Audit Trail
VaultAP maintains an immutable audit trail that records every significant action taken within your organization. The audit trail is designed to satisfy compliance requirements and provide forensic evidence in the event of a security investigation.
Immutability
Audit trail entries are append-only. Once written, they cannot be modified or deleted — not by users, not by Admins, and not by VaultAP staff. Entries are retained for the full duration of your organization's configured data retention period.
There is no mechanism to edit or remove individual audit trail entries. This is by design. If you believe an entry was created in error, add a note to the relevant record explaining the situation rather than attempting to alter the trail.
Hash-Chain Integrity
Each audit trail entry includes a cryptographic hash of the previous entry, forming an unbroken chain. This mechanism, similar to a blockchain, ensures that any insertion, deletion, or modification of an entry would break the chain and be immediately detectable.
The hash chain works as follows:
- Each entry is assigned a sequential ID and a timestamp.
- The entry's content (action, user, target, metadata) is combined with the hash of the previous entry.
- A SHA-256 hash is computed over the combined data.
- This hash is stored alongside the entry and used as input for the next entry.
VaultAP automatically verifies the hash chain integrity on a regular schedule. If a break in the chain is detected, Admins are notified immediately via email and in-app notification.
What Is Logged
Every action that changes state or accesses sensitive data is recorded:
User Authentication
- Login (success and failure)
- Logout
- MFA enrollment and verification
- Password changes and resets
Invoice Actions
- Invoice received (via email or manual upload)
- Risk score assigned
- Invoice approved
- Invoice rejected
- Invoice escalated
- AI explanation generated
Vendor Actions
- Vendor created (first invoice from new vendor)
- Vendor bank details changed
- Vendor information edited
Settings Changes
- Organization settings modified
- Risk configuration updated (with before/after values)
- Notification settings changed
User Management
- User invited
- User role changed (with before/after role)
- User deactivated
- User reactivated
Each entry includes:
| Field | Description |
|---|---|
| Timestamp | When the action occurred (UTC) |
| User | Who performed the action (email and user ID) |
| Action | What was done (structured action type) |
| Target | The entity affected (invoice ID, vendor ID, user ID, etc.) |
| Metadata | Additional context (e.g., old and new values for settings changes) |
| Hash | SHA-256 hash linking to the previous entry |
Viewing the Audit Trail
Navigate to Audit Trail in the main navigation to view entries. The trail supports filtering by:
- Date range
- User
- Action type
- Target entity
CSV Export
Admins can export the audit trail as a CSV file for external analysis, compliance reviews, or archival.
Set filters
Apply any desired filters (date range, user, action type) to narrow the export.
Click Export CSV
Click the Export CSV button. VaultAP generates the file in the background.
Download
A download link is sent to your email when the export is ready.
Tamper Detection
If the hash chain is broken — indicating that an entry has been inserted, modified, or removed — VaultAP triggers a tamper alert:
- All Admins receive an immediate email and in-app notification.
- The affected entries are flagged in the audit trail UI with a warning indicator.
- The tamper event itself is recorded as a new audit trail entry.
A tamper alert is a critical security event. If you receive one, investigate immediately and contact VaultAP support at security@vaultap.com.