Trust / Audit Logs

Every action, accounted for.

Tamper-evident audit logs record who accessed what, when, and why - across clinical, administrative, and API surfaces. Built to satisfy inspectors and your own future self.

What we log

  • Authentication events

    Sign-in, sign-out, MFA challenges, token issuance, and revocations.

  • Clinical actions

    Record views, edits, exports, prescription drafts, signatures, and amendments.

  • Admin activity

    Permission changes, invitations, and configuration updates.

  • API access

    Every authenticated API call with method, scope, and outcome.

Retention & export

Logs are retained for a minimum of 12 months. Hospital and Enterprise plans support extended retention and SIEM export via secure syslog or object storage delivery.

Log records are append-only and chained. Any modification is detectable during audit review.

Who can see what

Access to audit data is scoped: clinic admins see their clinic, platform admins see aggregate operational events, and no single role can silently disable logging.