Kairnex Evidence

Unified SOC 2 + ISO 27001 workspace (framework switching)

Held in memory only; cleared when this page reloads or closes.
Point this UI at the deployed Kairnex API when using a hosted backend.
Ready.

Quick Start

New environment? Use this to get to a first evaluation and an auditor-shareable snapshot fast.

1
Create Org + Engagement
Use the one-click demo path or create and select both below.
2
Seed baseline content
Idempotent. Safe for demos and fast starts.
3
Evaluate + handoff package
Run evaluation, create snapshot, generate PDF report, and queue audit ZIP.

Operations & Onboarding

This is the operator view for launch readiness: onboarding progress, connector health, workflow pressure, and pilot-proof artifacts.

Select an organization to load onboarding progress, automation health, and pilot-proof artifacts.

Onboarding Checklist

Operational Alerts

Pilot Outcome Readout

Your Engagement

Workspace access required

Engagement details appear after an authorized workspace credential is accepted.

Access
Protected
No customer workspace is visible without authorization.
Organization
Not loaded
Shown from the organization attached to your credential.
Review scope
Not loaded
Defined for the selected engagement.
Schedule
Not loaded
Start and target dates appear when assigned.

Current scope

No engagement is available without workspace access.

Included handoff

Organized evidence record
Reviewed findings and open-item summary
Sealed export package when approved

Next step

Your current action appears after the workspace loads.
Commercial terms remain in your signed agreement. This workspace reflects the scope, schedule, access, and deliverables assigned to your organization.

Organization

Engagement

Runs as a background job for reliability. If it takes a while, check Jobs.

Engagement Setup

One-click setup for demos: seed control libraries and PBC requests (idempotent).


      

Imports (Connector-lite)

Upload a CSV/JSON export to create Evidence + Evidence Signals mapped to existing controls (by framework + control_code).


      

Source App Evidence

Import sanitized Kairnex evidence packages from KeyControl, AgentBoundary, ExposureOps, ShieldDesk, TechStack, or custom systems. Raw secrets, credential values, session material, and sensitive prompts are rejected.

Select an engagement to see imported source-app evidence.

      

Connectors (Evidence Sources)

Pull auditor-friendly evidence directly from common systems. Most connector pulls attach to the currently selected control and automatically record provenance + replay instructions. (Baseline pack imports attach to multiple controls.)

Select a control in Controls first.
Managed connectors

Save recurring connector definitions with encrypted secrets, run them on a schedule, and monitor whether automation is healthy enough for customer-facing use.

Inventory

Selected connector

Choose a connector type to load a starter config template.
Non-secret configuration such as targets, limits, and replay guardrails.
Stored encrypted at rest. Leave blank during updates to preserve existing secrets. Use {} to clear.

            
GitHub — Audit log
Produces JSON evidence (audit log entries) + replay info.
Google Workspace — Admin audit log
Requires start/end (Admin SDK Reports API).
Jira — Audit log
Captures change-management / admin activity evidence.
Microsoft Entra — Security posture (Graph)
Fetches Conditional Access policy metadata (starter posture).
AWS — IAM credential report (import)

Upload a credential report CSV and Kairnex Evidence will attach it to the selected control, compute a posture summary (MFA, active keys), and store replay instructions for auditors.

Generates evidence + connector signal + provenance replay steps.
HTTP JSON — Fetch (bridge connector)
SSRF-hardened; intended for pre-authenticated JSON endpoints.
Cloud export — Ingest JSON (AWS/GCP/etc.)

For providers that require external tooling (AWS CLI / gcloud), export JSON locally and ingest it here. This attaches evidence to the selected control while recording provenance + optional replay instructions.

Stored as provenance replay instructions for auditors/operators.
Baseline packs — Import ZIP (AWS / Entra / GCP)

Upload a ZIP created from a baseline export pack folder (must include manifest.json). The pack attaches evidence to multiple controls based on the manifest targets.

Optional (idempotent). Leave blank to skip seeding.

      

Controls

Import controls catalog (CSV/JSON)
Columns: framework, control_code, title, description, required_frequency_days, objective_codes

        

List

Selected

Select a control to show the live provenance story.
Raw control JSON
(none)

ISO 27001 ISMS (Clauses 4–10)

These artifacts drive the computed ISO clause controls in /evaluate. Use “Approve + Save” to attach an approval decision id (auditor-friendly).

