One command
hexr audit$ hexr audit --framework soc2 --tenant globex-azure --period 24h → globex-azure-soc2-2026-09-19.pdf 17,547 evidence rows · chain intact · 12,830 signatures valid · 0 invalid every page carries the row ids it was built from
Control map — what the rows on the Evidence page satisfy
hexr audit --framework soc2 | hipaa | iso42001| Framework | Control | Evidence | Rows (24h) |
|---|---|---|---|
| SOC 2 | CC6.1 | Logical access — every cloud credential exchange, allowed or refused, by process identity | 3,685 |
| SOC 2 | CC7.2 | Monitoring — identity-plane health and evidence signing, reported every 60 s | 1,440 |
| ISO 42001 | A.6.2.6 | AI system operation and monitoring — inventory of agent processes, including the unregistered one | 3 |
| NYC LL144 | §20-871 | Automated employment decision tools — which screening tools run, and which has no audit | 3 |
It is not a summary you wrote. Every page is checkable against the original signed record, and the auditor can run
GET /v1/evidence/verify themselves.A regulator, not just SOC 2
New York City Local Law 144 requires an annual independent bias audit of any automated employment decision tool, and every day an unaudited tool is used is a separate violation. The audit firms answer is this model fair? The question before it — which tools are we running, and which has nobody audited? — is an inventory question, and the Agents page answers it: three screening processes, one of them never registered.