Skip to content
Private evidence vault

Keep your security readiness proof in one place.

Organize policies, screenshots, exports, training records, vendor lists, and notes by the controls they support.

The vault surface

Every file knows which control it supports.

Each row in the vault carries the control id, the upload date, and a freshness badge. When a carrier or broker asks for the MFA screenshot or the latest backup test, you do not go hunting in email.

Index8 evidence vault listing twelve files by control with freshness status badges and pillar tags
The workflow

Four steps from scattered to organized.

How the vault works
Four steps
  1. 01Upload documentation
    PDFs, screenshots, exports, signed policies
  2. 02Link to controls
    Each file maps to the control it supports
  3. 03Track freshness
    Current, due soon, or stale
  4. 04Renewal-ready
    No email hunt when a carrier asks
Renewal-ready, organized by the control the carrier cares about.
Privacy posture

Private by default, server-mediated by design.

The vault is built so that the wrong person never sees the wrong file. Posture is enforced in code, not in copy.

Private storage by default

Files live in a private bucket. No public URLs. No directory listings. No file content in your browser.

Server-mediated access

Every upload and download is gated server-side. Signed URLs are short-lived and scoped to your organization.

Organization-scoped paths

Every object key is namespaced to your organization. Cross-org access fails by construction.

Role-aware uploads

Owner and admin roles upload. Member roles view. Soft delete preserves recovery.

How evidence is handled

Organized in your workspace, labeled by status.

The vault keeps your security readiness proof organized so your team can see what is current, missing, stale, or ready for review.

Labeled by status

Every file shows current, missing, stale, or ready for review so your team can see what to focus on next.

Organized by control

Files attach to the readiness control they support, so the right artifact surfaces when the right question comes up.

Your evidence is yours

Export any file at any time. Soft delete preserves recovery if something is removed by accident.

When it matters most

Cyber insurance conversations get easier.

When renewal lands and your broker asks for the MFA screenshot, the AI usage policy, the last backup test, or the vendor list, the vault has it organized by the control the carrier cares about. No email hunt. No more guessing whether it is in the shared drive. Just the document, with the review date, ready to share.

Start here

Start your evidence vault.

Create your account and start uploading your own files. Or open the Cedar & Co. workspace to see how the vault works.

Or request Index8 Setup