ReguNav™Trust
Auditor portal

Read-only auditor access

Customers invite their external auditors (Big-4 firms, ISO notified bodies, regulator inspectors) into a per-tenant read-only view. The auditor sees evidence packs + audit-trail replay + control attestations. They never see other customers and never modify anything. Their activity is itself audited and surfaces in the customer's WORM chain.

What the auditor sees

Evidence Pack browser

Per-tenant audit pack browser. View signed Evidence Packs by date range + framework. Download as ZIP with cryptographic manifest.

Audit-trail replay

Reconstruct platform state at any timestamp from the WORM chain. Side-by-side with the current snapshot. Tamper-detection per-row.

Control attestation status

Live per-framework coverage map. Click any control to see the evidence chain + last-reviewed-at + reviewer principal.

Sub-processor + vendor inventory

ReguNav's own sub-processors (CF, Neon, ClickHouse, Stripe, Clerk, etc.) with current DPA + SCC + sub-processor-of-sub-processor chain.

Incident timeline

Public-facing incident log: detection time, root cause, remediation, customer-impact assessment.

Penetration test letters

Latest pen-test attestation letter (when available). Status: Type I ✓ · Type II Q4 2026.

Read-only by construction

How auditors get access

  1. Customer invites you via app.regunav.com → Settings → Auditors → Invite. You receive an email with a sign-in link.
  2. You complete SCA (TOTP or hardware key) on first sign-in. All subsequent sessions require re-auth every 8 hours.
  3. You are routed to trust.regunav.com/auditor/<tenant-slug> — a read-only mirror of the customer's evidence, attestations, and audit-trail.
  4. You can download Evidence Packs, browse the audit-trail replay, export attestation tables. The customer is notified of every export in real-time.
  5. When the engagement ends, the customer revokes access. Your view collapses to a final summary page with the evidence-pack hashes you accessed during the engagement (proof-of-review for your own working papers).
Already invited? Sign in. Not yet invited and your client uses ReguNav? Ask them to invite you via the customer dashboard.