Skip to content
deveca GRC
For auditors

Audit access that releases only what you need.

The deveca auditor portal gives external assessors secure, read-only access to released evidence — with scope grants, mandatory 2FA, and automatic expiry. Auditor accounts for external assessors are permanently free.

Capabilities

Everything for the audit — and nothing beyond it.

Auditors see only the evidence pack and the context the tenant releases for that audit. Assessments, findings, and communication stay in the portal — the tenant keeps control.

Evidence Library

Released control and audit evidence in a clear library — with filters, preview, and download.

Controls & SoA

Review control assessments with implementation status, domain, and audit notes, and assess conformity.

Record findings

Document findings directly in the portal — with severity, control reference, and links to evidence.

Scope & context

Scope document and optional risk and asset context only for the defined audit scope — nothing beyond it.

Audit communication

A comment thread per audit for questions to the auditee team — without email ping-pong and Excel attachments.

Scope grants & expiry

Time-limited access with a definable evidence pack, extension, revocation, and an access log (PDF).

Free — permanently

Auditor accounts for external assessors are free and stay free — no licence fee, regardless of how many audits you run.

Flow

From the invite to expired access.

  1. Step 01

    Receive the invitation

    The tenant invites you by email — with a validity date and a preview of the released evidence pack.

  2. Step 02

    Activate access

    Create a free auditor account or use an existing login — permanently without fees. Two-factor authentication is mandatory.

  3. Step 03

    Work the audit

    Review evidence, assess controls, record findings, and communicate with the auditee team.

  4. Step 04

    Access ends automatically

    After expiry or revocation, access is blocked — every portal action remains traceable in the audit trail.

Security

Traceable for procurement and audit leads.

External auditors do not receive tenant-admin access. Every grant is audit-specific, time-limited, and revocable — with logged portal access.

  • Auditor accounts for external assessors are permanently free
  • Read-only evidence library with optional watermarked download
  • Mandatory 2FA for every auditor account
  • Several external auditors in parallel per audit
  • Evidence-pack preview before the invitation is sent
  • Access log as PDF for compliance evidence
  • 100% made in Germany · hosted in the EU · German data residency

For tenant admins

You manage auditor access in the audit module: invite, define the evidence pack, optionally release risk and asset context, extend, or revoke.

Module
Audit programme
Plan (tenant)
Starter+
Auditor account
Free · permanent
Portal
Dedicated auditor portal
Audit module in detail

Already invited as an auditor?

Sign in to the auditor portal or activate access from the link in the invitation email. Your auditor account is permanently free.