Evidence that was never
yours to edit.
The audit log is database-immutable and hash-chained — tampering is detectable, exports are signed. Audit packs generate from live data, and GDPR rights are built-in flows, not projects.
Immutable by the engine
Not a policy. A database trigger.
Updates and deletes on the audit log are rejected by the database itself. Every record carries a cryptographic link to its predecessor; the chain is verifiable on demand and exports are signed.
- Hash-chained records — verify the chain any time
- Every sign-in, decision and write recorded — and every configuration change made through the staged-diff surface, which is where the product puts them
- And every change to the governance configuration itself — approval rules, SoD rules, review rules, reviewer chains, masking rules. Who loosened the review interval is a query, because the change history of the review regime is the foundation under every review it produced
- Free-text search on the trail — "everything that mentions Sofie Bakker" is a search box, not a filter puzzle. And the export takes your filters with it: the file's first line is a signed manifest naming the filter set it was drawn with, so "the evidence, as the screen showed it" is a property of the file, not a promise
- Point-in-time answers: "why did X have Y at moment Z?" — replayed for one person, one entitlement or a whole connected system. The replay reads the recorded events, so it states its own reach instead of guessing past it: how far back the record goes, whether the page was truncated, and, on a person’s Recent view, how many grants it cannot account for. Access that an import writes straight into a target does not pass through the trail today, and we would rather name that than hand an auditor a confident empty hand
- Even deleting an entire tenant leaves the trail standing — the audit history is deliberately kept out of the purge, on the Art. 17(3)(b) retention ground
Audit season, compressed
What your auditor asks for, generated.
Pick a framework and a date range: SOX, ISO 27001 Annex A.9, HIPAA §164.312, GDPR Art. 32, the joiner-mover-leaver lifecycle, or time-boxed privileged access — a ZIP with indexed evidence and framework citations. GDPR Art. 17 erasure and Art. 20 portability are built-in, self-service flows.
- Ten audit-pack templates, framework-cited, from live data — SOX, ISO 27001 Annex A.9, HIPAA §164.312, GDPR Art. 32, DORA Art. 9, NIS2 Art. 21, SOC 2 CC6 and the EU AI Act / ISO 42001 agent pack, plus lifecycle and privileged-access evidence
- Every pack is signed twice over the same bytes. The HMAC is ours. The second signature is ECDSA P-256 with a per-tenant key whose public half we hand out — so your auditor verifies the pack without us, with a verifier that ships inside the pack itself: a standalone script, signed along with the data it checks, that imports nothing from our platform. Your auditor unzips, runs it against the published public key, and needs nothing further from us — not a download, not an account. The public keys sit on a card in the product, and a returned pack can be re-verified by upload, years later, under the key that signed it. Strip the second signature and the first one notices, because it is declared inside the manifest it signs
- Compliance posture control by control against ISO 27001, DORA, NIS2 and SOC 2 — and it refuses to flatter you: a control nobody attested reads not-assessed, never implemented. The coverage percentage counts only what someone put their name under, with the evidence reference on the attestation and the change on the trail. A fresh tenant scores honestly low, which is the only score worth improving
- An audit is a thing with a name, not a folder of downloads. Open an engagement — auditor, firm, scope, dates — and every pack and every report run produced for it binds to it. The Delivered list is then what they actually received: each row carries the SHA-256 of the artefact and, for an evidence pack, the key that signed it. Nothing was back-filled into that list when it shipped, because once written a guess and a record look the same
- GDPR export and erasure as flows — the erasure preserves the legally-required audit history. And an Art. 15 request is answered with a dossier, not a mail thread: the person asks for their own data from their own profile, and what comes back is a signed ZIP — a readable index that also names what is deliberately not in it, one file per section, and the same two signatures an evidence pack carries, so whoever received it can show a regulator that it is what was sent. Your side gets the same artefact: fulfilling a subject request now leaves proof of what was handed over, instead of a free-text note saying that something was
- Scheduled reports: a curated catalog rendered to XLSX or PDF, delivered on a schedule. A grant report scoped to a single system can be replayed to a past date — "this connector, as of 31 December" — and a question the replay cannot answer honestly is refused with the reason, never quietly widened to the whole tenant
A report opens, it is not ordered. A report is a view first. Server-side paging, sort and search, filter chips that state the filter that was actually resolved, a sentence saying whose scope you are looking at, and drill-through per cell. The same saved filter drives the export, so the file and the screen cannot disagree — including the masking, which now holds in the file as well. Caps are stated before you click: this format holds N, you are exporting M. You narrow it where you stand — columns and conditions on the view itself — and every reading of that question follows the edit: the rows, the summary, the caps and the file. Switch to summary and the group counts add up to the list underneath, because they are three readings of one query rather than three queries. And the header says how much of the population you are looking at — "96 of 2,339 in scope" — from a second, unfiltered count, not from arithmetic.
See audit evidence generated on your own data.
A 30-minute kickoff connects your HR feed and one system — working POC the same day.
Bring your HR feed plus one system you trust us to read — that is all the kickoff needs. No NDA, no second call with a sales engineer, no procurement form.