DocSupra › Enterprise Compliance Studio › Tamper-evident document audit log
DocSupra · Enterprise Compliance Studio
An audit log that proves itself
Who audited what, and when, chained by hash. Names, hashes and verdicts. Never the images.
A document audit log that cannot be edited without breaking its chain.
The short answer. Every batch a desk records goes into the organisation log: the files by name or pseudonym, their SHA-256 hashes, sizes and verdicts, the department, the destination, who did it and when. Each record carries the hash of the previous one, so changing or removing a record breaks the chain, and the whole chain can be verified at any time. The log never holds a document.
An auditor asks two questions: what did you do with these documents, and how do I know this record was not written afterwards? A spreadsheet answers the first. The second needs a record that proves its own order. This one is kept by the software as the work happens, and anyone with the right key can recompute it.
What the log holds, and how it is protected
Each audit and each delivery: date, type, department, destination, who, how many files were ready, fixable or to retake, a sequence number and a seal.
Per file: the name or a pseudonym, the SHA-256 of the source, the SHA-256 of the delivered file on deliveries, the verdict, the reasons, the integrity risk and what was done on export.
Every record carries the seal of the one before it. Verification recomputes every seal of a month and names the first altered batch, if there is one.
Policy changes, purges, key and webhook changes are recorded as entries in the same chain, so the trail of administration is part of the evidence.
Under HIPAA, GLBA or GDPR mode the record is mandatory before an export is released, names become pseudonyms and records are kept for the retention window you set.
An API key reads the log and verifies the chain; signed webhooks and SIEM export (Splunk, Datadog, Sumo Logic) push each batch as it happens; an AI assistant can read and verify the log through the connector.
How it works on a desk
Audit a batch
Open the Enterprise Compliance Studio, choose the department and the destination and drop the files. Every file is measured on your own machine.
Record it
Record the batch to the organisation log. Under compliance mode this is required before the ZIP is released.
Verify
In the team console, verify the chain for the month: how many records were verified and whether any was altered.
Hand it to the auditor
The evidence PDF summarises the policy in force and the state of the log. A read-only auditor role can read the log without being able to change anything.
What it is not
The log records metadata: names or pseudonyms, hashes, sizes and verdicts. It never contains an image or a page, so it cannot be used to recover a document. A verified chain shows that the records were not altered after they were written; it does not certify that the organisation is compliant with any law, and we do not sell a certification.
What it costs a team
Both plans include the same software. Corporate Studio adds people, a named support contact and invoice billing.
Prices are in USD and exclude any tax that applies in your country; Stripe calculates it and shows it before you pay. Only the monthly plans renew, and they cancel in one click from the Stripe receipt.
Open the Enterprise Studio →Questions
What makes the audit log tamper-evident?
Each record carries a seal computed from its own content and the seal of the previous record. Changing, removing or reordering a record changes the seals that follow, and verification names the first batch that no longer matches.
Does the log contain our documents?
No. It holds file names or pseudonyms, SHA-256 hashes, sizes, verdicts, the department, who did it and when. The images never leave the machine that opened them.
Can our systems read the log?
Yes. An organisation API key reads the log and verifies the chain, signed webhooks and SIEM export push each batch to Splunk, Datadog or Sumo Logic, and an AI assistant can read and verify it through the MCP connector. A key cannot download files, administer the organisation or change the policy.
How long are records kept?
For the retention window in your compliance policy, between 30 and 400 days. A purge is possible only by an administrator and is itself recorded in the chain.
Which plans include it?
It is part of both team plans: Professional Team ($149 per month, up to 3 people) and Corporate Studio ($349 per month, 10 people included and $29 per extra seat, up to 500 people).
More on DocSupra
Made and copyrighted © 2026 by Soelys Muñoz. DocSupra™ is her trademark. All rights reserved. How to recognise the real site.