Skip to content
Published

Last reviewed: 2026-09-15

Auditor Export Pack

Download a ZIP of reports, SBOM, audit trail, and policies for auditors. Optional billed evidence refresh before assembly; ZIP assemble stays free.

Purpose

Assemble one auditor-ready ZIP from evidence on file: organization reports (CSV/PDF subset), CycloneDX SBOM per project unit, audit-trail export, and a policy bundle snapshot — plus coverage.json and a SHA-256 manifest.json.

Optionally refresh evidence first (bulk ensure scans at branch tip). Refresh scans are billed; assembling the ZIP does not consume credits.

Who can use it

  • Roles with Settings access in the app.
  • Plan entitlement auditorExportPack: Team and Regulated (not Free/Starter).

Prerequisites

  • At least one repository in the organization.
  • Optional: recent scans and SBOMs for the selected repositories (missing pieces are soft-skipped and recorded in Coverage unless you refresh).
  • Enough credits if you enable refresh (HTTP 402 when the pool cannot cover the estimate).

How to use it

  1. Open Reports → Auditor export packs.
  2. Select repositories and an optional audit-trail date range.
  3. Optionally enable Refresh evidence when launching (and Continue even if some refreshes fail). Preview credits if needed.
  4. Acknowledge the warning, then create the pack — you are redirected immediately (no waiting on the create screen).
  5. If refresh was selected, follow Evidence refreshes (linked from Reports/SBOM and the pack detail) for per-unit progress.
  6. When pack status is completed, download the ZIP.

Coverage honesty trail

Coverage records each include/skip/stale decision:

  • SBOM (per project unit): skipped if missing; stale when the scanned commit differs from the known default-branch tip; tip unknown when tip or commit is missing. Stale SBOM files are still included.
  • Reports: aggregated latest scans (aggregated_latest_scans) — not a single commit SHA. Exception: SLA compliance is org-wide (org_wide_sla_not_repo_filtered) because live SLA data is not repository-filtered today.
  • Audit trail: may be truncated at the row cap.
  • Policies: org-wide snapshot (not SHA-stale).

Default-branch tips are refreshed from GitHub on push to the default branch (independently of scan-on-push) and during identify-commit flows.

Limits / out of scope (v1)

  • No branch/commit picker and no billed ensure-scan at pack time.
  • Per-project-unit CycloneDX files include a JWS (RS512) signature when platform signing keys are configured; manifest.json SHA-256 hashes cover ZIP integrity only (the ZIP itself is not cryptographically signed).
  • No MCP or public API surface for packs yet.
  • Pack files expire after AUDITOR_EXPORT_TTL_DAYS (default 7).

Related documentation