AuditRailsAuditRails

For software companies

Give every customer an audit trail they can verify themselves

Your customers are asking for immutable audit logs during procurement. Building that yourself is six to twelve months of work that earns you nothing. Embed AuditRails instead, and provision each customer with one API call.

Who this is for

Software companies whose own customers need a record that holds up under scrutiny.

Whistleblowing platforms

EU Directive 2019/1937 requires internal reporting channels to keep a durable, confidential record of every report and every follow-up, with access restricted to authorised staff. That is an append-only tamper-evident log with a restricted auditor view.

GRC and AI-governance tools

You verify that a company has audit logging. You do not want to build, store and defend the logs themselves for a decade. This is the layer underneath your controls.

Regulated vertical SaaS

Healthtech, fintech, legaltech. Your buyers raise immutable audit trails in security review, and a row in your own database is not an answer that survives the question.

Why an audit trail you host yourself is worth less

An audit log kept by the same system it audits proves very little. If you can write the records, you can rewrite them, and any auditor who thinks about it for a minute will say so.

When the trail is a cryptographic hash chain held by an independent third party, your customer can verify it without trusting you, and without trusting us either. The maths does the work. That is a stronger claim than you can make on your own infrastructure, and it is a reason to say who is underneath rather than hide it.

This is a co-branded arrangement. Your customers see that AuditRails keeps the trail, which is exactly what makes it independent. We do not white-label it away.

How it works

Three calls, then their events flow into their own chain.

1

Provision a customer

One call creates the customer as a fully isolated tenant, on the plan and compliance frameworks you choose for them.

2

Mint their key

You get an ordinary API key scoped to that customer. Send their events with it, from your own backend.

3

Hand them the proof

Auditor-ready reports, evidence bundles and a public verification endpoint, per customer, without you building any of it.

POST https://api.auditrails.io/v1/partner/customers
{
  "name": "Comune di Verona",
  "plan": "compliance_trails",
  "frameworks": ["gdpr"]
}

What every one of your customers gets

The same product a direct customer gets, isolated per tenant.

8 compliance frameworks

DORA, GDPR, NIS2, ISO 27001, SOC 2, the EU AI Act and more, with per-framework action catalogues enforced at ingest.

WORM storage

Every event lands in object storage under Object Lock. Not deletable by us, not deletable by you, not deletable by them.

Auditor-ready reports

Compliance reports and evidence bundles with a manifest of SHA-256 hashes, generated on demand over the API.

A partner console

Every customer in one list, with their usage, their frameworks and their keys, plus a rolled-up view of what you owe.

Webhooks, not polling

Signed callbacks when a report finishes, an export is ready, or a customer's hash chain fails verification.

SDKs in 4 languages

Node.js, Python, PHP and Go, plus a documented REST API and an OpenAPI spec.

Consultants, DPOs and advisory firms

You advise companies on NIS2, DORA, ISO 27001 or national access-logging rules. You do not have to integrate anything: you need something to hand a client that survives an inspection. Start here, then talk to us.

Get the DORA and NIS2 log checklist

What we guarantee to your customers

A reseller arrangement is only worth building on if the customer is not collateral in a dispute between us.

Real isolation, not a shared table

Each customer is a separate tenant with its own storage prefix, its own database partitions and its own hash chain. No customer's events are ever in another's chain.

Suspending you never stops their logging

If your partner account is suspended, your console and API stop. Your customers keep ingesting. A gap in an audit trail cannot be filled in afterwards, so we do not create one to settle an account.

Losing you never deletes their data

Delete your partner account and your customers' organizations survive as direct customers, with their trails intact.

They can verify without either of us

An offline verifier recomputes the chain from an export. Your customer can prove their trail is intact even if both of our companies disappeared.

Commercials

Partner pricing is per active end-customer, with an event allowance pooled across all of them rather than metered per customer. Active means a customer that actually logged something that month, so you never pay for an account nobody has used.

The right numbers depend on how many customers you have and how much they log, so we agree them with you rather than publishing a table. Tell us roughly how many customers and what they do, and we will come back with something concrete.

Buying for your own company rather than reselling? That is standard pricing.

Tell us what you are building

A short description of your product and roughly how many customers you would onboard is enough to start.