Evidence cards
The core review artifact for procurement, security, and legal.
Every vendor package becomes an evidence card — documents received, missing items, risk lane, owners, and recommended decision. Every AI conclusion links to source documents.
| Evidence Card Field | Content |
|---|---|
| Vendor name | Legal entity and product name |
| Vendor category | SaaS · infrastructure · AI · financial · critical |
| Data classification | PII, PHI, financial, confidential, public |
| Documents received | SOC 2, ISO, DPA, pen test, insurance, questionnaires |
| Missing evidence | Gaps flagged before approval |
| Questionnaire status | SIG / CAIQ / custom responses reviewed |
| Risk lane | Low-risk SaaS through critical infrastructure |
| Recommended decision | Approve · conditional · reject · hold |
| Owner | Procurement, security, legal, or GRC reviewer |
| Audit trail | Upload, extraction, review, and approval events |
Upload real vendor packages and generate evidence cards.
- Upload vendor docs
- → Extract fields with AI
- → Flag missing evidence
- → Route for review
- → Export audit-ready cards