What an evidence pack is
An evidence pack is the signed PDF an assessor reads. Generate is not built. This page lists packs once they exist. Tagnovo does not certify.
Last reviewed September 2026.
The screen this guide means
“Evidence packs” is the Manifest tab with that name. It is not Script inventory and not Pages that take card details. The block below is that screen.
Evidence packs
No packs yet. No pack has been written. That is not the same as an empty inventory. Generate stays off until it can write a signed PDF from the record.
What is in a pack
Explanation only — not this workspace's rows. A pack is generated from the record. Nothing written by hand.
- The inventory
- Every approved script, the reason given, who approved it, and when
- Every check
- Timestamp, page, what was seen, and how it was seen
- Every change
- What changed, when, and who reviewed it
- Headers
- Security headers as the customer's browser received them
- Fingerprint
- A checksum printed on the cover, so anyone can prove the file was not edited
What this is for
An assessor, a QSA, or the acquiring bank may ask for a file that shows every script on pages that take card details, why it was allowed, who signed that, and whether anything changed later. That file is the evidence pack: a generated PDF for a period, with a checksum on the cover so anyone can prove it was not edited.
PCI DSS 6.4.3 wants a signed inventory — a written reason and a named person, not a list a system invented. 11.6.1wants change detection of scripts and security headers as the customer's browser received them. The pack is meant to be that record for one period. We keep it. We do not certify compliance and nothing here is an assessment.
What is in a pack
Explanation of the intended file — not numbers from your store. A pack is generated from the record. Nothing is written by hand.
- The inventory
- Every approved script, the reason given, who approved it, and when
- Every check
- Timestamp, page, what was seen, and how it was seen
- Every change
- What changed, when, and who reviewed it
- Headers
- Security headers as the customer's browser received them
- Fingerprint
- A checksum printed on the cover, so anyone can prove the file was not edited
Why Generate does nothing
The button is off on purpose. This page can list packs that already exist. The step that writes a PDF, stores the checksum, and adds a row is not built. A named sign-off for the period (the attestation) is not built either.
An empty list means no pack has been written. It does not mean the inventory is empty. Approving scripts does not create a pack.
What you do until Generate ships
- Approve third-party scripts on Script inventory, with a written reason and a named person. A pending row never appears in a pack as authorised.
- Declare checkout and cart paths onPages that take card details.
- You cannot download a Tagnovo pack for an assessor yet. Do not treat this tab as a report you can hand over.
Open the screen this guide means
Generate is not built. This page lists packs once a signed PDF exists. We do not certify.