VeritomeHelp Center
/

The Evidence hub: coverage, uploads, connectors and freshness

Read coverage and gaps across the portfolio, upload hash-deduplicated files, pull proof in with read-only OAuth connectors, and track expiry so stale evidence is flagged.

Updated 15.07.2026

The Evidence hub is the cross-portfolio view of every file you hold as proof. It shows every record, its source, and the obligations it satisfies — grouped so identical documents collapse into a single row.

Read the coverage cards

The cards along the top answer "how covered am I?":

  • Evidence records — how many pieces of proof you hold, across how many systems.
  • Obligations covered — how many obligations have at least one piece of evidence (and the percentage).
  • Gaps — obligations with no evidence yet. This is your to-do list.
  • Auto-sourced — the share that arrived without a manual upload (generated by Veritome or pulled in by a connector).

Filter the table by source — Verified links · Documents · Code / tickets · Cloud config — and search by name.

Upload evidence

  1. Click Upload.
  2. Choose the file, then attach it to the obligation (and system) it proves — or leave it as an org-level record when it's a policy that applies across the whole organisation rather than to one system.
  3. Veritome fingerprints the file with its SHA-256 hash, so re-uploading the same document is recognised as the same evidence rather than a duplicate. One data-governance policy can satisfy obligations on a dozen systems, and the hub shows that read-across — with a jump to every linked obligation.

OAuth connectors — bring evidence in automatically

Rather than upload by hand, connect the tools your proof already lives in. Click Connectors:

  • Google Drive, SharePoint / OneDrive, GitHub and Jiraread-only OAuth connections.
  • A connector is connectable only when this deployment has its OAuth app set up, and connecting is an admin action.
  • Once connected, Sync pulls in the most recent items as Connected evidence (deduped so a re-sync doesn't pile up copies). Disconnect at any time.

See Connect identity, HR and cloud for auto-evidence for the connector detail.

Freshness, expiry and renewal

Proof goes stale — a certificate lapses, a signed policy ages out, a dated screenshot stops reflecting reality. Veritome tracks this:

  • Give a record an expiry date (or a review cadence). Records with no expiry are evergreen.
  • Each record carries a freshness state — Fresh, Renew soon (expiring within the window) or Expired — shown as a badge once it needs attention.
  • A daily job reminds owners and admins as evidence approaches or passes expiry, and quietly drops expired proof out of coverage until it's renewed. It does not auto-fail the obligation — it flags the control as at-risk.
  • Renew a record to re-verify it and roll its clock forward one cadence.

Coverage, gaps and freshness together are what let you walk into an audit knowing exactly which controls are proven, which are stale, and which are still bare.

Need to act on this?Open Veritome