Deadline

Nov 2026: DoD CMMC L2 enforcement begins for new prime contracts. Most DIB firms aren't ready. See your gap →

Platform · Evidence Locker

Per-control evidence, hashed and audit-logged. Not a shared drive.

Drop a screenshot, config export, or policy attestation into the evidence slot for any control. Cincra hashes it (SHA-256), scans it, marks it for CUI, and binds it to the control with a review state — pending, approved, audit-ready.

Evidence Locker illustration: steel vault with indexed file drawers
What's inside

SHA-256 hashing

Every upload is hashed at ingest. Re-hash on download proves the bytes never changed.

Executable & EICAR screening

Magic-byte and EICAR signature checks flag obvious risky uploads before they reach an auditor's eyes. (Full AV scan via ClamAV / VirusTotal is on the roadmap.)

CUI flag

Mark evidence as CUI / non-CUI. Triggers handling rules and access-log requirements. Full NARA CUI category marking is on the roadmap.

Per-control binding

Every file is bound to a specific control and visible to the reviewer in the same context.

Download audit log

Every download by an MSP operator or auditor is recorded with timestamp, actor, and engagement ID in the hash-chained audit trail.

Private object storage

Stored in a private Backblaze B2 bucket. Server-proxied uploads — no direct client-to-storage URLs.

Evidence Locker explainer: gold-trimmed vault with per-control file slots, SHA-256 integrity, CUI flag
Per-control slots · SHA-256 · executable screening · CUI flag