Self-hosted audit logging
that auditors actually trust

A tamper-evident audit trail, intelligent search, UEBA anomaly detection and compliance reporting — all running on your servers. SOC 2 / ISO 27001 / GDPR-ready out of the box. No per-seat SaaS fees, no data leaving your perimeter.

Get a License See features
Self-hosted · own your data Tamper-evident hash chain GDPR right-to-erasure built in Spring Boot 3 + Vue 3 Single JAR + PostgreSQL

Why teams pick Log Audit Platform

Most logging tools are built for engineers debugging prod. Log Audit Platform is built for the moment an auditor, regulator or customer asks: "prove what happened, and prove it wasn't changed."

INTEGRITY

Tamper-evident by design

Every record carries a hash chained to the previous one. Any retrospective edit breaks the chain and is caught by the built-in verification report.

PRIVACY

GDPR from day one

Right-to-erasure and data-subject export are first-class: anonymize a user's or IP's records without breaking the hash chain; export is masked by default.

SEARCH

Find anything, fast

Full-text + structured query plus an expert query builder. Aggregate by actor, asset, action, geo or result; save and share views.

DETECT

UEBA anomaly alerts

Behavioral rules flag outliers — impossible travel, off-hours admin, brute-force patterns — and notify via email / in-app.

COMPLIANCE

Reports & evidence packs

Pre-built compliance templates generate audit reports and a downloadable evidence ZIP for SOC 2 / ISO 27001 control evidence.

RBAC

Separation of duties

Distinct Auditor / Security-admin / Compliance roles. The person who configures sources is not the person who signs off the report.

Own your data. Deploy in minutes.

One Spring Boot 3 application (Java 17+) ships the API and the Vue 3 admin UI in a single runnable JAR. Point it at PostgreSQL, set a few env vars, done.

  • Single deployable JAR — no separate frontend build to babysit
  • Secrets via environment variables, never hardcoded
  • Ingest via Syslog and configurable sources; map to a normalized schema
  • Docker Compose included for a 2-minute local stand-up
  • Runs on-prem, in your VPC, or air-gapped

What you get in the package

What ships depends on your tier:

  • Single / Business: prebuilt runnable JAR + docker-compose.yml + .env.example + schema SQL — no source code
  • Enterprise / OEM: full backend & frontend source + Dockerfile + white-label + redistribution license
  • Email support for the license term

Pricing

One-time payment, no subscription. Single & Business ship a ready-to-run package (no source); Enterprise / OEM include the full source code. Checkout is handled securely by Waffo Pancake (Merchant of Record — cards, Apple/Google Pay + Alipay/WeChat; global tax/VAT handled for you, payouts to your bank/Alipay).

Single Instance

$199 / one-time

For one production deployment — runtime, no source.

  • Packaged runtime (no source code)
  • Commercial license — 1 instance
  • 6 months updates
  • Community email support
Buy — $199

Business

$699 / one-time

Most teams. Multiple instances — runtime, no source.

  • Packaged runtime (no source code)
  • Commercial license — up to 5 instances
  • 12 months updates & priority support
  • GDPR + compliance report modules
  • Onboarding assist (1 session)
Buy — $699

Enterprise / OEM

$2,499 / one-time

Resell or embed in your product.

  • Full source code + white-label rights
  • OEM / redistribution license
  • 24 months updates & support
  • Optional external WORM anchoring (RFC 3161)
  • Custom integration support
Buy — $2,499

Prices are set in Waffo. Need a different split (e.g. per-seat, annual maintenance)? Just ask.

Optional annual maintenance ($39 / $139 / $499 by tier) extends updates & support — renew anytime; expiry never locks you out of the running product.

FAQ

Is this a SaaS or self-hosted?

Self-hosted. You run it on your own infrastructure. There is no recurring per-seat fee and your audit data never leaves your perimeter.

What are the runtime requirements?

Java 17+ and PostgreSQL 12+. The app is a single Spring Boot JAR that also serves the Vue 3 admin UI. Docker Compose is included.

How does the tamper-evidence work?

Each record stores a hash of itself chained to the previous record's hash. A verification report walks the chain and flags any broken link — so post-hoc edits are detectable. (For stronger guarantees, anchor periodic roots externally; an OEM hook is available.)

Does it handle GDPR?

Yes. Right-to-erasure anonymizes a data subject's records (by account or IP) without breaking the hash chain, and data-subject export plus masked exports are built in.

What license do I get?

A commercial source license. You may use and modify the code for your own deployments; resale/redistribution of the source requires the Enterprise/OEM tier.

Is support included?

Yes — email support for the license term (6–24 months by tier), plus optional onboarding for Business and above.

Can I see a demo?

Yes — deploy the included Docker Compose locally, or request a recorded walkthrough via the contact link above.

How do I activate after purchase?

Self-hosted and simple. After checkout we email you an activation code (a signed key). Open System > Configuration > License, copy your server's machine code, send it to us, and we issue a code bound to that server. Paste the code back and it activates instantly — no external server, no phone-home. The code is machine-bound, so moving to a new server just needs a quick re-issue.

Can we use this for SOC 2 or ISO 27001 evidence?

Yes. The platform produces ready-to-use evidence packs for common access-control, logging and monitoring controls, plus a tamper-evidence verification report auditors can run independently.

Where does my audit data live?

Exactly where you deploy it. The application runs in your own data center, VPC or air-gapped environment; there is no vendor-hosted backend or telemetry pipe that leaves your perimeter.