Thiqa

Evidence that collects itself

Thiqa reads the systems you already run, attaches each artefact to every control it proves, and flags it the moment it goes stale.

Request a call →Early access · work email only
One collection, start to finish

Every artefact, against every control it answers

Evidence

What proves each control, and how far each one is from collecting itself.

112

Satisfied and current

11

Failing collection

23

Expiring within 30 days

22

Never collected

68 of 168 collect themselves

A hundred need a person every cycle. Twenty-two of those could stop needing one today — you already run on AWS.

Automate 22
All168Automatic68Assisted24Manual76
Search evidenceFrameworkStatusSourceOwnerAdd evidence
EvidenceCollectionStatusBlockingPersonnelSoonest first
  • EV-041Encryption at restCloud infrastructure · CryptographyAWS · APIFailing2 of 12 databasesPCI DSS · 31 daysCloud teamView
  • EV-033Container encryption settingsEngineering · CryptographyManual · ScreenshotNever collectedNo record existsPCI DSS · 31 daysUnassignedUpload
  • EV-052Backup retention configurationCloud infrastructure · ResilienceAWS · ScreenshotPartial3 of 5 capturedISO 27001 · 24 daysA. FathyCapture
  • EV-002Network architecture diagramGRC · Scoping · RegisterManual by nature · RegisterNeeds review3 of 5 checksISO 27001 · 24 daysGRC teamView
  • EV-061TLS versionCloud infrastructure · NetworkAWS · APIFailing1 of 4 balancersNot blockingCloud teamView
  • EV-007Security committee minutesGRC · Governance · QuarterlyManual by nature · RecordGap foundQ2 quorum sign-offNot blockingGRC teamUpload
  • EV-018Quarterly access review exportHuman resources · Access reviewsWebhook · CustomCollectedCurrentNot blockingHR teamView
1–7 of 168Sweep #84 completed 29 Aug · next 28 Sept
One artefact answering CBE, PCI DSS and ISO 27001

Collected once, attached to each control it proves, across frameworks at the same time. An access review pulled for CBE is the artefact PCI DSS and ISO 27001 also ask for — so the work happens once, and coverage is derived from what exists rather than asserted.

Works with PDPLPCI DSS v4.0ISO 27001CBEFRAAgent

How this compares

Thiqa

When evidence is gathered
On each control’s own cadence, continuously
One artefact, many frameworks
Mapped to every control it proves, at once
Regional obligations
CBE, FRA, SAMA and UAE alongside the global set
How a control’s state is decided
Derived from the evidence that exists
When evidence expires
Coverage drops and the control is flagged
Who signs it off
A named approver, before anything files

Compliance automation tools

When evidence is gathered
On a fixed platform schedule
One artefact, many frameworks
Usually mapped per framework
Regional obligations
Global frameworks, regional as custom work
How a control’s state is decided
Derived, where a connector exists
When evidence expires
Varies by platform
Who signs it off
Varies by platform

Manual and consultants

When evidence is gathered
In the weeks before an audit
One artefact, many frameworks
Re-gathered for each framework
Regional obligations
Whatever the engagement scoped
How a control’s state is decided
Asserted by whoever filled the sheet
When evidence expires
Found at the next audit
Who signs it off
A named approver, before anything files

Evidence FAQ

Does Thiqa need write access to my systems?
No. Connectors are read-only and scoped to the specific objects a control requires.
What happens when evidence expires?
The control moves to expiring, then expired, and overall coverage falls accordingly — before an auditor asks.
Does one artefact really answer several frameworks?
Yes. An access review pulled for CBE is the same artefact PCI DSS and ISO 27001 ask for, so it is collected once and attached to every control it proves.

Stop rebuilding the same evidence pack.