FAQS
It is the work of producing evidence that your controls operated as documented over a period. Where the evidence lives in an append-only ledger, that reporting becomes a filtered export rather than a manual reconstruction from several systems.
Actor, action, timestamp and context for every view, edit, download, permission change, workflow step and AI action, in a record that cannot be edited after the fact. If any of those are missing, the auditor has to take a system's word for it.
Not on its own - anyone with administrative rights can alter a database log. Entries here are cryptographically chained and anchored with blockchain-backed timestamps, so an alteration breaks the chain and an auditor can verify integrity independently.
It depends on the regime - FINRA 17a-4, FDA 21 CFR Part 11, HIPAA and SOX all set different periods. Retention schedules run automatically per regulation and document type, with legal-hold override, so multiple regimes can apply to the same estate.
Yes. Controls are mapped to SOC 2 Type II, ISO 27001, GDPR, HIPAA, PCI-DSS, GLBA, FINRA and NERC CIP from one interface, so one set of evidence answers several frameworks instead of being assembled separately for each.