A scan is a snapshot. Audits ask for a film.
Run the open-source framework and you get an answer about today: 412 passed,
18 failed, here is how to fix them. That answer is genuinely useful, and it is
also gone the moment the next run overwrites it.
The questions that actually cost you time are historical ones. Was this
exclusion in place during the incident window? When did that policy stop
requiring MFA? Can you show a reviewer twelve months of evidence that the
control held? A folder of HTML reports on a share drive is not an answer to
any of those.
Aura Cloud is the layer that keeps them. Every run is stored, indexed, and
diffed against the one before it.