New signups are temporarily closed.Existing customers can still sign in. Contact us to be notified when we reopen.
Skip to main content
Documentation

Governance & evidence

Evidence vault & audit trail

Everything else in the platform serves one purpose: being able to prove what you did and when. The evidence vault and the audit trail are where that proof lives.

Transcript

Everything in this platform ultimately serves one purpose: being able to prove what you did, and when.

This is a different mechanism from the evidence vault: nothing to upload, the platform writes it automatically on every action, with its actor and timestamp. It now carries a cryptographic hash chain too, so verifying it proves the log itself hasn't been altered or deleted.

Narrow the log by resource type, outcome, or a date range before you export, and the file you download is exactly that slice, not the whole history. CSV for a spreadsheet, JSON for feeding into your own tooling.

For AI systems, the AI Act's Article 12 requires automatic recording of events over the system's lifetime, and its Article 26 requires deployers to keep those logs for at least six months.

The evidence vault is different again: a file you actually upload, attached to a system or to a specific tracked obligation. The policies, test results, contracts and approvals that turn a ticked checklist box into something a regulator can inspect. Flag a corrective action as requiring evidence and it cannot be marked resolved until one is attached.

A checklist item with no evidence is a claim. A checklist item with a dated, attributable artefact behind it is a demonstration, and demonstration is the standard the law actually sets.

Why this is required

GDPR Article 5(2) makes accountability an obligation in itself: you must be able to demonstrate compliance, not merely achieve it. A control that operated but left no trace is, evidentially, a control that cannot be shown to have operated.

The AI Act builds the same expectation into the system. Article 12 requires high-risk systems to technically allow automatic recording of events over their lifetime, ensuring a level of traceability appropriate to the intended purpose. Article 19 requires providers to keep those logs where they are under their control.

Article 26(6) puts a floor on retention for deployers: keep the logs automatically generated by the high-risk system, to the extent they are under your control, for a period appropriate to the intended purpose and at least six months, unless other law provides otherwise.

Article 32(1)(d) of the GDPR requires a process for regularly testing, assessing and evaluating the effectiveness of your security measures, which again presumes records showing that testing happened.

The practical distinction is simple. A checklist item with nothing attached is a claim. A checklist item with a dated, attributable artefact behind it is a demonstration, and demonstration is the standard the law sets.

What EuroCompliant does

The audit trail records actions taken in the platform with actor and timestamp, giving you an attributable history of who changed what.

Every audit entry is chained to the one before it with a cryptographic hash, so any edit, deletion or reordering of a historical entry breaks the chain. Settings > Audit lets an admin verify the chain is intact on demand, rather than trusting that the log was never tampered with.

The evidence vault holds the artefacts behind checklist items (policies, test results, approvals, contracts, screenshots and scan outputs) linked to the obligation each one discharges.

Evidence is dated, so it is possible to show not just that a control exists but that it was operating at the relevant time.

On Enterprise, generated PDFs can be signed and tied to a snapshot of this hash chain at the moment of generation (see Documentation & evidence generation). The two features share the same tamper-evidence, one for the log, one for exported documents.

Walking through it

1

Attach evidence when you complete an item

Not later. Reconstructing evidence months afterwards is where compliance programmes lose credibility.

Open /evidence →
2

Prefer dated, attributable artefacts

A signed policy with a date and an author beats an undated screenshot of a settings page.

3

Retain AI system logs for at least six months

The AI Act's Article 26(6) sets six months as the floor for deployers, and longer where the intended purpose or other law requires it.

4

Review the audit trail after incidents

The trail is what reconstructs the sequence of events when something goes wrong.

Open /settings/audit →

The law

Frequently asked

What counts as good evidence?

Something dated, attributable and specific to the obligation. A board minute approving a policy, a scan report with a timestamp, a signed processor contract, a training completion record. Generic vendor marketing material is not evidence of your control.

How long should we keep everything?

AI system logs: at least six months for deployers under Article 26(6). Technical documentation and conformity records: ten years under Article 18. GDPR records: for as long as the processing continues, plus your limitation period. Personal data inside evidence is still subject to storage limitation under Article 5(1)(e).

Related guides

Try it on your own systems

Everything in this guide runs in the live product. Start a free trial and follow along with your own data.

Start free trial