own
Tamper-Evident Audit Log + Evidence Ledger
Every gate decision on a hash chain your auditor can verify.
What you get
Chained by the database
Each audit row carries the hash of the one before it, computed inside Postgres. An edited or deleted row shows up as a broken chain — the log is tamper-evident, not just append-only by convention.
Never a false pass
Every deploy gate — dependency, code, license, compliance and live posture — records passed, blocked, advisory or error. A gate that could not run is recorded as an error, never as a pass.
An evidence ledger for auditors
Business plans export a signed ledger of every deploy: which gates ran, what they decided, and which deploys shipped fully gated — the question a SOC 2 auditor actually asks.
How it works
- 1
Every sensitive action and every gate decision writes an audit row.
- 2
A database trigger links each row to the previous one by hash.
- 3
Verification replays the whole chain in the database and reports any gap or edit.
- 4
Owners and Admins on Business plans export the evidence ledger as signed JSON or PDF.
What this check inspects
Project, key, member and setting changes — field names recorded, secret values never.
Each deploy's gate verdicts, with scope: full, partial or failed-open.
Breaks in the chain: edits, deletions or gaps.
What it means when this fails
An audit log that an admin can quietly edit proves nothing. When an incident or an audit asks what was checked before a release shipped, the answer has to survive someone who wishes it said something else.
Questions
- Is it tamper-proof?
- Tamper-evident: a change cannot be hidden, because the chain breaks. That is the property auditors rely on.
- Which plans include it?
- The audit log runs for every organization; the exportable evidence ledger is part of Business and above.
Related features
Compliance Readiness Mapping
SOC 2, HIPAA, and GDPR controls mapped to your deploy — with a PDF export.
Learn moreGoverned Safety Rules
The rules that judge your code are versioned and change only through a reviewed PR.
Learn moreSecurity Scan on Every Deploy
Catch RLS gaps, secret leaks, and CVEs before your app is reachable.
Learn more