ð Evidence is the difference between "we did it" and "we can prove it." This tracker gives you one place per client to log what you can prove, who owns it, and when it goes stale â so the next auditor, underwriter, or prospect request isn't a fire drill. Duplicate it, point it at one client, fill the first ten rows. It supports audit-preparation workflows â it is not legal, compliance, or audit advice. Adapt it to your organization.
Evidence â [Client].If producing an item takes longer than an hour, it's a ðĄ at best. The register's job is turning ðĄs into ðĒs on a schedule â not during a request.
The auditor's five: patch timelines you can date · access reviews with sign-off · restore-test proof · an asset inventory that matches reality · an incident plan plus evidence it was tested.
The underwriter's five: MFA on admin/email/remote access · EDR coverage percentage · offline/immutable backup claims backed by proof · an EOL systems list · a prior-incident disclosure trail.
The enterprise client's five: your own vendor list (yes, yours) · a data-flow answer ("where does our data live?") · sub-processor security terms · a breach-notification commitment · a named security owner.
Same evidence serves all three audiences. That's the point of keeping one register.
ð This tracker is the by-hand version. AxiomLens is the engine: 106 controls across 8 linked tables, coverage computed instead of eyeballed, evidence tied to controls, and a board report written locally â on your machine, nothing phoning home. It supports compliance documentation and audit-prep workflows (it's a tool, not a certification). See it run (2 min): https://youtu.be/namYnNbox4k · Store: https://thesecuritygator.gumroad.com · Free weekly issue: https://thesecuritygator.com
Sibling tools: Gatorbyte #001 â the 10-missed-controls field guide · #002 â the CSF Govern tracker.