Use case / Auditor evidence

Timestamped auditor evidence packs

One frozen HTML file for the period — invoices, chase timeline with actors, maker-checker approvals, SOX actions, and daily anchors — plus a SHA-256 digest and OpenTimestamps proof your auditor can verify without trusting docstoc.

Create timestamped pack

Where to get the file in the product

  1. Sign in → SOX reporting
  2. Open the Evidence & exports tab
  3. Pick from/to dates → Create timestamped pack
  4. Download HTML, .sha256, and .ots from the frozen list and email all three to your auditor

What is in the pack

  • Control coverage snapshot at generation time
  • Invoices touched in the period + email open/click stats
  • Chase timeline with actor attribution
  • Maker-checker approvals (maker ≠ checker)
  • SOX audit actions and daily Bitcoin hash anchors

Why OpenTimestamps (not just a PDF)

A PDF from your SaaS proves nothing if the vendor can rewrite history. docstoc hashes the exact HTML bytes you download and anchors that digest to Bitcoin via public OpenTimestamps calendars — the same approach used for document certificates and daily chase anchors.

Send three files: .html · .sha256 · .ots

How auditors verify

  1. Hash the HTML (sha256sum pack.html) and match the .sha256 file.
  2. Verify the .ots with the OpenTimestamps client or any compatible verifier.
  3. Confirmation on Bitcoin calendars can take hours after creation — pending packs are still valid to hold.

Included on Business · part of SOX reporting

Open Evidence & exports