Evidence that collects itself
Thiqa reads the systems you already run, attaches each artefact to every control it proves, and flags it the moment it goes stale.
Request a call →Early access · work email only
Every artefact, against every control it answers
Evidence
What proves each control, and how far each one is from collecting itself.
112
Satisfied and current
11
Failing collection
23
Expiring within 30 days
22
Never collected
68 of 168 collect themselves
A hundred need a person every cycle. Twenty-two of those could stop needing one today — you already run on AWS.
All168Automatic68Assisted24Manual76
Search evidenceFrameworkStatusSourceOwnerAdd evidence
EvidenceCollectionStatusBlockingPersonnelSoonest first
- EV-041Encryption at restCloud infrastructure · CryptographyAWS · APIFailing2 of 12 databasesPCI DSS · 31 daysCloud teamView
- EV-033Container encryption settingsEngineering · CryptographyManual · ScreenshotNever collectedNo record existsPCI DSS · 31 daysUnassignedUpload
- EV-052Backup retention configurationCloud infrastructure · ResilienceAWS · ScreenshotPartial3 of 5 capturedISO 27001 · 24 daysA. FathyCapture
- EV-002Network architecture diagramGRC · Scoping · RegisterManual by nature · RegisterNeeds review3 of 5 checksISO 27001 · 24 daysGRC teamView
- EV-061TLS versionCloud infrastructure · NetworkAWS · APIFailing1 of 4 balancersNot blockingCloud teamView
- EV-007Security committee minutesGRC · Governance · QuarterlyManual by nature · RecordGap foundQ2 quorum sign-offNot blockingGRC teamUpload
- EV-018Quarterly access review exportHuman resources · Access reviewsWebhook · CustomCollectedCurrentNot blockingHR teamView
1–7 of 168Sweep #84 completed 29 Aug · next 28 Sept
Collected once, attached to each control it proves, across frameworks at the same time. An access review pulled for CBE is the artefact PCI DSS and ISO 27001 also ask for — so the work happens once, and coverage is derived from what exists rather than asserted.
Works with PDPLPCI DSS v4.0ISO 27001CBEFRAAgent
How this compares
| What is being compared | Thiqa | Compliance automation tools | Manual and consultants |
|---|---|---|---|
| When evidence is gathered | On each control’s own cadence, continuously | On a fixed platform schedule | In the weeks before an audit |
| One artefact, many frameworks | Mapped to every control it proves, at once | Usually mapped per framework | Re-gathered for each framework |
| Regional obligations | CBE, FRA, SAMA and UAE alongside the global set | Global frameworks, regional as custom work | Whatever the engagement scoped |
| How a control’s state is decided | Derived from the evidence that exists | Derived, where a connector exists | Asserted by whoever filled the sheet |
| When evidence expires | Coverage drops and the control is flagged | Varies by platform | Found at the next audit |
| Who signs it off | A named approver, before anything files | Varies by platform | A named approver, before anything files |
Thiqa
- When evidence is gathered
- On each control’s own cadence, continuously
- One artefact, many frameworks
- Mapped to every control it proves, at once
- Regional obligations
- CBE, FRA, SAMA and UAE alongside the global set
- How a control’s state is decided
- Derived from the evidence that exists
- When evidence expires
- Coverage drops and the control is flagged
- Who signs it off
- A named approver, before anything files
Compliance automation tools
- When evidence is gathered
- On a fixed platform schedule
- One artefact, many frameworks
- Usually mapped per framework
- Regional obligations
- Global frameworks, regional as custom work
- How a control’s state is decided
- Derived, where a connector exists
- When evidence expires
- Varies by platform
- Who signs it off
- Varies by platform
Manual and consultants
- When evidence is gathered
- In the weeks before an audit
- One artefact, many frameworks
- Re-gathered for each framework
- Regional obligations
- Whatever the engagement scoped
- How a control’s state is decided
- Asserted by whoever filled the sheet
- When evidence expires
- Found at the next audit
- Who signs it off
- A named approver, before anything files
Evidence FAQ
- Does Thiqa need write access to my systems?
- No. Connectors are read-only and scoped to the specific objects a control requires.
- What happens when evidence expires?
- The control moves to expiring, then expired, and overall coverage falls accordingly — before an auditor asks.
- Does one artefact really answer several frameworks?
- Yes. An access review pulled for CBE is the same artefact PCI DSS and ISO 27001 ask for, so it is collected once and attached to every control it proves.