Platform
Audit & evidence
Immutable logs and exportable compliance evidence.
Log model
Every policy decision produces an immutable, content-addressed log entry in the audit ledger. Entries include the full evaluation context: inputs, outputs, policy version, decision, and identity.
{
"id": "evt_01HQ...",
"ts": "2026-04-24T18:21:03.244Z",
"policy_version": "v4.21#a91c",
"decision": "deny",
"rule": "block-pii-egress",
"identity": { "user_id": "u_92...", "purpose": "support" }
}Compliance exports
Pre-built exports for SOC 2, HIPAA, and EU AI Act. Auditors can be granted read-only, time-scoped access without an engineering ticket.
Tip · Auditor mode
Generate a signed evidence bundle for any time window in under a minute.
Retention
Default retention is 7 years. Customer-controlled keys (CMK) are required for retention beyond 1 year. Logs can be replicated to your SIEM in real time.
Was this page helpful?