How ProofLayer works

Audit evidence, collected every day and provable to the byte.

ProofLayer reads your cloud, SaaS, devices, HR and ticketing read-only, checks them against versioned rules, hash-chains every result, and files audit-ready evidence in the GRC you already run. It is not another GRC platform to migrate to — it is the evidence layer the ones you have are missing.

Why ProofLayer

Six things no bundled suite gives you.

Vanta, Drata, Sprinto and Scrut bundle evidence automation with their own GRC platform — buy theirs, or nothing. ProofLayer unbundles the part that is actually hard.

not a platform

Feeds the GRC you already run

CISO Assistant, ServiceNow, Archer, Eramba, or a spreadsheet and a consultant — ProofLayer pushes audit-ready evidence into it. No migration, no second system of record for your compliance team to learn.

tamper-evident

A cryptographic evidence chain

Every result is a hash-chained manifest recording what was collected, from where, by which collector and rule version, and when. Auditors verify the chain offline with a standalone script — no ProofLayer software, nothing to trust but the maths.

the moat

Indian regulators, built in

CERT-In, DPDPA, RBI, SEBI CSCRF and IRDAI mapped alongside ISO 27001, SOC 2 and PCI DSS. Anyone can write an AWS collector; almost nobody has the RBI or SEBI evidence mapping. That content is the product.

sovereign

Your data stays in India

Self-host with Docker or run hosted in India. Access is read-only; in agent mode the collector runs inside your account and we hold no key into your cloud. Residency rules prove workloads and logs stay in Indian regions.

beyond IT

Evidence people forget exists

Not just cloud config: device/MDM posture, code and dependency scanning, HR evidence (background checks, security training, offboarding) and change-management from Jira. The people-and-process controls that are 40% of an audit.

grounded AI

AI that respects your data residency

Optional AI drafts auditor narratives, maps requirements to rules, answers plain-language questions and suggests fixes — always grounded in your own evidence, cited, and human-reviewed. It never invents evidence. Bring your own in-region model (Azure OpenAI, Claude, a self-hosted model or a gateway); your key is sealed per tenant and inference stays in your region. Off unless you turn it on.

the right segment

Priced for who the suites ignore

Bundled US suites are priced and mapped for US frameworks. We serve the teams they skip: Indian BFSI, fintech and SaaS, enterprises on workflow-rich but evidence-poor GRC, and open-source GRC users.

The pipeline

From your account to a signed, verifiable result.

Seven steps, the same for every provider and every framework. Read-only in, an auditor-ready artefact out.

1 · connect

Connect, read-only

Add a connection and grant least-privilege read access — or run the in-account agent so no credential leaves your environment.

2 · collect

Collect on a schedule

Collectors fetch the facts (IAM, storage, devices, tickets, people…) on the cadence you set. Nothing is ever written back.

3 · evaluate

Evaluate versioned rules

Each snapshot is judged by CEL rules you can read. A finding records the exact rule version that produced it, forever.

4 · chain

Hash-chain the manifest

Every result becomes a SHA-256 hash-chained manifest — tamper-evident and ordered per audit period.

5 · map

Map to frameworks

Versioned mappings translate one result into the requirements it satisfies across every framework at once.

6 · deliver

Deliver the evidence

Push into CISO Assistant, raise a Jira/ServiceNow ticket for a failure, or produce a signed CSV/auditor pack.

7 · verify

Verify offline

The auditor re-walks the chain with a standalone verifier — no ProofLayer software required to trust the evidence.

One collector serves many frameworks: a single privileged-access listing satisfies ISO 27001 A.5.18, SOC 2 CC6.3, RBI, SEBI CSCRF and DPDPA at once. Adding a framework is mapping work, not new code — which is why the India coverage is deep and keeps growing.

How we compare

The evidence layer, not a replacement for what you run.

A quick, honest read of where ProofLayer fits against the three things teams use today. Short version: we make your existing GRC audit-ready instead of asking you to rip it out.

