How ProofLayer works
Audit evidence, collected every day and provable to the byte.
ProofLayer reads your cloud, SaaS, devices, HR and ticketing read-only, checks them against versioned rules, hash-chains every result, and files audit-ready evidence in the GRC you already run. It is not another GRC platform to migrate to — it is the evidence layer the ones you have are missing.
Why ProofLayer
Six things no bundled suite gives you.
Vanta, Drata, Sprinto and Scrut bundle evidence automation with their own GRC platform — buy theirs, or nothing. ProofLayer unbundles the part that is actually hard.
Feeds the GRC you already run
CISO Assistant, ServiceNow, Archer, Eramba, or a spreadsheet and a consultant — ProofLayer pushes audit-ready evidence into it. No migration, no second system of record for your compliance team to learn.
A cryptographic evidence chain
Every result is a hash-chained manifest recording what was collected, from where, by which collector and rule version, and when. Auditors verify the chain offline with a standalone script — no ProofLayer software, nothing to trust but the maths.
Indian regulators, built in
CERT-In, DPDPA, RBI, SEBI CSCRF and IRDAI mapped alongside ISO 27001, SOC 2 and PCI DSS. Anyone can write an AWS collector; almost nobody has the RBI or SEBI evidence mapping. That content is the product.
Your data stays in India
Self-host with Docker or run hosted in India. Access is read-only; in agent mode the collector runs inside your account and we hold no key into your cloud. Residency rules prove workloads and logs stay in Indian regions.
Evidence people forget exists
Not just cloud config: device/MDM posture, code and dependency scanning, HR evidence (background checks, security training, offboarding) and change-management from Jira. The people-and-process controls that are 40% of an audit.
AI that respects your data residency
Optional AI drafts auditor narratives, maps requirements to rules, answers plain-language questions and suggests fixes — always grounded in your own evidence, cited, and human-reviewed. It never invents evidence. Bring your own in-region model (Azure OpenAI, Claude, a self-hosted model or a gateway); your key is sealed per tenant and inference stays in your region. Off unless you turn it on.
Priced for who the suites ignore
Bundled US suites are priced and mapped for US frameworks. We serve the teams they skip: Indian BFSI, fintech and SaaS, enterprises on workflow-rich but evidence-poor GRC, and open-source GRC users.
The pipeline
From your account to a signed, verifiable result.
Seven steps, the same for every provider and every framework. Read-only in, an auditor-ready artefact out.
Connect, read-only
Add a connection and grant least-privilege read access — or run the in-account agent so no credential leaves your environment.
Collect on a schedule
Collectors fetch the facts (IAM, storage, devices, tickets, people…) on the cadence you set. Nothing is ever written back.
Evaluate versioned rules
Each snapshot is judged by CEL rules you can read. A finding records the exact rule version that produced it, forever.
Hash-chain the manifest
Every result becomes a SHA-256 hash-chained manifest — tamper-evident and ordered per audit period.
Map to frameworks
Versioned mappings translate one result into the requirements it satisfies across every framework at once.
Deliver the evidence
Push into CISO Assistant, raise a Jira/ServiceNow ticket for a failure, or produce a signed CSV/auditor pack.
Verify offline
The auditor re-walks the chain with a standalone verifier — no ProofLayer software required to trust the evidence.
One collector serves many frameworks: a single privileged-access listing satisfies ISO 27001 A.5.18, SOC 2 CC6.3, RBI, SEBI CSCRF and DPDPA at once. Adding a framework is mapping work, not new code — which is why the India coverage is deep and keeps growing.
How we compare
The evidence layer, not a replacement for what you run.
