FAQS
Controls are mapped to SOC 2 Type II, ISO 27001, GDPR, HIPAA, PCI-DSS, GLBA, FINRA and NERC CIP, with industry-specific additions where relevant.
Every view, edit, download, permission change, workflow step and AI action — with actor, timestamp and context — in an append-only record.
No. Entries are cryptographically chained and anchored with blockchain-backed timestamps, so any alteration breaks the chain and is detectable.
Schedules run automatically per regulation and document type — archive, flag for review or crypto-shred on schedule — with legal-hold override.
Filter the audit trail by record, user or date range and export the evidence directly. What used to be a manual reconstruction becomes a query.
Yes. Scoped, time-limited auditor roles give visibility into exactly the evidence they need and nothing else.