Evidence no one — including the operator — can backdate.
Assurance is only as good as the evidence behind it. Praman writes every compliance event to an append-only, hash-chained log that the database itself refuses to update or delete. A one-click verifier recomputes the chain and pinpoints any tampering, making the Audit Pack's integrity certificate something an auditor or cyber-insurer can actually trust.
The problems we hear from audit, risk & assurance teams
- ▹Compliance evidence that could, in principle, be edited after the fact
- ▹Audit preparation that consumes weeks of manual collation
- ▹No independent way to prove a log has not been altered
- ▹Findings disconnected from the evidence that produced them
What Praman does for you
Tamper-evident audit log
SHA-256 hash chain over canonicalised events; a Postgres trigger rejects every UPDATE and DELETE on the audit spine.
One-click verification
Recompute the chain over any range; get PASS, or the exact sequence number and nature of the first divergence.
Integrity certificate
The Audit Pack embeds the chain-verification result and Merkle root, so the bundle proves its own integrity.
Future-proof anchoring
A pluggable anchorer lets you later commit Merkle roots to a public ledger — a config change, not a rewrite.
Obligations you’ll see covered
Each maps to an automated check with its statutory citation and tamper-evident evidence.
Frequently asked
How do you prove the log was not altered?
Each event's hash binds the previous hash, the canonicalised payload, the timestamp and the sequence. Changing any byte breaks the chain, and the verifier reports the exact point of divergence.
What is in the Audit Pack?
Current posture, all check results with citations and evidence references, the breach timeline, retention proofs and an integrity certificate — exported as a PDF plus a zip of the underlying JSON evidence.