Skip to content

Feature: Add tamper-evident audit, retention, legal hold, and SIEM export #308

Description

@JustNZ

Release

Release 3 — Regulated and air-gapped operations

Goal

Make security decisions and administrative activity reviewable over long retention periods.

Scope

  • Make audit events append-only and hash-chain them for tamper evidence.
  • Cover access, policy, VEX, exception, evidence export, identity, feed, and retention actions.
  • Add configurable retention policies, legal holds, and approval for protected evidence deletion.
  • Add an EU-oriented ten-year evidence-retention preset.
  • Export audit data as NDJSON and deliver it through RFC 5424/syslog with redaction controls.

Acceptance criteria

  • Audit verification identifies the first missing or modified event.
  • Legal hold prevents automated and manual deletion.
  • Retention jobs are resumable, observable, and audited.
  • SIEM delivery retries safely without duplicating event identity.
  • Sensitive credentials and raw secrets never appear in audit exports.

Metadata

Metadata

Assignees

No one assigned

    Type

    No type

    Projects

    Status
    Todo

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions