An audit is only as good as the evidence you present. A folder full of screenshots convinces no BSI C5 auditor – a signed, cryptographically verifiable evidence bundle does. The SecTepe platform (SecTepe.Comm) generates exactly that: monthly, automated, and with proven data residency.
Monthly Signed Evidence Bundles
Every month a Cosign-signed evidence bundle is generated and stored in an Object-Lock bucket in COMPLIANCE mode (35 days) – tamper-evidently preserved. An export script builds the bundle, a verify script checks it (SHA-256 plus keyless Cosign). The auditor can thus not only see the content but also prove that it is unchanged since generation.
What Belongs in the Bundle
The contents map directly to C5:2020 criteria and include, among others:
- C5 and ISO 27001 SoA, risk register, asset inventory, and CAPA,
- records of processing activities, DPAs, supplier and sub-processor registers,
- data-residency attestation and internal audit log,
- all 24 written policies, configuration baselines (kube-bench, lynis, trivy, pgaudit),
- SBOM collection, pentest reports, and live state of Kyverno PolicyReports, NetworkPolicies, and Velero.
Data-Residency Attestation: Where the Data Really Lives
Additionally there is a written data-residency attestation (C5:2020 BC-01..04, GDPR Art. 44 ff.): all platform data resides in Frankfurt (IONOS DC FRA-1), backup replicas in Berlin (DC BER-1) – each row with a configuration file as evidence. A dedicated section covers jurisdiction and the CLOUD Act: applicable law Germany, no US sub-processors for personal platform data; optional US providers only upon explicit activation by the tenant, secured via SCCs and a Schrems II TIA.
The Path to the C5 Attestation
The C5 audit scheme (IDW PS 951 / ISAE 3402) first foresees a Type 1 attestation, then Type 2 after six months of operational evidence. C5:2020 comprises 17 areas with 121 base and additional criteria and is complementary to ISO 27001:2022 – not a replacement. This very sovereignty and evidence discipline runs through the entire platform, from supply-chain hardening to the EU-native GRC work in SecTepe.Core.
Conclusion
Monthly, signed evidence bundles and a proven data-residency attestation turn BSI C5 audit readiness from a statement of intent into a verifiable fact. For customers with KRITIS, government, or sovereignty requirements, that is the difference between "we are secure" and "we can prove it".