Evidence, not screenshots.
An auditor does not take a screenshot. They take a file, and then they ask where each field in it came from.
A styled Excel or CSV export
The problem
"Just export it to Excel" is how every audit ends.
And then the export turns out to be a CSV with no headers, dates stored as text, broken Hebrew, and somebody editing it by hand before it is sent. Any one of those three makes the file worthless as evidence.
| Export | What's in it | For |
|---|---|---|
| Host inventory | Every row currently filtered on screen, with due dates | Infrastructure |
| System workbook | Score, its terms, and every host by status | The system owner |
| Vulnerability register | By patch: CVEs, hosts, systems | Security |
| Audit log | Every change: who, when, what changed | Internal audit |
- 01
What you see
The export takes what is filtered on screen, not the whole table. If you filtered to one quarter, that is what comes out.
- 02
Styled Excel
A sheet with a frozen header, an autofilter, real column widths, and dates that are genuine dates so they sort. The sheet opens right-to-left.
- 03
Per system
From the recommendations page you can export one workbook for a single system: its score, the terms behind it, and every host with its patch status.
- 04
Mail to the owner
The same workbook goes to the system owner as an unsent Outlook draft they review, edit and send themselves. Regulaxy never sends it for them.
Formats that open without Regulaxy.
- Excel
- CSV
- Outlook
- The audit log
A file, and a log row
The file is the evidence. The log row is the proof of when it was produced and from what — and both survive deletion of the event they describe.
Show us your worst window.
Bring the one that keeps slipping. Thirty minutes, your estate, no slides.