Skip to main content
Evidence Handling & Retention

Evidence Handling and Data Retention

Understand how Auditzo handles audit reports, screenshots, HAR/network evidence, cookie and storage exports, monitoring snapshots and other supporting materials across automated and manually scoped review paths.

This page is a practical buyer-clarity page. It explains evidence expectations and boundaries, but it does not replace Auditzo’s Privacy Policy, Terms, Cookie Policy or any custom agreement.

Evidence lifecycle Scope-based
Observe website behavior within scope
Generate report or scoped evidence files
Limit access to authorized review and delivery
Retain based on plan, scope or agreement
Why this page exists

Evidence handling matters because audit files can contain more than a summary

Audit outputs can include report files, screenshots, request-level context, cookie and storage observations, accessibility reproduction notes, monitoring snapshots or remediation verification notes. Buyers should understand what may be generated, what is included by default and what requires a manually scoped engagement.

Evidence can contain sensitive technical context

Screenshots, HAR/network files, cookies, storage exports and request logs can reveal more context than a normal report summary.

Different report paths produce different artifacts

Automated reports, Manual Evidence Audits, WCAG reviews, monitoring and verification work do not create the same evidence outputs.

Retention should match the reason for collection

Auditzo aims to keep evidence only for the period needed to deliver, support, review or verify the agreed audit work.

Access should stay controlled

Evidence access should be limited to authorized Auditzo reviewers, system processes and approved client recipients based on the selected path.

Evidence by review path

Automated reports and Manual Evidence Audits do not create the same evidence package

The most important distinction: automated reports are built for structured initial visibility. Raw evidence handoff, deeper screenshots, HAR/network evidence and cookie or storage comparisons belong to manually scoped evidence work where agreed.

Automated reports

Self-generated reports are designed for quick initial visibility. They do not include human verification, Accept/Decline interaction testing or raw evidence handoff by default.

  • PDF/HTML report output
  • Initial-state cookies, storage and request signals where detected
  • No raw evidence package by default
  • No human review by default

Manual Evidence Audits

Manual audits are scoped human-reviewed engagements. They can include deeper evidence files and handoff materials where agreed in scope.

  • Screenshots where scoped
  • HAR/network evidence where scoped
  • Cookie/storage comparisons where scoped
  • Evidence index and raw files where scoped

WCAG Accessibility Audits

Accessibility reviews focus on human-verified accessibility findings, reproduction context and remediation guidance within the agreed WCAG-oriented scope.

  • Screenshots and affected components
  • Keyboard/focus/semantic observations
  • WCAG-oriented mapping where scoped
  • No ADA or WCAG certification

Monitoring and verification

Monitoring and post-remediation verification create comparison records for selected signals or findings, not unlimited re-audits of the entire website.

  • Change snapshots where selected
  • Selected finding rechecks
  • Status notes such as appears resolved or still present
  • No compliance guarantee
Artifact comparison

What files may exist depends on the selected audit path

A self-generated automated report is not the same as a manually scoped raw evidence package. This table is designed to prevent confusion before ordering or sharing results with a team.

“Where scoped” means the file or evidence type must be included in the selected plan, proposal, order or custom engagement terms.

Artifact Automated reports Manual / custom scope
PDF / HTML report
Used for review, sharing and remediation planning.
Yes, based on selected automated plan Yes, where part of the agreed deliverable
Screenshots
May show banner states, page context, findings or accessibility evidence.
Limited report visuals where available Yes, where scoped
HAR / network evidence
Can include request URLs, domains, timing, headers or request context depending on capture.
Not provided as raw handoff by default Yes, where scoped
Cookie and browser storage exports
Used for state comparison such as initial, Accept, Decline or preference states.
Initial-state observations may appear in report Yes, where scoped
Findings register / evidence index
Helps connect observations to evidence files and remediation notes.
Automated report structure only Yes, where scoped
Raw evidence package
Provided only when included in the Manual Evidence Audit or custom engagement scope.
No, not included by default Yes, where scoped
Monitoring snapshots
Used to compare changes over time, not to replace a manual evidence audit.
Only if monitoring is selected Only if included in monitoring or follow-up scope
Verification notes
Used after remediation to document whether selected findings appear changed.
No, unless a verification workflow is selected Yes, where scoped
Retention approach

Retention should be clear before teams rely on evidence files

Auditzo’s retention approach should stay tied to the product path, paid plan, manual scope, monitoring setup or custom agreement. Exact retention windows should be confirmed in the order, proposal or engagement scope before relying on them.

