A written procedure
It shows intent, not action. The auditor asks what it looked like during the last incident.
ISO 27001 and SOC 2 ask you to show how you communicate incidents to customers. A timestamped page proves it without extra work.
No standard names a tool — they ask for evidence:
It shows intent, not action. The auditor asks what it looked like during the last incident.
The evidence exists, but you assemble it by hand before every audit, and the recipient list is never complete.
Excellent for the team and silent to the outside — and the outside is what is being asked about.
Every report and update is timestamped automatically and stays in the archive.
Subscriber notifications are recorded, and maintenance is announced ahead of time with start and end.
Every change in the workspace — who, what, when — including what an AI assistant did through MCP.
Retention is written into the plan and the data stays in the EU, which answers the next question on the list.
Evidence no longer has to be collected before an audit: it collects itself.
No, the standard names no tool. But a public page with history is the fastest way to show you communicate with external parties.
Reports stay for as long as the page exists. Check data retention depends on the plan — from 14 days to 24 months.
Yes: API, CLI, RSS and JSON feeds. The page is also available as Markdown.