One command

hexr audit
$ hexr audit --framework soc2 --tenant globex-azure --period 24h
→ globex-azure-soc2-2026-09-19.pdf
   17,547 evidence rows · chain intact · 12,830 signatures valid · 0 invalid
   every page carries the row ids it was built from

Control map — what the rows on the Evidence page satisfy

hexr audit --framework soc2 | hipaa | iso42001
FrameworkControlEvidenceRows (24h)
SOC 2CC6.1Logical access — every cloud credential exchange, allowed or refused, by process identity3,685
SOC 2CC7.2Monitoring — identity-plane health and evidence signing, reported every 60 s1,440
ISO 42001A.6.2.6AI system operation and monitoring — inventory of agent processes, including the unregistered one3
NYC LL144§20-871Automated employment decision tools — which screening tools run, and which has no audit3
It is not a summary you wrote. Every page is checkable against the original signed record, and the auditor can run GET /v1/evidence/verify themselves.

A regulator, not just SOC 2

New York City Local Law 144 requires an annual independent bias audit of any automated employment decision tool, and every day an unaudited tool is used is a separate violation. The audit firms answer is this model fair? The question before it — which tools are we running, and which has nobody audited? — is an inventory question, and the Agents page answers it: three screening processes, one of them never registered.