof, on its own clock.

Each artifact type has a freshness window tuned to how fast the underlying truth can change. Fast-moving state is re-pulled in minutes; slow documents, daily.

AW
Cloud config12.4k artifacts

IAM policies, security groups, KMS keys, CloudTrail settings the literal control-plane state, snapshotted and diffed.

IAM policy + role snapshots15m
Encryption + key rotation state15m
CloudTrail / log integrity config1h
OK
Identity events8.1k artifacts

MFA enrollment, SSO coverage, access grants and revocations captured as events, so the history is the evidence.

MFA + factor state per user5m
Joiner / mover / leaver eventsevent
Access review attestationscycle
GH
Change management9.7k artifacts

PR approvals, reviewer trails, CI gate results, signed commits the merge record that proves your SDLC controls held.

PR approval + reviewer trailmerge
CI gate + check resultsmerge
Branch protection config1h
KJ
Endpoint posture3.9k artifacts

Disk encryption, OS version, EDR health, screen-lock policy pulled from MDM/EDR, not a self-attestation survey.

FileVault / BitLocker state1h
EDR enrollment + health15m
OS patch level per device1h
VN
Vendor documents2.6k artifacts

SOC 2 reports, DPAs, pentest letters, sub-processor lists attached to the vendor record and expiry-tracked.

SOC 2 / ISO attestations1d
Signed DPAs + expiry1d
Sub-processor disclosures1d
UP
Program records1.7k artifacts

Policies, risk assessments, incident timelines, training completion the human-process evidence, versioned like code.

Policy versions + approvalson change
Incident + postmortem recordsevent
Security training completion1d

Uproot PtaaS offers the perfect suite of features to ensure the highest security standards for our clients. We are impressed by their dedication to continuous testing. Their seamless integration combined with the hacker mindset and thorough manual pentesting approach, truly sets them apart.

GK
Gaurav KulkarniCEO
1
Link shared, instead of a 240-file evidence zip
Common questions

What teams ask about the evidence model.

Evidence integrity is the part auditors scrutinize hardest. Here's how the library holds up.

How do you prove an artifact wasn't altered after collection?+

Each artifact's bytes are hashed with sha256 at write-time and signed with an org-scoped ed25519 key. The hash and signature travel with it, so anyone including your auditor can verify integrity offline.

What happens when evidence goes stale?+

Every artifact type has a freshness window. When one ages past it, the library flags it and auto-queues a re-pull from the source so you see staleness before an auditor does, and most gaps close themselves.

Can I export everything if we leave?+

Yes the full library exports as a structured archive you own: artifacts, hashes, signatures, version history, and control mappings. No lock-in, and the evidence stays verifiable outside Uproot.

Do you store the actual sensitive data?+

We store the minimum needed to prove the control: configuration state, event metadata, and document references. Where an artifact would contain secrets or PII, we capture the assertion (e.g. "encryption enabled, key rotated 14d ago") rather than the value.

How far back does version history go?+

Storage is write-once with full version history, retained for your framework's required period typically 7 years, configurable. New state becomes a new version; nothing is overwritten before its retention clock expires.

Stop being the screenshot department.

Connect a source and watch the library fill itself signed, hashed, and timestamped within minutes of the first sync.

Start free trialBook a demo

No upload forms, ever

Evidence is pulled, not submitted.

Verifiable outside Uproot

Hashes and signatures your auditor can check independently.

Yours to export

Full archive on demand artifacts, history, and mappings.

Mapped to every framework

One artifact backs every criterion that references it.