Skip to main content
The Documents page is your central repository for all compliance-related files. Upload evidence documents, audit reports, certificates, and any other files your auditors need to review — everything lives in one place.

What documents are for

During an audit, your auditor requests evidence — SOC 2 reports, penetration test results, insurance certificates, signed agreements, training records, and more. Instead of scrambling to find these files across Google Drive, email, and Slack, you upload them to DSALTA once. When the auditor needs them, they are already organized and ready.

Viewing your documents

The document list shows all uploaded files with: Click any row to open the Document panel, which has Evidence, Controls, Notes and Comments tabs. The Evidence tab lists every file on the document with a download button, and Add Files attaches more.

Uploading documents

  1. Navigate to Data Library → Documents in the sidebar.
  2. Click Add Document. The Add New Document dialog opens.
  3. Drag and drop your file or browse to select it. Supported formats include PDF, DOCX, XLSX, PNG, JPG, and CSV.
  4. Enter a Title (required, up to 100 characters), optionally a Description (up to 200 characters), and pick any Frameworks the document belongs to. Controls are mapped afterwards, from the document’s Controls tab.
  5. Click Upload.
Selecting several files in one go attaches all of them to a single document — one row in the list, with every file on its Evidence tab. Each file can be up to 50 MB. Run Add Document once per document you want listed separately.

Organizing documents

Keep your repository navigable with the Title you give each document, the Frameworks you tag it with — the list has a Framework column and a matching filter — and the controls you map to it. A naming convention helps here, for example:
  • Certificates — SOC 2 reports, ISO certificates, insurance certificates
  • Reports — Penetration test results, vulnerability scan reports, risk assessments
  • Agreements — DPAs, NDAs, vendor contracts, BAAs
  • Evidence — Screenshots, configuration exports, audit logs
  • Policies — Signed policy documents (these are separate from the Policies module, which handles approval and employee acceptance)

Linking documents to controls

When you link a document to a compliance control, it appears as evidence for that control during audits. This means your auditor can see exactly which documents support each control requirement without you having to explain it. To link a document to a control:
  1. Open the document detail page.
  2. Open the Controls tab and click the + button in its card header.
  3. Search for and select the relevant control(s).
  4. The document now appears as evidence under those controls in the Compliance section.

Document expiry

Some documents expire — insurance certificates renew annually, penetration tests are valid for a year, SOC 2 reports cover a specific audit period. Track those renewals with the document’s Due Date: set it from My Tasks using the row’s Change Due Date action, and the Documents list shows it in the Due Date column, turning red once the date has passed. When the renewed file arrives, open the document and use Add Files on its Evidence tab, so the framework and control mapping already on that document carries over.