Auditor Portal

Auditor access is by invitation

Access to an organization’s audit-preparation portal is granted through an invitation link issued by that organization — there is no signup and no account to create.

How it works

  • The organization you are auditing issues you a private link of the form /auditor/<token>. Opening that link is the only way in.
  • The link is scoped to the frameworks the organization chose to share, is strictly read-only, and always expires. The organization can revoke it at any time.
  • If your link no longer works, contact the organization that invited you and ask for a new one — expired or revoked links cannot be reactivated.

This portal shares internal readiness information for audit preparation. It is an internal readiness indicator, not a certification, attestation, or legal advice — only an external auditor or certification body can certify. The results are the organization's own and have not been independently tested. Where a result rests on an AI-drafted attestation that a person reviewed and accepted, it is an assertion about how the control operates rather than a machine-observed measurement: the split is stated with the framework results, control rows resting only on such an attestation are labelled “Met (attested)”, and the attestation narratives themselves are listed separately from collected artifacts.