A quick, honest read of where ProofLayer fits against the three things teams use today. Short version: we make your existing GRC audit-ready instead of asking you to rip it out.
| Capability | ProofLayer | Bundled suites (Vanta, Drata, Sprinto, Scrut) | Enterprise GRC (ServiceNow, Archer) | Open-source GRC (CISO Assistant, Eramba) |
|---|---|---|---|---|
| Works with your existing GRC | Purpose-built to feed it | Their own GRC only | Is the GRC | Is the GRC |
| Continuous automated cloud/SaaS evidence | 15 providers, versioned rules | Core strength | Integrations, often manual | Evidence is uploaded by hand |
| Non-IT evidence (HR, change/ticketing) | BambooHR, Jira, offboarding | Some HR integrations | Workflow, little evidence | Manual |
| India frameworks (CERT-In, DPDPA, RBI, SEBI, IRDAI) | Mapped and shipping | US-framework focus | Build it yourself | Import a library |
| Data residency: self-host / India / your account | Docker self-host or India-hosted | US-hosted SaaS | Enterprise deployment | Self-host |
| Cryptographic evidence chain + offline verifier | Hash-chained, verify with no vendor software | Trust the dashboard | Trust the dashboard | Not built in |
| In-account agent (vendor holds no keys) | Agent mode, outbound-only | They hold access | Deployment-dependent | You host everything |
| Fit for spreadsheet / consultant / OSS-GRC teams | The target customer | Sells the whole suite | Enterprise scale/price | Free, but evidence is manual |
| Grounded AI — in-region / BYOK, cited | Your model, cited to evidence | AI on their cloud | Add-on, if any | None |
Comparison reflects the typical shape of each category, not a feature-by-feature audit of any one vendor; capabilities change. ProofLayer is complementary to the last two — it feeds evidence into them.
What we prove
15 providers · 103 versioned rules · 8 frameworks.
Every rule is content you can read, versioned so a finding always points at the exact text that judged it. Grouped by what they evidence:
Cloud posture
AWS, Azure, Google Cloud and Kubernetes: IAM and MFA, encryption, public exposure, logging and retention, threat detection, backups and India data-residency.
Identity & access
Microsoft Entra ID, Okta and Google Workspace: MFA everywhere, least privilege, dormant accounts, and prompt deprovisioning of people who left.
Devices / MDM
Intune, Jamf Pro and ManageEngine: disk encryption, compliance, patch currency, passcodes, jailbreak checks and Microsoft Defender health.
Code & vulnerabilities
GitHub and Snyk: branch protection, required reviews, 2FA, no force-push, and no unmanaged critical or high vulnerabilities.
People & process
BambooHR: background checks, security-awareness training currency, policy acknowledgment and completed offboarding — with only hashed identifiers on the manifest.
Change management
Jira: changes approved before deploy and incidents resolved within SLA — the process evidence around your code.
Host & endpoint hardening
Wazuh: each server and endpoint’s Security Configuration Assessment (CIS/hardening) score, file-integrity monitoring and detected vulnerabilities — the host-level evidence cloud posture cannot reach. Host names are hashed on the manifest.
Grounded AI (optional)
Auditor narratives, coverage & gap analysis, a mapping co-author, plain-language search over findings, and grounded remediation — all cited to your own evidence, human-reviewed, and run on your own in-region model (BYOK). Off by default; it explains and drafts, it never authors audits or invents evidence.
Configure in ProofLayer
A connection is live in minutes.
Everything that differs between organisations is a setting in the app — never a config file we touch for you.
Add a connection
Pick the provider and name the account. ProofLayer generates the setup card with exactly what to grant.
Paste the read-only credential
A role ARN, an app registration, a service-account key or an API token — stored write-only and sealed at rest. Or choose agent mode and skip this.
Test the connection
One click verifies access from the control plane and reports a clear reason if anything is off — never a stack trace.
Set the schedule
Choose the scan cadence. Every run appends to the evidence chain for that account and rule.
Choose a framework mapping
Point the connection at ISO 27001, SOC 2, PCI DSS, CERT-In, DPDPA, RBI, SEBI or IRDAI — or all at once.
Deliver the evidence
Enable a push into CISO Assistant, a Jira/ServiceNow ticket on failure, or a scheduled auditor pack.
Grant access from your side
Read-only, least-privilege, and revocable in one click.
You create the access in your own console and paste a credential we store sealed — or run our agent in your account so no credential ever leaves it. What each provider needs:
A read-only IAM role ProofLayer assumes with an external ID (SecurityAudit / ViewOnly). We mint short-lived STS credentials — no long-lived keys.
