How Nexxis collects, stores, organises, and presents compliance evidence for audits.
Evidence is the foundation of any compliance programme. Nexxis manages two types of evidence:
Once integrations are connected, Nexxis automatically collects evidence on a scheduled basis (hourly by default). Examples:
| Control | Automated Evidence |
|---|---|
| MFA enforced | IAM configuration export from cloud/IdP |
| Encryption at rest | Storage bucket encryption settings |
| Logging enabled | CloudTrail/Cloud Logging configuration |
| Access reviews performed | IAM role last-used timestamps |
For controls that can't be auto-collected, you can upload:
Evidence is retained for 7 years by default to support multi-year audit trails. You can adjust retention in Settings → Organisation → Data Retention.
Every evidence item has a full audit trail:
Some evidence (like screenshots) becomes stale. Nexxis lets you set an expiry date on manual evidence items. You'll be notified 2 weeks before evidence expires.