Plan and scope based

Retention depends on the selected report path, paid plan, manual engagement scope, monitoring setup or custom agreement.

Evidence-minimizing by default

Auditzo should not retain raw evidence longer than needed for delivery, support, verification or agreed client use.

Authorized access only

Access should be limited to the people and systems needed to produce, deliver, support or verify the audit work.

Deletion can be requested

Clients can ask about removal of report files or evidence materials, subject to operational, backup, billing, security and legal record constraints.

Safe evidence sharing

Before a manual audit, reduce unnecessary sensitive data exposure

Manual evidence work is most useful when the testing scope is clear and the client avoids sharing unnecessary sensitive information. Use test flows wherever possible.

  • Use test accounts or staging environments when authenticated or checkout-before-payment flows are included.
  • Do not send real customer passwords, live payment card details, government IDs, medical records or unnecessary personal data for testing.
  • Share credentials through an agreed secure method rather than public tickets, open spreadsheets or plain email threads when possible.
  • Tell Auditzo before testing if a page, flow or screenshot may expose customer data, account data, internal dashboards or regulated information.
  • Confirm whether evidence files are needed before the audit begins, because raw evidence handoff is not included in standard self-generated automated reports.
What this page is not

This is not a legal policy replacement

This page helps buyers understand audit evidence handling in practical terms. Formal legal terms should still be reviewed through Auditzo’s policy pages and any signed agreement.

  • This page is not a replacement for Auditzo’s Privacy Policy, Terms, Cookie Policy or any client-side legal review.
  • This page does not create a data processing agreement, legal opinion, compliance certification or legal guarantee.
  • This page does not promise that every possible file, log, screenshot, request, cookie, visitor state or backup copy will be retained or deleted in a particular way unless separately agreed.
  • Exact retention windows, evidence handoff formats and deletion expectations should be confirmed in the selected plan, order, proposal or custom scope.
Need raw evidence?

Request a Manual Evidence Audit when supporting files matter

If your team needs screenshots, HAR/network evidence, cookie or storage comparisons, evidence indexes or raw evidence handoff, confirm those expectations before the audit starts.

Important buyer note

Do not assume that every report includes every evidence file. Raw evidence handoff, consent-state comparisons, screenshots and HAR/network materials should be explicitly scoped when needed.

Auditzo provides technical evidence and observations for review. It does not provide legal advice, compliance certification or guarantees.

Related pages

Continue from evidence handling into the right Auditzo path

These pages explain scope, methodology, manual evidence work, sample outputs, monitoring and verification after remediation.

FAQs

Evidence handling and retention FAQs

Common questions about automated reports, manual evidence files, HAR/network evidence, deletion requests and retention expectations.

No. Self-generated automated reports do not include raw evidence handoff by default. Raw evidence files such as screenshots, HAR/network evidence, cookie or storage exports and evidence indexes can be included in Manual Evidence Audits or custom engagements where scoped.

Not by default. Automated reports are designed for structured initial visibility. Downloadable raw evidence packages are handled through manually scoped evidence work or custom engagements where agreed.

A Manual Evidence Audit can include screenshots, HAR or browser network evidence, cookie and browser-storage comparisons, request-level observations, evidence indexes and raw evidence handoff where included in the agreed scope.

Retention depends on the selected plan, report path, manual scope, monitoring setup or custom agreement. Exact retention expectations should be confirmed in the plan, order, proposal or engagement scope before relying on them.

Clients can ask Auditzo about removal of report files or evidence materials. Deletion may be subject to operational, backup, billing, security, support or legal record constraints.

Yes. HAR and network evidence can include URLs, request destinations, timing, headers, query strings and other technical context. Clients should avoid unnecessary personal data and should use test accounts where possible.

No. This page explains practical evidence handling and retention expectations for audit work. It does not replace Auditzo’s Privacy Policy, Terms, Cookie Policy, data processing terms or legal review.

No. Auditzo provides technical evidence, observations and review support. It does not provide legal advice, compliance certification, legal conclusions or guarantees.

Need clearer evidence of what your website is doing?

Start with an automated scan for quick visibility, or request a Manual Evidence Audit when screenshots, network evidence, consent-state comparison or raw supporting files matter.