Trust & Security
Audit trail and data disclosure
The immutable history of what happened, and the verifiable ledger of third-party access.
The audit history
Every application has a dedicated audit database recording what changed, who changed it, and when — kept separate from live data so operational activity can't disturb the record.
Disclosure ledger for extensions
When a marketplace extension accesses tenant data, that access is written to a hash-chained ledger: each entry cryptographically commits to everything before it, so the record cannot be silently altered or trimmed after the fact. The exact code identity of the extension is snapshotted at invocation, so the ledger reflects precisely what ran. Tenants can verify their own ledger independently.
Capability review: 2026-09-14. For exact current technical availability, use the generated API Map and first-class module inventory.