Evidence an auditor can verify alone.
A log neither you nor we can quietly change.
Event. Hash. Seal. Signature.
Every event in order, each carrying the fingerprint of the last.
service chatgpt · browser
classes [IBAN]
action REDACT · rule fin-…
prev e07b…44
hash 3a9f…c1
= sha256(prev + event)
leaves 200
root 9ceb…5ac8
sealed per batch
key org-signing-01
sig 28d1…41b3
VERIFIED
Chain: OK (201 events)
Pack signature: OK
Batch c83ec1d9-7c0e-4a45-b0f0-ae72541c2ebd: merkle OK, signature OK
VERIFIED — record is intact.
Labels, hashes, metadata. Never content.
Six fields, and none of them is what your employee typed.
One export. One command. No vendor in the room.
Signed, in three formats.
From the console, filtered by data type, outcome and period. The pack carries the organisation's public key, the batch seals and every event in the range.
- JSON for the verifier
- CSV for the analyst
- PDF for the file

A standalone script. No network.
Your auditor runs it on their own machine. Three lines come back: chain, pack signature, seal. Nothing contacts Deltawall.
- Works with Deltawall offline or gone
- The employer cannot alter the record either
- It protects the works council too

Permanent. And still erasable.
Personal data stays off the log by design. Erasure deletes the link to the person and the salt. Every record about them becomes anonymous. The chain stays intact.
- GDPR Article 17 and a permanent log, together
- Follows the EDPB's 2025 direction
- No rewrite of history, ever

What the DPO and the auditor ask.
01Who is it for?
Your DPO, for Article 5(2) accountability. Your auditor, who wants proof nothing was edited. Your works council, protected by the same property. Your SOC, through a webhook and event stream.
02What stops you from editing it?
Each record carries the fingerprint of the one before it, batches are sealed, and the seal is signed with the organisation's key. Change one record and every later fingerprint stops matching.
03Do we have to trust your verifier?
No. It is a standalone script with no network access. Read it, or write your own against the published format.
04How long is it kept?
Per-person events: 90 days by default, then aggregated and discarded. Department aggregates: 24 months. Both configurable per tenant.
05Can we send it to our SIEM?
Yes. An outbound webhook and a JSON event stream. Any SIEM ingests it on the first day.
Let's talk.
Thirty minutes. You watch the product stop realistic data in a real browser.
- Six leaks: three prompts, three files, live
- The dashboard a security lead sees on Monday
- An evidence pack exported and verified while you watch
- Whether a proof of value in your estate makes sense
