Evidence is the proof that your controls are implemented and operating effectively. LowerPlane provides both automated and manual evidence collection, with multi-framework tagging so a single piece of evidence can satisfy requirements across all your enabled frameworks.

Automated vs Manual Evidence

Automated evidence is collected by LowerPlane from your connected integrations without manual intervention. This is the fastest way to build your evidence library and maintain continuous compliance.How it works:
  1. You connect an integration (AWS, Okta, GitHub, etc.)
  2. LowerPlane syncs data from the integration on a scheduled basis
  3. Collected data is processed, categorized, and mapped to relevant controls
  4. Evidence artifacts are stored securely and linked to controls across all applicable frameworks
  5. Your compliance dashboard updates automatically
Examples of automated evidence:
  • AWS encryption-at-rest configuration from AWS Config
  • MFA enrollment status from Okta
  • Branch protection rules from GitHub
  • User access lists from Google Workspace
  • Vulnerability scan results from Snyk
Automated evidence collection can cover 30-50% of your total compliance requirements. Connect your integrations early to maximize this benefit.

Evidence Types

LowerPlane supports a wide range of evidence formats:
TypeDescriptionExamples
ScreenshotsVisual proof of configurations or settingsCloud console settings, security configurations
DocumentsPDF, DOCX, or other document filesSigned policies, audit reports, certifications
API DataStructured data pulled from integrationsUser lists, configuration exports, scan results
LogsSystem or audit log exportsAccess logs, change management logs, incident logs
ReportsGenerated reports from tools or LowerPlaneVulnerability reports, compliance assessments
LinksURLs to external evidenceGoogle Drive documents, Confluence pages

How Automated Collection Works

The automated evidence collection pipeline follows a structured flow:
1

Integration Connection

You connect an integration by providing OAuth credentials or API keys. LowerPlane verifies the connection and saves the configuration securely.
2

Initial Sync

An initial sync job is queued to collect all available evidence from the integration. This runs as a background process and may take several minutes depending on the volume of data.
3

Data Processing

Collected data is processed by LowerPlane’s worker infrastructure. The system categorizes evidence, extracts relevant metadata, and determines which controls and frameworks it applies to.
4

Storage and Mapping

Processed evidence is stored securely (files in encrypted object storage, metadata in the database). Each artifact is mapped to relevant controls with multi-framework tags.
5

Ongoing Sync

After the initial sync, LowerPlane schedules recurring sync jobs based on the integration type. Most integrations sync daily, with critical integrations syncing more frequently.
You can view the status of all collection runs under Integrations > Sync History. Each run shows the number of artifacts collected, any errors encountered, and the controls that were updated.

Evidence Validity and Expiration

Evidence has a limited lifespan. A screenshot of a security configuration taken six months ago may not reflect the current state of your systems. LowerPlane tracks evidence validity to ensure your compliance posture remains current.

Validity Periods

  • Automated evidence - Refreshed automatically on each sync cycle. Validity is tied to the sync schedule of the integration.
  • Manual evidence - You set the validity period when uploading. Common periods are 30, 60, 90, or 365 days.
  • Policies and documents - Validity is typically tied to the policy review cycle (annually).

Expiration Notifications

When evidence is approaching expiration, LowerPlane:
  1. Displays a warning icon on the evidence item and any linked controls
  2. Sends email notifications to the evidence owner and control owners
  3. Updates the compliance dashboard to reflect the upcoming gap
  4. Surfaces the item in the Upcoming Deadlines section of the dashboard
Expired evidence causes linked controls to show degraded compliance status. Set up automated collection wherever possible to avoid evidence gaps caused by manual renewal delays.

Multi-Framework Tagging

Every evidence artifact in LowerPlane can be tagged with multiple frameworks. This is a key feature that eliminates the need to collect the same evidence multiple times for different frameworks.

How Tagging Works

When evidence is collected or uploaded:
  1. LowerPlane identifies which controls the evidence applies to
  2. Each control’s framework mappings are checked
  3. The evidence is automatically tagged with all applicable frameworks
  4. A single upload can satisfy requirements in multiple frameworks simultaneously

Managing Tags

You can view and edit framework tags on any evidence artifact:
  1. Open the evidence detail view
  2. The Frameworks section shows all tagged frameworks
  3. Click Edit Tags to add or remove framework tags manually
  4. Linked controls update automatically when tags change
When uploading manual evidence, take a moment to review the suggested framework tags. LowerPlane suggests tags based on the controls you link, but you can add additional tags if the evidence is relevant to other frameworks.

Organizing Evidence

Searching and Filtering

The evidence library supports:
  • Full-text search across evidence titles, descriptions, and tags
  • Framework filter to view evidence for a specific framework
  • Type filter to show only screenshots, documents, API data, etc.
  • Status filter to find expired, expiring soon, or current evidence
  • Control filter to see all evidence linked to a specific control

Evidence Vault

All evidence is stored in a centralized vault accessible from Compliance > Evidence. The vault provides:
  • A complete inventory of all collected and uploaded evidence
  • Download capability for audit package preparation
  • Audit trail showing when evidence was collected, by whom, and any modifications

Best Practices

Connect integrations before manually collecting evidence. Automated collection is more reliable, stays current automatically, and scales across your organization without additional effort.
For manual evidence, choose validity periods that match your actual review cycles. Setting a 365-day validity on a configuration screenshot that changes monthly creates false confidence.
Before an audit, filter for expired or soon-to-expire evidence and refresh it. An auditor will flag stale evidence even if the underlying control is still implemented.
When uploading manual evidence, provide clear titles and detailed notes. An auditor reviewing “screenshot_2024.png” will have more questions than one reviewing “AWS S3 encryption configuration - all buckets - Jan 2024.”