On provable records, audit evidence, and the design decisions behind Sigilbase. Subscribe with the Atom feed; there is no newsletter and no tracking of readers.
Start here · 18 July 2026
What a tamper-evident audit log is, how it differs from ordinary logging, and how hash chains and signed checkpoints turn records into provable evidence. The rest of this section builds on the ideas explained here.
18 July 2026
How to integrate an audit event ingestion API well: idempotency, batching, the outbox pattern, failure alerting and schema design that survives audits.
18 July 2026
Cryptographic audit log solutions compared, from managed services to open-source verifiable logs, and the questions separating provable from promised.
18 July 2026
How to implement provable audit logs: event schema, hash chains, Merkle checkpoints, signed proofs and independent offline verification, in build order.
10 July 2026
The audit log requirements of SOC 2, ISO 27001 and PCI DSS: events, integrity, retention and review, plus one design that satisfies all three.
10 July 2026
What the SEC's 2022 amendments to Rule 17a-4 changed, what the audit-trail alternative actually requires, and how to evaluate systems against either path.
10 July 2026
SOC 2 audit evidence from the engineering side, covering what auditors request, continuous collection, trustworthy records and a 90-day plan.