Published
Last reviewed: 2026-09-15
Auditor Export Pack
Download a ZIP of reports, SBOM, audit trail, and policies for auditors. Optional billed evidence refresh before assembly; ZIP assemble stays free.
Purpose
Assemble one auditor-ready ZIP from evidence on file: organization reports (CSV/PDF subset), CycloneDX SBOM per project unit, audit-trail export, and a policy bundle snapshot — plus coverage.json and a SHA-256 manifest.json.
Optionally refresh evidence first (bulk ensure scans at branch tip). Refresh scans are billed; assembling the ZIP does not consume credits.
Who can use it
- Roles with Settings access in the app.
- Plan entitlement
auditorExportPack: Team and Regulated (not Free/Starter).
Prerequisites
- At least one repository in the organization.
- Optional: recent scans and SBOMs for the selected repositories (missing pieces are soft-skipped and recorded in Coverage unless you refresh).
- Enough credits if you enable refresh (HTTP 402 when the pool cannot cover the estimate).
How to use it
- Open Reports → Auditor export packs.
- Select repositories and an optional audit-trail date range.
- Optionally enable Refresh evidence when launching (and Continue even if some refreshes fail). Preview credits if needed.
- Acknowledge the warning, then create the pack — you are redirected immediately (no waiting on the create screen).
- If refresh was selected, follow Evidence refreshes (linked from Reports/SBOM and the pack detail) for per-unit progress.
- When pack status is completed, download the ZIP.
Coverage honesty trail
Coverage records each include/skip/stale decision:
- SBOM (per project unit): skipped if missing; stale when the scanned commit differs from the known default-branch tip; tip unknown when tip or commit is missing. Stale SBOM files are still included.
- Reports: aggregated latest scans (
aggregated_latest_scans) — not a single commit SHA. Exception: SLA compliance is org-wide (org_wide_sla_not_repo_filtered) because live SLA data is not repository-filtered today. - Audit trail: may be truncated at the row cap.
- Policies: org-wide snapshot (not SHA-stale).
Default-branch tips are refreshed from GitHub on push to the default branch (independently of scan-on-push) and during identify-commit flows.
Limits / out of scope (v1)
- No branch/commit picker and no billed ensure-scan at pack time.
- Per-project-unit CycloneDX files include a JWS (RS512) signature when platform signing keys are configured;
manifest.jsonSHA-256 hashes cover ZIP integrity only (the ZIP itself is not cryptographically signed). - No MCP or public API surface for packs yet.
- Pack files expire after
AUDITOR_EXPORT_TTL_DAYS(default 7).