Immutable Audit Engine
An append-only, tamper-evident record of every security-relevant event: not just changes, but privileged reads, searches, exports and denied authorizations. Each entry carries the actor, action, resource and scope, a trusted timestamp, reason, outcome, redacted before/after, session and device references, approval evidence and correlation IDs. Records are hash-chained, secrets and PII are never stored, and deletion is only ever a governed, lawful, audited redaction — never a silent erase.
Storage is append-only and access-restricted. Any attempt to update or delete an audit record is itself blocked and recorded. Lawful deletion requests never break the chain: they are governed, require a legal basis, respect each category's minimum retention floor, and result in field-level redaction rather than removal.