Security Questionnaire
The answers a vendor-security review usually asks for, pulled from our Security and DPA pages into one page you can print or save as a PDF.
This is a self-service summary, not a substitute for reading the full Data Processing Agreement or Security page it's drawn from, links to both are at the bottom.
What does AuditRails do with our data?
AuditRails is a tamper-evident audit logging service. As a processor, we store the audit-log events our customers send us via SDK/API: we don't inspect, classify, or use that content for any purpose other than storing, indexing, and returning it to the customer that sent it.
Where is our data stored?
Audit-log data is stored in AWS eu-central-1 (Frankfurt, Germany) by default: an EU-first choice on every plan. The application and database layer runs on self-hosted infrastructure on Hetzner, also EU-based.
Encryption
- In transit: All public traffic, the SDK, the dashboard, and this website, is served over TLS with automatically renewed certificates. There is no unencrypted path from your SDK to our ingestion API.
- At rest: Your audit logs' durable copy in S3 is encrypted at rest with AWS KMS (SSE-KMS).
How is our data isolated from other customers?
Every API key maps to exactly one tenant. Every database query, every S3 path, and every cache key enforces tenant isolation at the query layer itself, not as an application-level convention. There is no code path that can return one organization's data to another.
How long is our data retained?
For the term of the subscription plus the applicable retention period.
Audit logs are written to S3 with Object Lock in Compliance mode, not Governance mode. That distinction matters: in Compliance mode, no one, including AuditRails administrators and AWS' own root account, can shorten a retention lock or delete a log before it expires. The default retention window is seven years.
What's the backup and recovery posture?
We run nightly backups of PostgreSQL and Cassandra to a separate, dedicated storage location. Restore isn't just scripted, it's tested: our most recent drill (2026-08-25) restored both databases from backup and confirmed an exact row-count match against live data.
What happens if there's a breach?
AuditRails will notify the Controller within 48 hours of becoming aware of a Personal Data breach. Notification will include: nature of the breach, categories and volume of data affected, likely consequences, and measures taken to mitigate.
Report a suspected security issue to security@auditrails.io, see our full disclosure policy for scope and response times.
Can we verify the integrity claims ourselves?
We publish an open-source command-line tool that independently recomputes your audit log's hash chain and confirms it hasn't been tampered with. It doesn't call our API and doesn't trust our infrastructure, it only trusts the math.
Which compliance frameworks does this support?
All 8 supported frameworks, including DORA, GDPR, NIS2, ISO 27001 and the EU AI Act, are active and bundled per plan tier, not sold as separate add-ons.
We're actively preparing for a SOC 2 Type II audit. We haven't started the formal audit process yet, and we'd rather say that plainly than leave you guessing.
Subprocessors
| Sub-processor | Service |
|---|---|
| AWS | Amazon Web Services, S3 (WORM audit log storage) and SQS (queueing) only. |
| Hetzner | Hetzner, hosting for our application servers and databases. |
| Stripe | Stripe, payment processing. |
| Resend | Resend, transactional email. |
| Sentry | Sentry, error tracking. |
| Plausible | Plausible, cookieless website analytics on this site only. |
| MaxMind | MaxMind, geo-IP enrichment for logged events. |
| Cloudflare Turnstile | Cloudflare Turnstile, bot protection on our public contact and registration forms. |
AuditRails will notify the Controller 30 days before engaging a new sub-processor. The Controller may object within that period.