Skip to main content

Evidence Engine & Control Assessments

Infracast's Evidence Engine continuously generates cryptographically signed evidence artifacts for every NIST 800-53 control it can assess. Instead of assembling audit evidence manually before each review, your evidence library grows every day — automatically.

Why It Matters​

Traditional ATO evidence is collected manually:

  • Screenshots of console settings taken hours before the assessor arrives
  • Spreadsheet exports that don't match the current state of the environment
  • Unsigned PDFs that can be modified after generation with no way to detect tampering

Infracast changes this. Every control assessment is:

  • Continuous — generated on a schedule, not scrambled before audits
  • Timestamped — cryptographically bound to the exact moment of assessment
  • Signed — Ed25519 digital signature, verifiable by anyone with the public key
  • Traceable — linked to the specific findings and assets that informed the assessment

How Evidence Is Generated​

1. Control Effectiveness Assessment​

Infracast evaluates each automatable NIST 800-53 control against your current infrastructure state:

ResultMeaning
PassAll automated checks for this control pass
PartialSome checks pass, open findings exist
FailCritical checks fail — control not implemented
Not AssessedNo automated checks available (use GRC attestation)

2. Artifact Creation​

Each assessment creates a signed evidence artifact:

  • Control ID, family, and description
  • Assessment result and supporting finding IDs
  • Asset references (which resources were evaluated)
  • Timestamp, tenant ID, content hash
  • Ed25519 signature over all fields

3. Evidence Bundles​

For ATO submissions, generate a ZIP bundle:

  • Signed PDF for each control
  • Raw JSON evidence data
  • Chain-of-custody manifest (signed separately)

Evidence Library​

Access your evidence from the Evidence Library page (/evidence):

  • Filter by control family, date range, assessment result
  • Download individual artifacts or bulk export as ZIP
  • Configure daily/weekly generation schedules
  • View generation audit trail

API Reference​

# Trigger evidence generation
POST /api/v1/tenants/{tenantID}/evidence/generate
{ "control_families": ["AC", "AU", "SC"], "scope": "all" }

# List artifacts
GET /api/v1/tenants/{tenantID}/evidence?control_id=AC-2&from=2026-01-01

# Get a single artifact
GET /api/v1/tenants/{tenantID}/evidence/{evidenceId}

# Download a signed attestation-evidence artifact
GET /api/v1/tenants/{tenantID}/attestation-evidence/{evidenceId}/download

# Control effectiveness summary
GET /api/v1/tenants/{tenantID}/evidence/controls

# Delete artifact
DELETE /api/v1/tenants/{tenantID}/evidence/{evidenceId}
API paths corrected 2026-09-14

The evidence/{id}/download path does not exist. Signed artifact downloads are available at /api/v1/tenants/{tenantID}/attestation-evidence/{evidenceId}/download.

Verification​

Any party can verify an evidence artifact independently:

# CLI verification
infracast evidence verify --file evidence-AC-2-2026-04-15.pdf

✅ Signature valid
Signer: AZgardTek LLC (Infracast)
Signed at: 2026-04-15T00:00:00Z
Control: AC-2 (Account Management)
Result: PASS

Evidence Scheduling​

Configure automatic evidence generation in Settings → Authorization:

ScheduleDescription
DailyBest for FedRAMP ConMon (required monthly, but daily gives better coverage)
WeeklyFor standard compliance programs
On-demandVia API or UI button — useful before an auditor review
Event-triggeredTriggered by significant changes (new VPCs, IAM changes)

Control Coverage​

Evidence is generated for all automatable controls across:

FamilyControls AssessedExample
AC — Access ControlAC-2, AC-3, AC-6, AC-17IAM user review, MFA enforcement
AU — Audit & AccountabilityAU-2, AU-3, AU-9, AU-12CloudTrail status, log retention
CM — Configuration ManagementCM-2, CM-6, CM-7, CM-8Config drift, inventory completeness
IA — Identification & AuthIA-2, IA-5, IA-8MFA, credential rotation
SC — System & Comms ProtectionSC-7, SC-8, SC-13, SC-28Boundary protection, encryption
SI — System & Info IntegritySI-2, SI-3, SI-7Patch status, malware, integrity
CA — Assessment & AuthorizationCA-7Continuous monitoring
RA — Risk AssessmentRA-5Vulnerability scanning

Non-automatable controls are handled via POA&M and GRC questionnaire attestation.

Availability​

TierAccess
Free / ProNot available
BusinessEvidence generation (on-demand + scheduled)
EnterpriseEvidence bundles (ZIP + signed PDFs)
Enterprise Pro / GovFull ConMon integration, GRC platform sync