Skip to content

An approval trail you can hand to an auditor

A record of who approved which change, and against which version of the content. Each entry carries a hash. The hash shows the record has not been edited since.

Your audit trail writes itself while you work.

Verifiable by your auditor

Governed changes land in a hash-chained ledger using plain SHA-256 with no secret key, so your auditor can re-verify its integrity from the export with their own tools.

Approval is the gate

Every governed action is staged as a plan. It is applied only after a person approves it. The approval is the event on the record.

  • A person approves before anything is applied
  • The plan, the approver and the timestamp are recorded together
  • AI proposes, and a person applies, in every tool

The record proves it was not edited

A log anybody can add to is a log an auditor discounts. Entries are hashed by content and chained together. A later edit no longer matches.

  • SHA-256 content hashing on the ledger
  • The whole ledger exports, and the copy is yours to keep
  • The record keeps the shape of a secret, never the value

Identity you already trust

Sign in with a managed username and password, plus a required authenticator tool. Or use SAML 2.0 against your own identity provider, one connection per organisation.

  • Multi-tenant SAML: one organisation’s sign-in cannot mint another one’s session
  • Access ends on the next request
  • Role re-read on every request, never carried in the token

What changes

Evidence you can hand over

A record with a hash, exportable, naming the approver.

Audit ledger

One place to look

Every governed tool writes to the same trail.

Log

Where the mapping stops

Which checks map to which control, and where the mapping stops.

Control Frameworks

Read the control mapping first

It says which frameworks are covered by real checks, and which are not.