← Q&A knowledge base
Obligations and evidence Updated 2026-08-28

How does Maditon handle evidence for an audit?

Evidence files are uploaded against an AI system and attached to the specific checklist items they substantiate, so each obligation carries its own proof. Everything can be downloaded in bulk as a ZIP — per system, or the whole organisation's evidence at once under EU Data Act Article 4.

The problem evidence handling solves is not storage. It is the link between a document and the obligation it satisfies.

You upload a file against an AI system, then attach it to the checklist items it substantiates. One document can back several obligations; one obligation can be backed by several documents. When an auditor asks why you consider a particular requirement met, the answer is a specific file attached to that specific item, not a folder.

Files can be updated, detached and deleted, and every attachment is part of the record the audit log covers.

Getting it out is deliberately unrestricted. You can download all evidence for one system as a ZIP, or the entire organisation’s evidence archive in a single request. No support ticket, no waiting period — the EU Data Act treats friction on the way out as a form of lock-in, and building it would be an odd choice for a compliance vendor.

Related API endpoints

POST /api/evidence bearer

Upload an evidence file

PUT /api/compliance/checklist-items/{item_id}/evidence/{evidence_id} bearer

Attach an evidence file to a checklist item

GET /api/evidence/systems/{system_id}/download-all bearer

Download all evidence for a system as a ZIP archive

GET /api/data-act/evidence bearer

Download all evidence files as a ZIP archive (EU Data Act Article 4)

Base URL https://api.maditon.app · full specification at openapi.json

Regulation references

Read next

A free Solo account runs a real classification on one of your own systems — no card, no sales call.

Run a free classification