The Compliance Evidence Workspace is a free, self-service place to run a real compliance program for SOC 2, ISO 27001, or HIPAA — inside your intSignal account. It replaces the spreadsheet-and-screenshots approach with a structured program: every control in one place, evidence attached where it belongs, readiness scored live, and a one-click export your auditor can read.
It lives inside the portal as its own area alongside Billing, Support, and Services — one account, one login — and it's free to use. You do not need to be an intSignal customer.
What you get
- A fillable program — the controls for your framework, each with a status, notes, and structured fields, saved to your account. See Working the program.
- Readiness scoring & gaps — a live percentage complete and a prioritized list of what's missing. See Readiness scoring.
- An encrypted evidence vault — upload evidence per control; it's encrypted, versioned, and isolated. See Evidence vault.
- Tasks & reminders — owners, due dates, and email nudges. See Tasks & reminders.
- An exportable auditor pack — a branded PDF/ZIP of your state plus evidence. See Audit pack.
Why it's built the way it is
intSignal is targeted by attackers globally, so the workspace was built to a hostile threat model. Your evidence lives in a separately isolated system — its own service, database, storage, encryption keys, and tamper-evident audit log — with tenant isolation enforced deny-by-default. A portal or global admin has no implicit access to your evidence. The full model is in Security & isolation.
Start here
- Getting started — create your account and pick a framework.
- Choosing a framework — SOC 2 vs ISO 27001 vs HIPAA.
- Working the program — set statuses, add notes, attach evidence.
Prefer we run it for you? Our team can operate the whole program as a managed / virtual-CISO engagement. Talk to sales, or read about the two ways to get compliant.
