For External Auditors

The auditor portal that respects your time — and your client's data

Stop chasing evidence over email. CertiGuard gives external auditors a scoped, secure, read-only portal to review controls, download evidence packs, and raise findings — all through a single time-boxed link.

What you get inside the portal

Everything you need for fieldwork, nothing you don't.

Scoped, view-only access

See exactly the controls, evidence, and framework mappings the client has assigned to your engagement — nothing more, nothing less.

Evidence packs on demand

Download organized evidence bundles with version history, collection dates, and reviewer sign-off — ready for your working papers.

Findings & requests in one place

Raise audit findings, request additional evidence, and track resolution status without a single email thread.

Time-boxed engagement links

Access expires automatically when the engagement window closes. No lingering credentials, no follow-up cleanup.

How token access works

No account to create. No password to remember. Just a secure, scoped link.

1

Client issues a secure link

The engagement administrator generates a tokenised link from the Auditor Scope module, scoped to the frameworks and systems in your audit.

2

You enter the passphrase

Each link is protected by a passphrase shared out-of-band. The token is single-use, time-limited, and bound to your engagement scope.

3

You work inside the portal

Review evidence, map controls to requirements, raise findings, and request additional documentation — all within a read-only, audited environment.

Zero standing access. Tokens are single-use, scoped to specific frameworks and systems, and expire automatically at the engagement end date. Every action inside the portal is written to an immutable, hash-chained audit trail.

Frameworks supported in the portal

Your client scopes the link to the frameworks in your engagement. We support the full list below.

SOC 2 Type I & II
ISO 27001 / 27017 / 27018
ISO 27701 (Privacy)
NIST CSF 2.0
NIST 800-53
PCI DSS 4.0
HIPAA
GDPR
POPIA (South Africa)
SADC Data Protection frameworks
King IV (South Africa)
NIS2 (EU)

Request access for your next engagement

Tell us about yourself and your upcoming engagement. We'll set you up with a walkthrough and connect you with the client onboarding team.

We'll respond within one business day. Your details are used solely to set up your portal access.