CapabilityProofLayerBundled suites (Vanta, Drata, Sprinto, Scrut)Enterprise GRC (ServiceNow, Archer)Open-source GRC (CISO Assistant, Eramba)
Works with your existing GRCPurpose-built to feed itTheir own GRC onlyIs the GRCIs the GRC
Continuous automated cloud/SaaS evidence15 providers, versioned rulesCore strengthIntegrations, often manualEvidence is uploaded by hand
Non-IT evidence (HR, change/ticketing)BambooHR, Jira, offboardingSome HR integrationsWorkflow, little evidenceManual
India frameworks (CERT-In, DPDPA, RBI, SEBI, IRDAI)Mapped and shippingUS-framework focusBuild it yourselfImport a library
Data residency: self-host / India / your accountDocker self-host or India-hostedUS-hosted SaaSEnterprise deploymentSelf-host
Cryptographic evidence chain + offline verifierHash-chained, verify with no vendor softwareTrust the dashboardTrust the dashboardNot built in
In-account agent (vendor holds no keys)Agent mode, outbound-onlyThey hold accessDeployment-dependentYou host everything
Fit for spreadsheet / consultant / OSS-GRC teamsThe target customerSells the whole suiteEnterprise scale/priceFree, but evidence is manual
Grounded AI — in-region / BYOK, citedYour model, cited to evidenceAI on their cloudAdd-on, if anyNone

Comparison reflects the typical shape of each category, not a feature-by-feature audit of any one vendor; capabilities change. ProofLayer is complementary to the last two — it feeds evidence into them.

What we prove

15 providers · 103 versioned rules · 8 frameworks.

Every rule is content you can read, versioned so a finding always points at the exact text that judged it. Grouped by what they evidence:

cloud

Cloud posture

AWS, Azure, Google Cloud and Kubernetes: IAM and MFA, encryption, public exposure, logging and retention, threat detection, backups and India data-residency.

identity

Identity & access

Microsoft Entra ID, Okta and Google Workspace: MFA everywhere, least privilege, dormant accounts, and prompt deprovisioning of people who left.

devices

Devices / MDM

Intune, Jamf Pro and ManageEngine: disk encryption, compliance, patch currency, passcodes, jailbreak checks and Microsoft Defender health.

code

Code & vulnerabilities

GitHub and Snyk: branch protection, required reviews, 2FA, no force-push, and no unmanaged critical or high vulnerabilities.

people

People & process

BambooHR: background checks, security-awareness training currency, policy acknowledgment and completed offboarding — with only hashed identifiers on the manifest.

change

Change management

Jira: changes approved before deploy and incidents resolved within SLA — the process evidence around your code.

endpoints

Host & endpoint hardening

Wazuh: each server and endpoint’s Security Configuration Assessment (CIS/hardening) score, file-integrity monitoring and detected vulnerabilities — the host-level evidence cloud posture cannot reach. Host names are hashed on the manifest.

grounded AI

Grounded AI (optional)

Auditor narratives, coverage & gap analysis, a mapping co-author, plain-language search over findings, and grounded remediation — all cited to your own evidence, human-reviewed, and run on your own in-region model (BYOK). Off by default; it explains and drafts, it never authors audits or invents evidence.

Configure in ProofLayer

A connection is live in minutes.

Everything that differs between organisations is a setting in the app — never a config file we touch for you.

1

Add a connection

Pick the provider and name the account. ProofLayer generates the setup card with exactly what to grant.

2

Paste the read-only credential

A role ARN, an app registration, a service-account key or an API token — stored write-only and sealed at rest. Or choose agent mode and skip this.

3

Test the connection

One click verifies access from the control plane and reports a clear reason if anything is off — never a stack trace.

4

Set the schedule

Choose the scan cadence. Every run appends to the evidence chain for that account and rule.

5

Choose a framework mapping

Point the connection at ISO 27001, SOC 2, PCI DSS, CERT-In, DPDPA, RBI, SEBI or IRDAI — or all at once.

6

Deliver the evidence

Enable a push into CISO Assistant, a Jira/ServiceNow ticket on failure, or a scheduled auditor pack.

Grant access from your side

Read-only, least-privilege, and revocable in one click.

