Logs and events, errors, services, environments, HTTP status, endpoints, timeline, search and filters.
Detection rules per tenant: brute force, suspicious IPs, new country, unusual admin/root activity, 401/403 and error spikes, threat intelligence.
Actor, action, resource, timestamp, source IP, service and request ID — with an audit timeline and CSV export.
Event hash, block, Merkle proof of inclusion and integrity verification anyone can run independently.
Immutable by configuration isn't immutable. WORM buckets, retention locks and IAM policies all depend on someone not changing them — and the privileged user able to alter their own audit trail stays the highest-impact threat. Compliance now demands proof, not assertion.
One ingestion path feeds every layer. Each event is validated, normalized, enriched, evaluated by detection rules and then cryptographically sealed into an append-only ledger — so tampering becomes mathematically detectable instead of merely policy-prevented.
The core is written in Rust and runs as a multi-node cluster with a durable on-disk event queue, so ingestion survives restarts and back-pressure without losing evidence. Instrumentation is meant to be a decision, not a project: a static host agent covers infrastructure with zero code, and SDKs cover applications.
Regulated environments where an audit trail is not documentation but evidence — the record has to hold up in front of an auditor, a regulator or a court.