Evidence Management
How Nexxis collects, stores, organises, and presents compliance evidence for audits.
4 min readUpdated 2026-02-01
evidencedocumentsstorageaudit
Overview
Evidence is the foundation of any compliance programme. Nexxis manages two types of evidence:
- Automated evidence — collected directly from your integrations (cloud APIs, logs, configurations)
- Manual evidence — documents and screenshots you upload (policies, training records, contracts)
Automated Evidence
Once integrations are connected, Nexxis automatically collects evidence on a scheduled basis (hourly by default). Examples:
| Control | Automated Evidence |
|---|---|
| MFA enforced | IAM configuration export from cloud/IdP |
| Encryption at rest | Storage bucket encryption settings |
| Logging enabled | CloudTrail/Cloud Logging configuration |
| Access reviews performed | IAM role last-used timestamps |
Manual Evidence
For controls that can't be auto-collected, you can upload:
- Policy documents (PDF, Word, Google Docs link)
- Screenshots (PNG, JPG)
- Spreadsheets (CSV, Excel)
- Any file up to 50 MB
Uploading Manual Evidence
- Open a control → click Add Evidence
- Drag and drop your file or paste a link
- Add a description and the date the evidence was collected
- Click Save
Evidence Retention
Evidence is retained for 7 years by default to support multi-year audit trails. You can adjust retention in Settings → Organisation → Data Retention.
Evidence Chain of Custody
Every evidence item has a full audit trail:
- Who collected it (system or user)
- When it was collected
- What version it supersedes (if updated)
Expiring Evidence
Some evidence (like screenshots) becomes stale. Nexxis lets you set an expiry date on manual evidence items. You'll be notified 2 weeks before evidence expires.