Clause 4 — Scope

        
Clause 5 — Policy

        
Clause 6 — Risk Method + Risk Treatment Plan


          

        
Clause 7/8 — Competence + Operations


          

        
Clause 9 — Internal Audits + Management Reviews

Internal audits (9.2)

(none)

Management reviews (9.3)

(none)
Clause 10 — Corrective Actions

List

Selected

(none)

Evidence Library

Select evidence to attach to exceptions and control tests.

List

Selected

Select evidence to show provenance, replay, and scoring context.
Raw evidence / provenance JSON
(none)
Evidence Signals (integrity / relevance)

These scores are used by /evaluate (objective requirements gating and evidence confidence). Create multiple signals; the latest extracted_at wins.

List

Selected

(none)

Evidence + Attestation

Attach evidence to a control, then create an engagement attestation (drives /evaluate).


      

Evidence Requests (PBC)

Track PBC items, statuses, and attach evidence (auditor workflow).

List

Selected

(none)

Exceptions (Findings)

Create findings/exceptions and attach evidence (SOC 2 Type II realism).

List

Selected

(none)

Control Tests (Workpapers)

Create test results with Type II metadata (period, population, sampling) and evidence links.

List

Selected

(none)

SoA (Statement of Applicability)

Risk

Objective Requirements

Define objective-level evidence quality gates. When a requirement is present and not satisfied, an objective that would otherwise be PASS becomes INCONCLUSIVE.

Comma-separated evidence source types

List

Selected

(none)
Objective Graph (Prerequisites)

Define objective prerequisites (A → B). Evaluation gates objective PASS to INCONCLUSIVE when prerequisites aren’t satisfied.

List

Selected

(none)

Evaluation

Suggested workflow

Run evaluation to generate remediation actions.

Objective blockers

Run evaluation to see blocked objectives, next steps, and suggested owners.

Objectives

Select or click an objective to inspect requirement coverage, prerequisite gates, and trust signals.

Controls

Auditor Visuals (Graphs)

Visualize objective prerequisites and the merged engagement explanation graph. Click nodes to inspect details and “why” chains.

Crosswalk (SOC 2 + ISO → Canonical 10 frameworks)

This is a derived view computed from objective results (by default sources SOC2,ISO27001). It helps you reuse evidence across frameworks.

Summary

Selected

(none)
Objective prerequisite graph (DAG)

Selected node

(none)
Engagement explanation graph (merged)

Matches

Neighborhood

Selected node

(none)

Audit Pack Snapshots

Create immutable audit pack snapshots, verify hash integrity, and diff changes over time.

Runs as a background job for reliability. If it takes a while, check Jobs.

List

Output


          

Jobs (Background work)

Queue long-running exports and track status (useful for enterprise-scale audits).

List

Selected

(none)

          

Deployment (Scaling)

Scaling is controlled by your orchestrator (Docker Compose, Kubernetes, etc). These buttons copy reference Docker Compose commands for local scale testing.

Runtime readiness

Hardening checks

Enterprise posture

Key Vault, sealed export storage, SIEM export, request limits, security events, and sealed export verification.

Security events

Sealed exports

Verification

(none)
Auth disabled. Uses jobs queue + workers.
Requires KAIRNEX_ADMIN_API_KEY.

      

Security & Exports

Admin tools for auditor-grade exports: signing keys, recipient registry, export policy, and encrypted export approvals.

Org Signing Keys (seal + bundle signatures)

List

Selected

(none)
Export Recipients (RSA public keys)
Required when export policy enforces registered recipients.

List

Selected

(none)
Export Policy (per engagement)
(none)
Encrypted Export (approval flow)

Requires a sealed snapshot + recipient RSA public key.

Requests

Selected

(none)

After downloading, run: backend/.venv/bin/python tools/verify_encrypted_bundle.py --bundle ... --recipient-private-key ... --keys-bundle ...

Reports (PDF)

Generate and download a PDF report for the selected engagement.

List

Selected

(none)

Audit Logs

Read-only log of audit-relevant actions (seeds, requests, exceptions, snapshots, etc.).

List

Selected

(none)

Audit Pack (Raw)