AttestProof
Run the access review. Keep the proof. Turn a user-access CSV into per-reviewer review campaigns and a timestamped, hash-chained evidence pack that auditors accept.
The problem, in your words
Quarterly user-access reviews are giant spreadsheets emailed to managers: low completion, rubber-stamping, and no artifact when the auditor asks who reviewed what, when, and whether the revocations happened. Proper tooling is license-gated or priced for enterprises.
“No one stored anything we don't have any screenshots or logs. The guy who owned security left six months ago… Now leadership is asking me to 'recreate' what happened last year.”
“9,800 rows. 140 managers. Due in 10 days. Completion rate last quarter was 34%… The managers who do complete it approve everything. Every single row.”
“A list of users isn't enough. A quarterly access review with sign-off is… If you can't show it happened, for an auditor it didn't happen.”
How it works
Import: paste or upload a CSV of users and entitlements from any system, map the columns, and rows without a reviewer default to you.
Review: each reviewer gets a single-purpose link, no account, and marks every row Keep, Revoke or Don't know from a phone.
Close: mark revocations as actioned, close the review, and download the evidence pack PDF with its sha256, chain head and verify URL.
What you get
- One CSV splits into per-reviewer campaigns; reviewers get magic links, never accounts.
- Keep, Revoke or Don't know per row; "Keep all remaining" requires a typed justification.
- Reminders at T-7, T-2, the due day, then every three days overdue.
- A revocations-to-action list; mark each one done with a date and note.
- Evidence pack: roster, timestamps, IP, every decision, exceptions, sha256, chain head, verify URL.
- Compare with the previous review of the same system: new, removed, changed entitlements.
Screenshots
Pricing
Flat monthly prices. Limits are enforced with upgrade prompts, never by losing data. Cancel any time from the app's billing page. Refund policy.
Free
$0
- 1 system
- 1 open review at a time
- Up to 50 rows per review
- Evidence pack PDF
- Copy-link invites
Starter
$29 per month
- 5 systems
- Unlimited reviews
- Up to 1,000 rows per review
- Email invites and reminders
- CSV export
- History and compare
Pro
$79 per month
- Unlimited systems and rows
- Auditor share links
- 5 team members
- Your logo on packs
- JSON export
- Priority support
Questions
- What data do you hold, and where does it go?
- The rows you import (identifiers, entitlements, optional descriptions and notes), each reviewer's decisions and comments, and the timestamp, IP and browser of every reviewer action. It stays in your account's database; you set retention to 12, 24 or 36 months, and "Delete review data" hard-deletes rows and uploads.
- What happens when I cancel?
- Your account drops to Free limits. Nothing is deleted and existing reviews stay readable. If you delete the account, rows and uploads are removed immediately and generated packs are purged after 30 days unless you downloaded them.
- Does it replace Vanta, Drata, Entra P2 or SailPoint?
- No. Those connect to your identity systems and cover many controls. AttestProof runs one control from a CSV and replaces the spreadsheet-and-email version of a review. If you already own a platform with working access reviews, use it.
- Do reviewers or auditors need an account?
- No. Each reviewer gets a single-purpose link that works on a phone and shows who is asking, why, and what will be recorded. Reviewer links expire 30 days after the review closes. Auditor share links (Pro) are read-only, expire after 14 days by default, and can be revoked any time.
- Is this legal or audit advice?
- No. AttestProof records what your reviewers decided and when. Whether that satisfies a framework or a specific auditor is a judgment for you and them. We never state that your organization is compliant.
- How do I get my data out?
- Every plan generates the evidence pack PDF. Starter adds a CSV export of every row and decision; Pro adds JSON of the full pack. Each PDF prints its own sha256 and a public verify URL, so it stands on its own after you leave.
What it is not
- It does not connect to your identity provider or revoke anything. You import a CSV and make the changes; it records that you did.
- It is not a GRC platform and it does not make you SOC 2 compliant. It is the control and the proof for one control.
- It is not legal, audit or security advice. Your auditor decides what is sufficient; we produce the record they ask for.
Guides
Links
- attestproof.infinihash.com — the app
- Help and changelog
- Security page of AttestProof · practices shared by every app
- Live status · health endpoint
- Launched 28 Sep 2026.







