Skip to content

Evidence Management

GLACIS supports three types of evidence to demonstrate control implementation.

Evidence Types

Attestations

Automatically captured from sidecars:

  • L0/L2 attestations
  • Policy scores
  • Merkle proofs
  • Auto-mapped to relevant controls

Documents

Uploaded files:

  • PDF, DOCX, images
  • Policy documents
  • Audit reports
  • Training materials

External references:

  • Monitoring dashboards
  • Ticketing systems
  • Code repositories
  • Training platforms

Adding Evidence

  1. Navigate to the control
  2. Click Add Evidence
  3. Select type (attestation, document, link)
  4. Upload or enter details
  5. Save

Auto-Evidence

Attestations from sidecars automatically:

  1. Flow in via webhook
  2. Get validated and stored
  3. Map to applicable controls
  4. Count toward compliance score

Auto-Evidence Controls

ControlEvidence Source
A.6.2.6Request/response attestations
A.6.2.8Latency and error metrics
A.7.5Input validation scores
A.9.4Usage pattern analysis

Evidence Quality

Good evidence should be:

  • Relevant - Directly addresses the control
  • Current - Recent and up-to-date
  • Complete - Covers the full requirement
  • Verifiable - Can be independently confirmed

Next Steps