PRODUCT

Evidence Viewer

Every claim traces to a byte-exact quote in a stored, hashed document snapshot.

Book a demo Start free

What it is

The Evidence Viewer is TrustVendor's answer to a specific audit question: "Where exactly did you get that?" Every finding in the Trust Workspace — every certification, every subprocessor entry, every data residency claim — links to the precise character span in the original source document that supports it. That span is anchored in an immutable, SHA-256-verified snapshot stored in TrustVendor's evidence archive.

When you open a claim in the Evidence Viewer, you see the source document rendered with the supporting text highlighted. A sidebar shows the claim predicate, the extractor model version that produced it, the SHA-256 of the stored snapshot, and a button to verify the hash against the blob in storage. No trust in TrustVendor is required — the verification is a client-side computation.

The Evidence Viewer matters most when a vendor disputes a finding or an auditor asks for primary evidence. Instead of a PDF attachment that could have been modified, you present a hash-linked snapshot your auditors can independently verify. The chain from claim to byte offset to file hash is complete, tamper-evident, and requires no special tooling to check.

How it works

Three steps, fully auditable.

01

Snapshot

Every document fetch produces an immutable artifact stored with its SHA-256 content hash as the primary key. No update or delete operation is permitted — the artifact is permanently addressable by hash.

02

Extract

The extractor emits claims with span metadata: page number, character start and end offsets, and a quote hash computed from the normalized slice. A Go validator rejects the claim if the reconstructed hash does not match — hallucinated citations never reach the database.

03

Verify

In the viewer, clicking "Verify" fetches the blob key from the artifact record, downloads the raw bytes, and recomputes the SHA-256 client-side. The result is compared against the stored hash and displayed inline — green for match, red for divergence.

What you get

Built for compliance teams that have to prove things.

Span-level citations

Every claim links to exact character offsets, not just a document page. Auditors see exactly which sentence was relied upon, not a 40-page PDF to search manually.

Immutable archive

Snapshots are append-only and content-addressed. No document can be modified retroactively — the evidence you relied upon two years ago is still there, unchanged, with its original hash.

Client-side hash verification

Hash verification runs in the browser against the live storage backend. You are not trusting TrustVendor to tell you the hash is correct — you are computing it yourself.

Sample

What it looks like in practice.

Evidence drawer — art_8kQ2mR SHA-256 verified

Source: Acme Analytics Trust Centre (trust.acme.com)

...Acme Analytics maintains a SOC 2 Type II certification issued by Schellman and Company. The audit period covers January 1, 2026 through June 30, 2026.

The certification covers the Trust Services Criteria for Security, Availability, and Confidentiality.

No qualified opinions were issued. The next audit cycle begins January 1, 2027...

Claim

Predicate

certification.active

Span

chars 312–412

Content hash

a3f8...c291

Common questions.

What happens if the source document is behind a login?
If the source is a public trust centre or publicly shared document link, TrustVendor stores the full snapshot. For tenant-uploaded documents (e.g., a SOC 2 shared under NDA), the artifact is stored with tenant visibility — only your workspace can access it. The hash verification works identically regardless of visibility.
Can the span location drift over time if the document is re-extracted?
No. The span is anchored to a specific artifact, identified by its content hash. If the document changes and is re-fetched, that produces a new artifact with a new hash. The old span and the old artifact remain unchanged and permanently accessible.
How do I share evidence with an auditor?
Each evidence drawer generates a signed, time-limited read link that exposes the artifact, the highlighted span, and the hash verification result. The link works without a TrustVendor account. You can also export evidence packages as ZIP archives containing the snapshot, the claim metadata, and a verification script.
What format are the stored snapshots in?
Web pages are rendered to normalized plain text after headless rendering, with a companion HTML snapshot. PDFs are stored as-is alongside extracted plain text. The content hash is over the normalized plain text, so verification is consistent across document types.

See Evidence Viewer on your vendor data.

Book a 30-minute demo. We will run it live on vendors from your register.

We will respond within one business day.