Audit Ledger v5 - direct motion driver Krepling pattern: hero objects -> sticky chapters -> marquee -> proof sections -> FAQ
Audit workpapers, built for objective proof.

Audit Ledger

From control list to signed audit trail.

Store evidence, review workpapers, resolve RFEs, and produce a tamper-evident record for SOC 2 and ISO 27001 audits.

CONTROL CC6.1Logical access reviewcurrent v3
StatusReady
Evidence3
Open RFEs1
v3Okta Q1 access review exportclean
v2Returned for missing samplehistory
v1Initial user access screenshotsuperseded
LEDGER HEADverified
11:06rfe.comment#e199
13:48verdict.pass#1ab4
14:22control.close#e933
01

Workpapers that move.

Each control becomes a living case file: evidence versions, reviewer notes, verdicts, and current state all move together as the audit progresses.

Case file

CC6.1 - Logical access review

v3Okta exportclean
v2Missing samplehistory
v1Initial screenshotold
Review queue

18 workpapers need review.

SOC2
Controls
Evidence
Verdicts
02

RFEs without archaeology.

Requests, replies, uploads, and re-review decisions stay attached to the exact control they affect, so teams stop reconstructing audit context from email or chat.

Reviewer portal

What your audit team needs from you.

CC6.1Upload access review exportAction
A.8.15Logging evidence returnedFix
Conversation

Comments become audit evidence.

RFE
Request
Upload
Re-review
03

The ledger is always visible.

Every material action resolves into a chronological record: uploads, comments, verdicts, access, and closure become a verification receipt reviewers can trust.

Hash-chained record

Verification receipt

09:14controls.import#2a71
10:32evidence.upload#8f2d
11:06rfe.comment#e199
13:48verdict.pass#1ab4
14:22control.close#e933
#
Chronology
Integrity
Export

The verification package plus all the essentials.

Versioned evidence

Descriptions, file hashes, scan state, and origin.

Control case files

Every workpaper has a current state and complete history.

RFE portal

External reviewers answer only what is assigned to them.

Verifier export

Timeline, receipts, verdicts, and verifier notes.

Hash chain

Actions are linked into an objective audit trail.

Audit dashboard

See what is blocked, ready, returned, or closed.

Cryptographic certainty under every workpaper.

Audit Ledger keeps the workflow simple for audit teams while preserving a tamper-evident timeline beneath it: timestamped artifacts, signed actions, linked hashes, and a verification trail that can be independently reviewed.

01

Proof of chronology

Evidence collection, review notes, and conclusions are timestamped so the sequence of work is clear.

02

Proof of accountability

Material actions are tied to identities, verdicts, and control context for clean ownership.

03

Proof of integrity

Evidence changes affect the chain, making tampering visible instead of buried in file history.

0x8f2d...4e9a
09:14controls.import#2a71
10:32evidence.upload#8f2d
11:06rfe.comment#e199
13:48verdict.pass#1ab4
14:22control.close#e933

Enterprise proof without infrastructure drag.

The audit team sees workpapers, RFEs, verdicts, and exports. Underneath, the record can be backed by Hyperledger Fabric, IBM LinuxONE infrastructure, and hardware-isolated key management through the GreenHat and INBLOCK partnership.

Ledger fabricHyperledger Fabric
InfrastructureIBM LinuxONE
Key managementHardware-isolated signing
Deployment modelSaaS for assurance teams

Built for trusted audits, not technical spectacle.

The product story remains about audit work getting easier. The proof layer is there when a regulator, client, or external reviewer needs to verify how the engagement record was produced.

From subjective trust to objective proof.

The current audit process often asks reviewers to trust screenshots, spreadsheets, and chat history. Audit Ledger turns the work itself into a record that can be traced, reviewed, and packaged.

Traditional audit

-Point-in-time files that drift from the live state.
-Evidence context scattered across email, chat, folders, and ticket comments.
-Manual reconstruction when a client, regulator, or reviewer asks what happened.

Ledger-based assurance

+Live control case files with versions, decisions, and reviewer context.
+Hash-linked chronology of uploads, comments, verdicts, and closure.
+Verification package ready for third-party review at the end of the engagement.

What the verification package contains.

At close, the engagement produces more than a folder of workpapers. It produces a reviewer-ready asset with the evidence, history, receipts, and instructions needed to validate the audit trail.

Timeline summary

A high-level map of evidence requests, submissions, re-reviews, verdicts, and closure milestones.

09:14 controls.import
10:32 evidence.upload
14:22 control.close

Verification receipts

Signed bundles for material artifacts, including hashes, timestamps, state, and control references.

{"v":1,"hash":"e3b0c442...","control":"CC6.1"}

Verifier instructions

Plain-English guidance for regulators, customers, and external reviewers to validate integrity.

verify --package SOC2-Q1
chain head: #e933

Frequently Asked Questions

Does Audit Ledger replace our audit methodology?+
No. Audit Ledger is designed to sit underneath the way your audit team already works. It gives SOC 2, ISO 27001, and internal assurance teams a structured place to store workpapers, evidence, RFEs, reviewer comments, control verdicts, and exports while preserving the methodology and judgment your team applies.
How does the hash-chained log work?+
Material events create a receipt that includes the action, actor, timestamp, control reference, evidence reference, and a cryptographic hash. Each new receipt can reference the prior state, creating a chain of custody where later changes are visible instead of quietly overwriting the record.
Can external reviewers upload evidence?+
Yes. RFEs can be scoped to the exact control or workpaper that needs support. External reviewers or control owners can respond to assigned requests, upload evidence, and leave comments without digging through email threads. Those responses stay attached to the audit trail.
What do we export at the end of an audit?+
The export package can include a timeline summary, evidence index, control verdicts, RFE history, signed verification receipts, and verifier instructions. The goal is to give partners, clients, regulators, or peer reviewers enough context to understand how the engagement record was produced.
Y

This finally feels like the lane

I will write the design spec around this full-page choreography.

K

Keep developing it

Push the actual visuals/assets and section choreography another round.

Selection: none yet