Overview
Matproof’s Audit Trail (/[orgId]/audit-trail) records every action taken across your compliance program in an immutable, tamper-proof log. This gives you full visibility into platform activity and provides the evidence trail that regulators and external auditors expect.
What gets logged
Every significant action in Matproof creates an audit trail entry:
Each entry records:
- Timestamp — exact date and time (UTC)
- User — who performed the action
- Action type — what they did
- Object type — what was affected (policy, control, user, etc.)
- Object ID — the specific record
- Details — before/after values where applicable
Filtering and searching
Use the filter bar to narrow the audit trail:
You can combine filters — for example, show all evidence uploads by a specific user in the last 30 days.
Exporting for auditors
The full audit trail — or any filtered view — can be exported as CSV. To export:- Apply any filters needed to scope the export
- Click Export CSV in the top right
- The file downloads with all visible columns: timestamp, user, action, object type, object ID, details
- DORA supervisors during ICT risk examinations
- ISO 27001 certification auditors reviewing access and change controls
- Internal audit teams conducting periodic reviews
Data retention
Audit trail data is retained for a minimum of 5 years.DORA Art. 12 requires financial entities to retain logs for a minimum of 5 years. ISO 27001 Annex A 8.15 requires logging and monitoring of system activities. Matproof’s default retention satisfies both requirements.