Per-control evidence, hashed and audit-logged. Not a shared drive.
Drop a screenshot, config export, or policy attestation into the evidence slot for any control. Cincra hashes it (SHA-256), scans it, marks it for CUI, and binds it to the control with a review state — pending, approved, audit-ready.

SHA-256 hashing
Every upload is hashed at ingest. Re-hash on download proves the bytes never changed.
Executable & EICAR screening
Magic-byte and EICAR signature checks flag obvious risky uploads before they reach an auditor's eyes. (Full AV scan via ClamAV / VirusTotal is on the roadmap.)
CUI flag
Mark evidence as CUI / non-CUI. Triggers handling rules and access-log requirements. Full NARA CUI category marking is on the roadmap.
Per-control binding
Every file is bound to a specific control and visible to the reviewer in the same context.
Download audit log
Every download by an MSP operator or auditor is recorded with timestamp, actor, and engagement ID in the hash-chained audit trail.
Private object storage
Stored in a private Backblaze B2 bucket. Server-proxied uploads — no direct client-to-storage URLs.
