Guide

Informational

What an evidence pack is

An evidence pack is the signed PDF an assessor reads. Generate is not built. This page lists packs once they exist. Tagnovo does not certify.

Last reviewed September 2026.

The screen this guide means

“Evidence packs” is the Manifest tab with that name. It is not Script inventory and not Pages that take card details. The block below is that screen.

This is Manifest → Evidence packs.

Evidence packs

No packs yet. No pack has been written. That is not the same as an empty inventory. Generate stays off until it can write a signed PDF from the record.

What is in a pack

Explanation only — not this workspace's rows. A pack is generated from the record. Nothing written by hand.

The inventory
Every approved script, the reason given, who approved it, and when
Every check
Timestamp, page, what was seen, and how it was seen
Every change
What changed, when, and who reviewed it
Headers
Security headers as the customer's browser received them
Fingerprint
A checksum printed on the cover, so anyone can prove the file was not edited

What this is for

An assessor, a QSA, or the acquiring bank may ask for a file that shows every script on pages that take card details, why it was allowed, who signed that, and whether anything changed later. That file is the evidence pack: a generated PDF for a period, with a checksum on the cover so anyone can prove it was not edited.

PCI DSS 6.4.3 wants a signed inventory — a written reason and a named person, not a list a system invented. 11.6.1wants change detection of scripts and security headers as the customer's browser received them. The pack is meant to be that record for one period. We keep it. We do not certify compliance and nothing here is an assessment.

What is in a pack

Explanation of the intended file — not numbers from your store. A pack is generated from the record. Nothing is written by hand.

The inventory
Every approved script, the reason given, who approved it, and when
Every check
Timestamp, page, what was seen, and how it was seen
Every change
What changed, when, and who reviewed it
Headers
Security headers as the customer's browser received them
Fingerprint
A checksum printed on the cover, so anyone can prove the file was not edited

Why Generate does nothing

The button is off on purpose. This page can list packs that already exist. The step that writes a PDF, stores the checksum, and adds a row is not built. A named sign-off for the period (the attestation) is not built either.

An empty list means no pack has been written. It does not mean the inventory is empty. Approving scripts does not create a pack.

What you do until Generate ships

  • Approve third-party scripts on Script inventory, with a written reason and a named person. A pending row never appears in a pack as authorised.
  • Declare checkout and cart paths onPages that take card details.
  • You cannot download a Tagnovo pack for an assessor yet. Do not treat this tab as a report you can hand over.

Open the screen this guide means

Generate is not built. This page lists packs once a signed PDF exists. We do not certify.

Evidence packs

All guides · What a scan covers · Watch the store