The problem
Audit preparation becomes a last-minute file hunt when requirement mappings, source excerpts, evidence, and review decisions live in separate systems.
What EKOS does
EKOS walks qualifying reviewed relationships for a framework or citation prefix and assembles the requirements, documents, excerpts, provenance, and review context into a canonical manifest and companion binder.
- Framework-wide or citation-prefix assembly
- Inclusion from reviewed evidence relationships
- Canonical hash-chained JSON manifest
- Readable PDF binder tied to the package identity
- Verification that identifies where consistency breaks
How it works
An administrator scopes the package to a framework, or to a citation prefix such as one control family.
EKOS walks the qualifying reviewed relationships and assembles requirements, documents, excerpts, provenance, and review context as of that moment.
The authoritative output is a canonical JSON manifest whose entries are linked by hashes, with the root hash stored in the package catalog.
A readable PDF binder is rendered from the manifest and carries the package ID and root hash on its cover.
Verification recomputes the chain against the catalog and reports the first edited, removed, or reordered entry if consistency breaks.
Business outcome
Teams can produce a consistent, reviewable audit artifact without rebuilding the evidence trail for every request.
Proof and human control
Manifest entries are linked by hashes and tied to a stored root hash, allowing verification to identify edited, removed, or reordered entries.
Example in practice
An auditor requests evidence for a control family. An administrator assembles the scoped package, verifies its root hash, and provides the JSON manifest and PDF binder as a point-in-time record.
Scope today
This capability is in preview. Hash verification shows internal consistency; it does not establish that the evidence is complete, sufficient, truthful, or legally compliant.