You create the access in your own console and paste a credential we store sealed — or run our agent in your account so no credential ever leaves it. What each provider needs:

AWS

A read-only IAM role ProofLayer assumes with an external ID (SecurityAudit / ViewOnly). We mint short-lived STS credentials — no long-lived keys.

Azure / Entra ID / Intune

An app registration with Reader / Security Reader (Azure) or the read-only Graph permissions (Entra/Intune). A write-only client secret, or ProofLayer’s multi-tenant app via admin consent.

Google Cloud / Workspace

A service account with Viewer + Security Reviewer (GCP), or domain-wide delegation with read-only Admin SDK scopes (Workspace). Key uploaded write-only.

GitHub

Install ProofLayer’s read-only GitHub App on the org, or a fine-grained read-only PAT.

Okta

A read-only administrator API token (SSWS).

Jamf / ManageEngine

A read-only API Role client (Jamf) or a read-only API token for the device inventory (ManageEngine).

Snyk

A read-only service-account or personal API token scoped to the org.

BambooHR

A read-only API key; ProofLayer keeps only status booleans and a hashed person reference — never names.

Jira

An account email plus a read-only API token with browse access to the change/incident projects.

ProofLayer never writes to your systems. In hosted mode credentials are sealed with a per-tenant key and exchanged for short-lived tokens; in agent mode the collector runs inside your account on ambient credentials and posts evidence outbound-only — we hold no key into your cloud.

Questions

Straight answers.

How is ProofLayer different from Vanta, Drata, Sprinto or Scrut?

Those bundle evidence automation with their own GRC platform — you adopt the whole suite. ProofLayer is only the evidence layer and feeds the GRC you already run (CISO Assistant, ServiceNow, Archer, Eramba or spreadsheets). It also ships Indian frameworks (CERT-In, DPDPA, RBI, SEBI, IRDAI), keeps data in India, and hash-chains evidence so an auditor can verify it offline.

Do I have to replace my current GRC tool?

No. That is the entire point. ProofLayer produces audit-ready evidence and pushes it into whatever you use. Your compliance team keeps their tool; your security team gets automated, trustworthy evidence.

Which frameworks are covered?

ISO/IEC 27001:2022, SOC 2 (TSC 2017), PCI DSS 4.0.1, CERT-In Directions 2022, the DPDP Act 2023, the RBI Master Direction on IT Governance 2023, the SEBI CSCRF 2024 and the IRDAI Cyber Security Guidelines 2023. Mappings other than ISO 27001 are marked draft until a compliance professional has reviewed them for your use.

What access does ProofLayer need, and is it safe?

Read-only, least-privilege access per provider. In hosted mode the credential is sealed with a per-tenant key and exchanged for short-lived tokens; in in-account agent mode the collector runs inside your environment on ambient credentials and posts evidence outbound-only, so ProofLayer never holds a key into your cloud. Nothing is ever written to your systems.

Does my data stay in India?

Yes. Self-host with Docker or run hosted in India. Residency rules additionally prove that your cloud workloads, storage and logs stay in Indian regions, which CERT-In, RBI and DPDPA expect.

How does an auditor trust the evidence?

Every result is a hash-chained manifest. The evidence bundle ships a standalone verifier that re-checks file integrity and re-walks the chain with only the Python standard library — the auditor confirms nothing was altered without running or trusting any ProofLayer software.

How long does setup take?

A single connection is live in minutes: add it, grant read-only access (or run the agent), test, schedule, and pick a framework. Most teams start with one account against their next audit.

Do you use AI — and is my data safe?

AI is optional and off until you turn it on. When enabled it drafts auditor narratives, maps requirements to rules, answers plain-language questions over your findings and suggests fixes — always grounded in your own evidence, cited back to the manifests, and human-reviewed. It never fabricates evidence and never authors your audit. You bring your own model (Azure OpenAI, Claude, a self-hosted model, or a gateway); your key is sealed per organisation and inference stays in the region you choose, so evidence never leaves it.

Start

Bring the evidence. Keep your GRC.

Connect one account, point it at your next audit, and watch the manifests chain.