A tamper-evident audit trail, intelligent search, UEBA anomaly detection and compliance reporting — all running on your servers. SOC 2 / ISO 27001 / GDPR-ready out of the box. No per-seat SaaS fees, no data leaving your perimeter.
Most logging tools are built for engineers debugging prod. Log Audit Platform is built for the moment an auditor, regulator or customer asks: "prove what happened, and prove it wasn't changed."
Every record carries a hash chained to the previous one. Any retrospective edit breaks the chain and is caught by the built-in verification report.
Right-to-erasure and data-subject export are first-class: anonymize a user's or IP's records without breaking the hash chain; export is masked by default.
Full-text + structured query plus an expert query builder. Aggregate by actor, asset, action, geo or result; save and share views.
Behavioral rules flag outliers — impossible travel, off-hours admin, brute-force patterns — and notify via email / in-app.
Pre-built compliance templates generate audit reports and a downloadable evidence ZIP for SOC 2 / ISO 27001 control evidence.
Distinct Auditor / Security-admin / Compliance roles. The person who configures sources is not the person who signs off the report.
One Spring Boot 3 application (Java 17+) ships the API and the Vue 3 admin UI in a single runnable JAR. Point it at PostgreSQL, set a few env vars, done.
What ships depends on your tier:
docker-compose.yml + .env.example + schema SQL — no source codeDockerfile + white-label + redistribution licenseOne-time payment, no subscription. Single & Business ship a ready-to-run package (no source); Enterprise / OEM include the full source code. Checkout is handled securely by Waffo Pancake (Merchant of Record — cards, Apple/Google Pay + Alipay/WeChat; global tax/VAT handled for you, payouts to your bank/Alipay).
For one production deployment — runtime, no source.
Most teams. Multiple instances — runtime, no source.
Resell or embed in your product.
Prices are set in Waffo. Need a different split (e.g. per-seat, annual maintenance)? Just ask.
Optional annual maintenance ($39 / $139 / $499 by tier) extends updates & support — renew anytime; expiry never locks you out of the running product.
Self-hosted. You run it on your own infrastructure. There is no recurring per-seat fee and your audit data never leaves your perimeter.
Java 17+ and PostgreSQL 12+. The app is a single Spring Boot JAR that also serves the Vue 3 admin UI. Docker Compose is included.
Each record stores a hash of itself chained to the previous record's hash. A verification report walks the chain and flags any broken link — so post-hoc edits are detectable. (For stronger guarantees, anchor periodic roots externally; an OEM hook is available.)
Yes. Right-to-erasure anonymizes a data subject's records (by account or IP) without breaking the hash chain, and data-subject export plus masked exports are built in.
A commercial source license. You may use and modify the code for your own deployments; resale/redistribution of the source requires the Enterprise/OEM tier.
Yes — email support for the license term (6–24 months by tier), plus optional onboarding for Business and above.
Yes — deploy the included Docker Compose locally, or request a recorded walkthrough via the contact link above.
Self-hosted and simple. After checkout we email you an activation code (a signed key). Open System > Configuration > License, copy your server's machine code, send it to us, and we issue a code bound to that server. Paste the code back and it activates instantly — no external server, no phone-home. The code is machine-bound, so moving to a new server just needs a quick re-issue.
Yes. The platform produces ready-to-use evidence packs for common access-control, logging and monitoring controls, plus a tamper-evidence verification report auditors can run independently.
Exactly where you deploy it. The application runs in your own data center, VPC or air-gapped environment; there is no vendor-hosted backend or telemetry pipe that leaves your perimeter.