About The Audit Trail
Last updated Sep 23, 2026
What The Audit Trail is
The Audit Trail is an independent editorial desk that rates compliance automation software. We publish a scored rubric, apply it to platforms that help companies prepare for SOC 2, ISO 27001, HIPAA, PCI DSS, and related frameworks, and make the scores, methodology, and source links public.
We are not owned by a vendor, a security consultancy, or an audit firm. Some vendors pay us to be included, and that payment never affects the rankings or the review itself. Any commercial relationship with a vendor is disclosed on every page it touches.
The rubric
The current rubric is version 0.9, a public draft published on 23 September 2026. It covers eight criteria, each weighted by how much it affects a compliance team’s practical experience of a platform:
- Framework coverage (15 points): How many frameworks run automatically, without manual setup.
- Automated evidence (20 points): Published integration count and continuous automated testing.
- Audit path (15 points): How directly the platform connects you to a signed audit report.
- Pricing transparency (10 points): Whether a buyer can estimate cost before speaking to sales.
- Trust and questionnaires (10 points): Trust centers and questionnaire automation tools.
- Vendor risk management (10 points): Tools for assessing and tracking your own suppliers.
- Customisation (10 points): Support for frameworks and automated tests you build yourself.
- User sentiment (10 points): Independent review scores, weighted by volume.
Each criterion has five levels. Level 0 represents the absence of the capability; level 5 represents the strongest confirmed form of it. The score for a criterion is its level divided by five, multiplied by its weight. Totals range from 0 to 100. Score bands: 85 and above is Exemplary, 70 to 84 is Strong, 55 to 69 is Adequate, 35 to 54 is Limited, and below 35 is Deficient.
The rubric is published in full at the rubric page, with the rationale for each criterion’s weight.
What the scores are, and what they are not
Version 0.9 scores every platform from its own public documentation: product pages, pricing pages, documentation pages, and marketplace listings the vendor controls. A capability not confirmed on the vendor’s own pages scores as absent. The scorecard records what was and was not confirmed for each criterion.
Every scorecard carries a Provisional status at this stage. The scores reflect what is documented publicly in September 2026.
Version 1.0 of the rubric will add hands-on criteria, including time from account creation to first passing automated test and the accuracy of evidence collection against a known test environment. Those tests have not run. We will publish the methodology before running them.
Independence and conflicts of interest
Some vendors pay us to be included on The Audit Trail. That payment never affects the rankings or the review itself. Scores come from the rubric and nothing else, and a vendor cannot pay to move up a ranking or to push another vendor down.
We do not hold financial interests in any platform we rate. If this ever changes, we will disclose the relationship and explain how editorial separation is maintained. The details are on how we make money.
We accept re-score requests from vendors. A vendor can send us the public page that confirms a capability we scored as absent, and we will re-check it. The page must be the vendor’s own documentation; a third-party review site is not a valid source for a re-score. When a score changes, we update the scorecard and record the change in the rubric changelog with the date.
Corrections
If a score or factual detail is wrong, we want to know. Send the source URL that shows the correct information. We check it, update the record if confirmed, and note the change with the date. The previous score remains visible in the changelog. Our editorial policy describes the full corrections process.
Contact
For corrections, re-score requests, and editorial questions, contact us at hello@theauditrail.com.