continuous assurance

Audit evidence that
verifies itself.

Every change on the platform already passes through a machine-legible chokepoint — a hermetic build, a merge through the gate, a federated token, a signed deploy. fastverk turns that into content-addressed audit evidence as a byproduct of the SDLC. Test the whole population, not a sample. Regenerate the audit package on demand — and verify it by hash.

evidence ledger live
hermetic build CC8.1 blake3:9f2c…e401
merge gate CC8.1 blake3:3ad8…7c12
token broker CC6.1 blake3:be71…09aa
argocd deploy CC7.1 blake3:c40e…33bd
human approval CC5.2 blake3:71fa…8e6d
access control CC6.1 NO EVIDENCE
audit package · SOC 2 Type II manifest blake3:ee41…9c02
reproducible ✓
weeks → a query
audit prep
point-in-time, on demand
sample → population
controls testing
100%, not 25 of N
annual → continuous
assurance
the period is the evidence
verify by hash
every record
reproducible, tamper-evident
the auditor's workflow, collapsed

The parts that take weeks — gone.

Evidence-first assurance doesn't speed up the old audit. It removes the manual work the old audit was built around: the evidence request list, the sample, the once-a-year snapshot.

01 · the PBC list dies

No more "provided by client."

The evidence request list is the auditor's — and the client's — least favorite artifact: weeks of screenshots, exports, and chasing owners for proof a control operated. fastverk's evidence already exists — structured, content-addressed, and time-stamped the moment the platform did something auditable. The request list becomes a query.

02 · testing

Test the population, not a sample.

Sampling exists because collecting evidence for every item by hand is infeasible. When every change emits evidence automatically, that constraint is gone — you test 100% of the population. A stronger opinion, not a bigger sample.

traditional audit 25 of 160 sampled

A sample is pulled and tested; the rest of the population is inferred. Coverage you extrapolate — and defend.

fastverk · the population 160 of 160 attested

Every change already emits evidence, so you test 100% of the population — not a sample of it. Nothing inferred.

03 · continuity

Point-in-time becomes continuous.

A Type II report attests that controls operated over a period; the stretch between audits is covered by a bridge letter — a promise nothing changed. Continuous, content-addressed evidence attests every change across the whole period. It's the continuous-auditing substrate the profession has wanted for a decade.

point-in-timeannual audit
unobserved period — covered by a bridge letter
SOC 2 Type II
next audit
continuousfastverk
every change attested, continuously — the period is the evidence
evidence-first, by construction

Evidence, as a byproduct of the SDLC.

Collectors read the control plane's own state — they don't "integrate with" a heterogeneous, human-driven pipeline. Each machine-legible seam a change flows through emits an immutable record, mapped to the control it satisfies.

01 · chokepoints
Every change flows through machine-legible seams
  • hermetic RBE build
  • merge through the gate
  • ArgoCD deploy
  • federated access token
  • human approval
02 · collect
Collectors read the platform's own state

Each seam emits a structured EvidenceRecord — no screenshots, no agent bolted onto someone else's SDLC. A missing source degrades to NO EVIDENCE, never a fabricated green.

03 · seal
Content-addressed, write-once ledger
blake39f2c…e401
storeS3 Object-Lock · KMS
first writewins · immutable
04 · attest
Evaluator → reproducible audit package
SOC 2 Type II · signed
manifest blake3:ee41…9c02
trust, then transparency

Evidence an auditor can verify — without collecting it.

Every record is content-addressed. Regenerate the audit package over the same period and it yields the same digest; change one byte of evidence and the digest moves, flipping the control to an exception. Try it:

EvidenceRecord content-addressed · WORM
sourcehermetic RBE build · BUILD
controlCC8.1 — authorized, tracked change
captured2026-06-30T14:22:08Z
payloadplugin-compliance@a1b3f9 → sha256:9f2c…e401
digest sha256:9f2c…e401 verified ✓

Digest computed live in your browser to demonstrate the property — reproducible (regenerate the same evidence and the digest is identical) and tamper-evident (change one byte and it moves, flipping the control to an exception). It's how an auditor verifies evidence they didn't collect themselves. The platform uses BLAKE3.

frameworks

SOC 2 today. The evidence remaps.

The control catalog is data and the evidence is framework-agnostic — so more frameworks are a remap, not a re-collection.

activeSOC 2 (2017)17 controls · Type I & II
mappingISO 27001Annex A remap
plannedHIPAASecurity Rule
plannedPCI DSSv4.0

One evidence base, many attestations — the same reason SOC for Cybersecurity and SOC 2 can share the same underlying controls.

the economics of assurance

Fewer hours per engagement. A higher-confidence opinion.

For the firm

Evidence collection and sampling are where audit hours — and margin — go. Automating them means more engagements per practitioner, or the same engagement at a higher-confidence, population-level opinion.

For the client

Audit prep collapses from a quarter of screenshots to a query. Readiness is computed continuously, so there's no scramble before fieldwork and no surprise exceptions.

For the profession

Content-addressed, reproducible evidence changes the trust model: an auditor verifies evidence by hash instead of taking a collected artifact on faith. Independence, made mechanical.

diligence-ready

What's built today — and what's next.

Straight about maturity, because a partner will ask. The contracts and catalog exist; the collection and portal are the build ahead.

Built today
  • The 17-control SOC 2-2017 catalog, as data
  • The evidence contracts (proto) + control evaluator model
  • Content-addressed, write-once store design (Object-Lock + KMS)
  • The platform underneath: 14 live plugins, hermetic RBE, a CRD control plane
the moat

Not agents bolted onto your SDLC. The SDLC itself.

Legacy compliance tools read a heterogeneous pipeline through read-only integrations and still leave you collecting by hand. fastverk's evidence is a byproduct of a platform that is the pipeline — hermetic builds, a merge gate, content-addressed SCM, federated tokens. That's why the evidence is complete, and why it's hard to copy.

Bring continuous assurance to your clients.

Evidence as a byproduct, tested across the whole population, verifiable by hash. Let's talk about what a design-partner or alliance looks like.