Skip to main content

Evidence Management

How Nexxis collects, stores, organises, and presents compliance evidence for audits.

4 min readUpdated 2026-02-01
evidencedocumentsstorageaudit

Overview

Evidence is the foundation of any compliance programme. Nexxis manages two types of evidence:

  1. Automated evidence — collected directly from your integrations (cloud APIs, logs, configurations)
  2. Manual evidence — documents and screenshots you upload (policies, training records, contracts)

Automated Evidence

Once integrations are connected, Nexxis automatically collects evidence on a scheduled basis (hourly by default). Examples:

ControlAutomated Evidence
MFA enforcedIAM configuration export from cloud/IdP
Encryption at restStorage bucket encryption settings
Logging enabledCloudTrail/Cloud Logging configuration
Access reviews performedIAM role last-used timestamps
Automated evidence is time-stamped and stored with a full audit trail.

Manual Evidence

For controls that can't be auto-collected, you can upload:

  • Policy documents (PDF, Word, Google Docs link)
  • Screenshots (PNG, JPG)
  • Spreadsheets (CSV, Excel)
  • Any file up to 50 MB

Uploading Manual Evidence

  1. Open a control → click Add Evidence
  2. Drag and drop your file or paste a link
  3. Add a description and the date the evidence was collected
  4. Click Save

Evidence Retention

Evidence is retained for 7 years by default to support multi-year audit trails. You can adjust retention in Settings → Organisation → Data Retention.


Evidence Chain of Custody

Every evidence item has a full audit trail:

  • Who collected it (system or user)
  • When it was collected
  • What version it supersedes (if updated)
This chain of custody is included in the auditor export package.


Expiring Evidence

Some evidence (like screenshots) becomes stale. Nexxis lets you set an expiry date on manual evidence items. You'll be notified 2 weeks before evidence expires.