One place where compliance evidence is submitted, reviewed and proven.

StackWeaver is a web platform for regulated companies and the firms that audit and advise them. Clients upload evidence once; partners review and sign it off; every decision is recorded in a chain that shows if anything was changed later; and the whole set can be exported as an evidence package that an auditor, bank or investor can check on their own.

Last updated 2026-10-03 · Describes features that are live today

Client portal walkthrough
Partner portal walkthrough

Four parts, one evidence record

Client portal

For: Regulated companies (fintechs, PSPs, SaaS)

  • →Compliance posture, findings and remediation tasks in one place
  • →Evidence vault: every upload is fingerprinted (SHA-256) and stored as an Evidence Object with an ID such as EO-2026-000205
  • →Regulatory updates and reports for your engagement

Partner portal

For: Audit, compliance and delivery firms

  • →Run client engagements and see your portfolio
  • →Review evidence: accept, or reject with a written reason
  • →Sign off accepted evidence; signed evidence can no longer be edited
  • →Referral tracking and verified payouts

Evidence record

For: Everyone who relies on the evidence

  • →Each review and sign-off is written to an append-only decision record, chained with SHA-256 per workspace
  • →One click re-checks the chain, so anyone can see whether a past decision was altered
  • →New versions supersede old ones instead of overwriting them

Evidence packages

For: Auditors, banks, investors, regulators

  • →Export a workspace as one ZIP in the StackWeaver Open Evidence Format v1.0: evidence records, decisions, files and a manifest of hashes
  • →The format is documented and Apache-2.0 licensed, so a recipient can check a package without a StackWeaver account

Read the definitions: Evidence Object · Evidence Package · Audit trail · Evidence lifecycle.

How client data is protected

  • →Each client and partner works in its own workspace; the database itself enforces who can read what (row-level security)
  • →Sign-in through Clerk; every server request verifies the session
  • →Connector credentials are kept in an encrypted vault, never in browser code
  • →Bank details are held by Paystack; StackWeaver stores only the last four digits

More on the Trust Center. An independent penetration test is planned; we will publish the date when it is complete.

What is coming next

  • ○Team invitations and roles inside a workspace
  • ○A reviewed African control library (CBN, NDPA, SOC 2, ISO 27001, PCI DSS mappings)
  • ○Evidence requests from auditors to clients
  • ○A dedicated auditor view of an evidence package
  • ○Public release of the free package checker

These are not live yet. We list them so you can plan, not as a promise of dates.

Free tools and guides

Score your CBN AML readiness, estimate the cost of delay, or measure your trust maturity, then read the dated regulatory guides.

Common questions

Is StackWeaver a software platform or a consultancy?

Both. StackWeaver runs a web platform (a client portal and a partner portal) and pairs it with compliance engineering work. The platform holds the evidence, the reviews and the decision record; the engineering work produces the evidence.

What is an Evidence Object?

A single piece of compliance evidence (a file, a configuration export, a report) recorded with an ID, a SHA-256 fingerprint, who submitted it, when, for which workspace, and its review status. See the Evidence Object page for the full definition.

Can an auditor check our evidence without logging in?

Yes. You can export an evidence package in the StackWeaver Open Evidence Format v1.0. It contains a manifest of SHA-256 hashes and the chained decision record, so the recipient can check that nothing changed after export.

Which frameworks are covered?

Engagements cover CBN AML/CFT, NDPA, SOC 2, ISO 27001 and PCI DSS. Inside the platform, the built-in control library currently ships SOC 2; the reviewed African control library is in development.

Does using StackWeaver make us compliant or certified?

No. StackWeaver helps you produce, organise and prove evidence. Certification and regulatory decisions are made by independent auditors and regulators.

How do I get access?

Accounts are created during onboarding: clients through an engagement, partner firms through the partner programme. Contact us to start.