An app registration with Reader / Security Reader (Azure) or the read-only Graph permissions (Entra/Intune). A write-only client secret, or ProofLayer’s multi-tenant app via admin consent.
A service account with Viewer + Security Reviewer (GCP), or domain-wide delegation with read-only Admin SDK scopes (Workspace). Key uploaded write-only.
Install ProofLayer’s read-only GitHub App on the org, or a fine-grained read-only PAT.
A read-only administrator API token (SSWS).
A read-only API Role client (Jamf) or a read-only API token for the device inventory (ManageEngine).
A read-only service-account or personal API token scoped to the org.
A read-only API key; ProofLayer keeps only status booleans and a hashed person reference — never names.
An account email plus a read-only API token with browse access to the change/incident projects.
ProofLayer never writes to your systems. In hosted mode credentials are sealed with a per-tenant key and exchanged for short-lived tokens; in agent mode the collector runs inside your account on ambient credentials and posts evidence outbound-only — we hold no key into your cloud.
Documentation
The full reference.
Every feature, every provider's setup and least-privilege permissions, the evidence-manifest format, and how an auditor verifies a bundle offline.
Integrations
Every provider we support — what each proves, how to configure it and the access to grant.
Browse integrations →Setup
Create a connection, test it, schedule scans and choose a framework mapping.
Read setup →Permissions
The read-only, least-privilege access each provider needs, plus agent mode.
Read permissions →Start a pilot
Connect one account against your next audit and see real, verifiable evidence.
Sign in →Questions
Straight answers.
How is ProofLayer different from Vanta, Drata, Sprinto or Scrut?
Those bundle evidence automation with their own GRC platform — you adopt the whole suite. ProofLayer is only the evidence layer and feeds the GRC you already run (CISO Assistant, ServiceNow, Archer, Eramba or spreadsheets). It also ships Indian frameworks (CERT-In, DPDPA, RBI, SEBI, IRDAI), keeps data in India, and hash-chains evidence so an auditor can verify it offline.
Do I have to replace my current GRC tool?
No. That is the entire point. ProofLayer produces audit-ready evidence and pushes it into whatever you use. Your compliance team keeps their tool; your security team gets automated, trustworthy evidence.
Which frameworks are covered?
ISO/IEC 27001:2022, SOC 2 (TSC 2017), PCI DSS 4.0.1, CERT-In Directions 2022, the DPDP Act 2023, the RBI Master Direction on IT Governance 2023, the SEBI CSCRF 2024 and the IRDAI Cyber Security Guidelines 2023. Mappings other than ISO 27001 are marked draft until a compliance professional has reviewed them for your use.
What access does ProofLayer need, and is it safe?
Read-only, least-privilege access per provider. In hosted mode the credential is sealed with a per-tenant key and exchanged for short-lived tokens; in in-account agent mode the collector runs inside your environment on ambient credentials and posts evidence outbound-only, so ProofLayer never holds a key into your cloud. Nothing is ever written to your systems.
Does my data stay in India?
Yes. Self-host with Docker or run hosted in India. Residency rules additionally prove that your cloud workloads, storage and logs stay in Indian regions, which CERT-In, RBI and DPDPA expect.
How does an auditor trust the evidence?
Every result is a hash-chained manifest. The evidence bundle ships a standalone verifier that re-checks file integrity and re-walks the chain with only the Python standard library — the auditor confirms nothing was altered without running or trusting any ProofLayer software.
How long does setup take?
A single connection is live in minutes: add it, grant read-only access (or run the agent), test, schedule, and pick a framework. Most teams start with one account against their next audit.
Do you use AI — and is my data safe?
AI is optional and off until you turn it on. When enabled it drafts auditor narratives, maps requirements to rules, answers plain-language questions over your findings and suggests fixes — always grounded in your own evidence, cited back to the manifests, and human-reviewed. It never fabricates evidence and never authors your audit. You bring your own model (Azure OpenAI, Claude, a self-hosted model, or a gateway); your key is sealed per organisation and inference stays in the region you choose, so evidence never leaves it.
Start
Bring the evidence. Keep your GRC.
Connect one account, point it at your next audit, and watch the manifests chain.