Governance & evidence
Evidence vault & audit trail
Everything else in the platform serves one purpose: being able to prove what you did and when. The evidence vault and the audit trail are where that proof lives.
Transcript
Everything in this platform ultimately serves one purpose: being able to prove what you did, and when.
This is a different mechanism from the evidence vault: nothing to upload, the platform writes it automatically on every action, with its actor and timestamp. It now carries a cryptographic hash chain too, so verifying it proves the log itself hasn't been altered or deleted.
Narrow the log by resource type, outcome, or a date range before you export, and the file you download is exactly that slice, not the whole history. CSV for a spreadsheet, JSON for feeding into your own tooling.
For AI systems, the AI Act's Article 12 requires automatic recording of events over the system's lifetime, and its Article 26 requires deployers to keep those logs for at least six months.
The evidence vault is different again: a file you actually upload, attached to a system or to a specific tracked obligation. The policies, test results, contracts and approvals that turn a ticked checklist box into something a regulator can inspect. Flag a corrective action as requiring evidence and it cannot be marked resolved until one is attached.
A checklist item with no evidence is a claim. A checklist item with a dated, attributable artefact behind it is a demonstration, and demonstration is the standard the law actually sets.
Why this is required
GDPR Article 5(2) makes accountability an obligation in itself: you must be able to demonstrate compliance, not merely achieve it. A control that operated but left no trace is, evidentially, a control that cannot be shown to have operated.
The AI Act builds the same expectation into the system. Article 12 requires high-risk systems to technically allow automatic recording of events over their lifetime, ensuring a level of traceability appropriate to the intended purpose. Article 19 requires providers to keep those logs where they are under their control.
Article 26(6) puts a floor on retention for deployers: keep the logs automatically generated by the high-risk system, to the extent they are under your control, for a period appropriate to the intended purpose and at least six months, unless other law provides otherwise.
Article 32(1)(d) of the GDPR requires a process for regularly testing, assessing and evaluating the effectiveness of your security measures, which again presumes records showing that testing happened.
The practical distinction is simple. A checklist item with nothing attached is a claim. A checklist item with a dated, attributable artefact behind it is a demonstration, and demonstration is the standard the law sets.
What EuroCompliant does
The audit trail records actions taken in the platform with actor and timestamp, giving you an attributable history of who changed what.
Every audit entry is chained to the one before it with a cryptographic hash, so any edit, deletion or reordering of a historical entry breaks the chain. Settings > Audit lets an admin verify the chain is intact on demand, rather than trusting that the log was never tampered with.
The evidence vault holds the artefacts behind checklist items (policies, test results, approvals, contracts, screenshots and scan outputs) linked to the obligation each one discharges.
Evidence is dated, so it is possible to show not just that a control exists but that it was operating at the relevant time.
On Enterprise, generated PDFs can be signed and tied to a snapshot of this hash chain at the moment of generation (see Documentation & evidence generation). The two features share the same tamper-evidence, one for the log, one for exported documents.
Walking through it
Attach evidence when you complete an item
Not later. Reconstructing evidence months afterwards is where compliance programmes lose credibility.
Open /evidence →Prefer dated, attributable artefacts
A signed policy with a date and an author beats an undated screenshot of a settings page.
Retain AI system logs for at least six months
The AI Act's Article 26(6) sets six months as the floor for deployers, and longer where the intended purpose or other law requires it.
Review the audit trail after incidents
The trail is what reconstructs the sequence of events when something goes wrong.
Open /settings/audit →The law
Accountability
The controller must be able to demonstrate compliance with the data protection principles.
Record-keeping
Automatic recording of events over the system's lifetime, ensuring traceability appropriate to its intended purpose.
Deployer log retention
Logs under the deployer's control must be kept for a period appropriate to the intended purpose and at least six months.
Security of processing
Including a process for regularly testing, assessing and evaluating the effectiveness of security measures.
Frequently asked
What counts as good evidence?
Something dated, attributable and specific to the obligation. A board minute approving a policy, a scan report with a timestamp, a signed processor contract, a training completion record. Generic vendor marketing material is not evidence of your control.
How long should we keep everything?
AI system logs: at least six months for deployers under Article 26(6). Technical documentation and conformity records: ten years under Article 18. GDPR records: for as long as the processing continues, plus your limitation period. Personal data inside evidence is still subject to storage limitation under Article 5(1)(e).
Related guides
Compliance checklists
How Articles 9 to 15 become tracked, owned, evidenced work rather than a document nobody reads.
Documentation & evidence generation
Generating Annex IV technical documentation, declarations of conformity and framework records from data you have already entered.
Automated Scanning: Continuous Telemetry and Scan Pipelines
How scheduled scan jobs, 12 scan engines and local PII scrubbing produce dated Article 10/15 evidence without moving data outside the EEA.
Agent Runtime Telemetry
Stream signed execution decisions from your autonomous-agent runtime firewall straight into tamper-evident audit evidence.
Cryptographic Assurance: Audit Chains and Document Signing
Sealed documents and a tamper evident audit trail, with a verification link anyone can open in a browser. No login needed.
Try it on your own systems
Everything in this guide runs in the live product. Start a free trial and follow along with your own data.
Start free trial