Tamper-evident audit trail
An append-only, hash-chained audit trail records questions, answers, sources, approvals and administrative actions. Security events can forward to your SIEM.
Provenance
Every answer carries citations to the approved documents it was grounded in, with the knowledge-pack version recorded.
Decision and approval records
Knowledge approvals, baseline changes and go-live gates are recorded with who approved what, when.
Evidence export
Evidence exports are designed for security review, internal audit and renewal decisions — usage counts and durations, never raw content by default.
Known limitations, stated plainly
- The audit chain is tamper-evident, not WORM storage. If your policy requires WORM, pair the export with your existing WORM store.
- Evidence demonstrates system behaviour; it is not a substitute for your own audit function.
These are architecture and control descriptions, not audit results. Current assurance status — implemented, tested, planned — is summarised in the Security & Trust Centre, and deeper material is available through the security architecture pack.