Solutions / Internal Audit & Risk
Audit, Risk & Assurance

Evidence no one — including the operator — can backdate.

Assurance is only as good as the evidence behind it. Praman writes every compliance event to an append-only, hash-chained log that the database itself refuses to update or delete. A one-click verifier recomputes the chain and pinpoints any tampering, making the Audit Pack's integrity certificate something an auditor or cyber-insurer can actually trust.

The problems we hear from audit, risk & assurance teams

  • ▹Compliance evidence that could, in principle, be edited after the fact
  • ▹Audit preparation that consumes weeks of manual collation
  • ▹No independent way to prove a log has not been altered
  • ▹Findings disconnected from the evidence that produced them

What Praman does for you

Tamper-evident audit log

SHA-256 hash chain over canonicalised events; a Postgres trigger rejects every UPDATE and DELETE on the audit spine.

One-click verification

Recompute the chain over any range; get PASS, or the exact sequence number and nature of the first divergence.

Integrity certificate

The Audit Pack embeds the chain-verification result and Merkle root, so the bundle proves its own integrity.

Future-proof anchoring

A pluggable anchorer lets you later commit Merkle roots to a public ledger — a config change, not a rewrite.

Obligations you’ll see covered

Each maps to an automated check with its statutory citation and tamper-evident evidence.

DPDP-SDFPeriodic DPIA & annual auditDPDP-BREACHBreach timelinessCERTIN-INCIDENT-6HIncident reporting timeliness

Frequently asked

How do you prove the log was not altered?

Each event's hash binds the previous hash, the canonicalised payload, the timestamp and the sequence. Changing any byte breaks the chain, and the verifier reports the exact point of divergence.

What is in the Audit Pack?

Current posture, all check results with citations and evidence references, the breach timeline, retention proofs and an integrity certificate — exported as a PDF plus a zip of the underlying JSON evidence.