The dossier where security leads generate quarterly license & dependency
evidence packs — signed and datestamped, ready for SOC2, GDPR, and vendor
checks. One tenant, an auditable trail, no spreadsheets.
Doc seq: signed artifacts per period
Free trial · 2 packs · no card. Paid from $297/quarter (~$99/mo).
REC-2026-Q1Audit trail & contractssha256:… · awaiting period endPending
Signed & dated · hmac-sha256
A. Quorum
Who it's for
CTOs and Security Leads at software companies (10–50 engineers)
managing SOC2, GDPR, and license compliance.
You're tired of exporting license tables from Jira, Splunk, and the AWS console, manually
comparing them against contracts, and filing evidence into binders by hand. You want signed,
timestamped PDFs an auditor accepts without a second request.
B
Why it works
Automated quarterly evidence packs — one signed, datestamped artifact per quarter: license breakdown, dependency inventory, audit trail (SOC2-ready)
Dependency health scores — per-repo and per-library risk with recommended remediation
Invite-only workspace — share evidence with auditors via time-limited access links
Signed, timestamped artifacts — HMAC-SHA256 signed digests over declared manifests; no transitive or manufactured SBOM claims
C - Proc
How it works
1 · Create your workspace (free trial) — you get an owner key.
2 · Connect repos — add GitHub repos to sync dependencies and licenses.
3 · Generate evidence pack — pick the period, include licenses, dependencies, contracts.