Observability for auditability

Know the story behind every production change.

Evitrus continuously collects and correlates evidence across your engineering and AI systems — code, deploys, config, access and reviews. Answer “what changed?” in seconds, and produce SOC 2 evidence without the audit fire drill.

Infrastructure, not another compliance tool — closer to Datadog than to a questionnaire.

Two expensive facts about shipping software

When production breaks, nobody can quickly answer “what changed?” — the story is scattered across GitHub, Kubernetes, cloud consoles and Slack. And proving compliance is retrospective, manual and hated: reconstructed after the fact from spreadsheets and screenshots.

Both are the same missing capability: a continuously-collected, queryable record of every change to production and the evidence around it.

One record. Two audiences.

Evitrus persists exactly one thing — the Evidence Event — and derives everything else from it: correlated Changes, control coverage, and the AI provenance of each change. Engineers get a faster incident tool; compliance owners get evidence that was already there.

Two strictly separate, purpose-built views

Optimized for the person asking the question

Incident

What changed before this metric went bad?

Pick a moment and a tag selector (service:… env:… team:…) and see the event timeline in that window — with an optional metric overlay on the same axis, pulled on demand. Deliberately minimal, built for use between audits, not just during them.

Audit

Show me all evidence for control X in period Y.

Choose a control or framework and a period. See every change in scope, aggregate coverage, and — most importantly — the exceptions foregrounded. Export it as an evidence package.

How it works

Evidence flows in with zero application code changes

  1. 1

    Exporters push evidence

    A GitHub App (PRs, reviews, merges, code scanning), a reusable GitHub Actions step (builds with image digests) and a Helm-installed Kubernetes controller (deploy rollouts) emit normalized Evidence Events.

  2. 2

    Correlate into Changes

    Events are stitched by service, commit and image digest into a single Change — the story of one release as it moves from PR to production.

  3. 3

    Answer & attest

    Open the Incident view during an incident, or hand the Audit view an evidence package at review time. Same data underneath.

Compliance falls out of it

SOC 2 CC7 & CC8, continuously evaluated

Controls are evaluated as event-based checks over each Change, producing pass / fail results tied to the exact events that justify them. The exceptions are surfaced first — no screenshots, no Slack archaeology, no reconstructing the quarter after the fact.

  • Every result links to the evidence events behind it
  • Exceptions foregrounded, not buried
  • Exportable evidence packages per control and period

AI provenance, done honestly

Which changes were AI-assisted — and who reviewed them

AI involvement is recorded as a first-class ai actor on the events it touched, linked to the human review that followed. We lead with provenance — “this change was AI-assisted, here’s the review” — not a fuzzy percentage.

Built for the buyers who scrutinize vendors hardest

Least privilege, self-hostable, transparent

Least-privilege exporters

Read-only, scoped access. The Kubernetes controller only watches Deployments; CI and GitHub evidence is pushed with a tenant-scoped API key.

Runs in your boundary

Exporters run inside your cluster and CI. Hosted on EU infrastructure (Hetzner, Germany) with data-processing agreements in place.

Tenant isolation from day one

Every query is scoped to your organization server-side, and permissions are evaluated per role — multi-tenancy and RBAC are not an afterthought.

Closed beta

Request access to the Evitrus closed beta

We're onboarding a small number of design-partner engineering teams. Tell us a little about you and we'll be in touch.

By submitting, you agree that we may contact you about the beta. See our privacy policy.