Founder

ImmutableLog

Know what happened. Detect what matters. Prove what happened.

A security, audit and event observability platform built on a private, permissioned cryptographic ledger. The same event flows through observability, detection, audit and cryptographic proof — no separate tools, no separate pipelines.

01Observe

Logs and events, errors, services, environments, HTTP status, endpoints, timeline, search and filters.

02Detect

Detection rules per tenant: brute force, suspicious IPs, new country, unusual admin/root activity, 401/403 and error spikes, threat intelligence.

03Audit

Actor, action, resource, timestamp, source IP, service and request ID — with an audit timeline and CSV export.

04Prove

Event hash, block, Merkle proof of inclusion and integrity verification anyone can run independently.

The Problem

Immutable by configuration isn't immutable. WORM buckets, retention locks and IAM policies all depend on someone not changing them — and the privileged user able to alter their own audit trail stays the highest-impact threat. Compliance now demands proof, not assertion.

  • An administrator can edit or delete the records that would incriminate them.
  • Observability, SIEM and audit usually live in three disconnected pipelines.
  • Auditors, regulators and courts are asked to trust the operator, not to verify the evidence.
The Approach

One ingestion path feeds every layer. Each event is validated, normalized, enriched, evaluated by detection rules and then cryptographically sealed into an append-only ledger — so tampering becomes mathematically detectable instead of merely policy-prevented.

  • Authenticated event ingestion, validated against schema and signature.
  • ECS (Elastic Common Schema) normalization with SIEM enrichment — geolocation and threat intelligence.
  • Rule-based detection and alerts per tenant, on the same event stream.
  • SHA-256 hash chain and Merkle tree, with proof of inclusion for every event.
  • Private, permissioned ledger with multi-validator Proof of Authority consensus — no public blockchain.
Engineering

The core is written in Rust and runs as a multi-node cluster with a durable on-disk event queue, so ingestion survives restarts and back-pressure without losing evidence. Instrumentation is meant to be a decision, not a project: a static host agent covers infrastructure with zero code, and SDKs cover applications.

  • Rust core, multi-node cluster with consensus and append-only storage.
  • Durable on-disk event queue in front of the ledger.
  • Host agent as a static binary — no code changes required.
  • REST API plus SDKs for Node.js, Python, Go and Java.
  • Cursor-based pagination and CSV export over the audit trail.
Who It's For

Regulated environments where an audit trail is not documentation but evidence — the record has to hold up in front of an auditor, a regulator or a court.

  • Fintechs and digital banks
  • Healthtech platforms
  • Legaltech and arbitration
  • Government and public sector
  • Insurance and insurtech
Stack
  • Rust
  • SIEM
  • Cryptography
  • Merkle Proofs
  • Proof of Authority
  • ECS
  • REST API
  • SDKs
Compliance & frameworks
  • SOC 2
  • ISO 27001
  • LGPD
  • PCI DSS 10.5
  • NIST 800-53 AU-9
  • NIST AI RMF
  • ISO 42001
  • EU AI Act
Portfolio