Your client sends the auditor one structured Evidence Package: the evidence, the review decisions and a hash for every file, so the auditor can check nothing changed after export. Not a binder of screenshots.
See the Partner Network →Every exported package shares the same documented structure, whatever the framework. The format is open (Apache-2.0), so an auditor, bank or investor can check a package without a StackWeaver account, and other tools can read it too.
Join as a Founding Partner → Read the Evidence Object spec → See it in the Partner Dashboard →A single ZIP file exported from the StackWeaver platform in the StackWeaver Open Evidence Format v1.0. It contains each Evidence Object as a JSON record, the review and sign-off decisions, the evidence files themselves, and a manifest listing the SHA-256 hash of every file.
A PDF can be edited without anyone noticing. A package carries hashes and a chained decision record, so the recipient can check that nothing was changed after export. The format is documented and Apache-2.0 licensed, so anyone can read it without a StackWeaver account.
A package holds whatever evidence is in the workspace, so one package can support several frameworks (for example SOC 2 and NDPA). Control mappings inside the platform currently ship for SOC 2; mappings for CBN AML/CFT, NDPA, ISO 27001 and PCI DSS are being reviewed.
Only the people you send the file to. Packages are created by a signed-in client or partner from their own workspace. Shareable links with expiry and revocation are planned, not live yet.