Evidence Package

An Evidence Package is a curated collection of Evidence Objects, mapped to a specific set of controls and requirements (e.g., SOC 2 Type II, CBN AML review, investor due diligence), with scoped, read-only access for stakeholders, and a complete audit trail of access and review.

Explanation

Instead of exporting a static folder of PDFs or screenshots, an Evidence Package is a live, scoped view into the evidence base — tailored to exactly what a stakeholder needs and nothing more.

Evidence Packages can be time-bound (for a specific audit window), framework-bound (SOC 2, NDPA, PCI DSS), or purpose-bound (investor due diligence, enterprise security review).

Every access to the Evidence Package is logged, every review decision is timestamped and attributed, and every Evidence Object remains linked to its source.

Why it matters

It eliminates the "email with 40 attachments" problem: stakeholders get exactly the evidence they need, in a structured, auditable format.

Scoped access means you never overshare sensitive operational data with third parties.

It turns audit preparation into a verification step, since evidence is already assembled and mapped.

How StackWeaver applies it

StackWeaver lets clients create Evidence Packages for auditors, regulators, investors, and partners, with fine-grained access controls and complete audit trails.

Partners can request and receive Evidence Packages via the Partner API, without manual intervention.

Key points

Scoped, not exhaustive

Contains exactly what a stakeholder needs and nothing more.

Live, not static

Evidence remains current; no stale binders.

Auditable access

Every view and review is logged.

What this relates to