Compliance audit trail
A defensible audit trail for every regulatory record
Prove where every regulatory record came from. Source URL, timestamp, and verifier ID on each record, verified at 99.5% field-level accuracy.
99.5% field-level accuracy · Source URL, timestamp and verifier ID on every record · US federal, 50 states, France, EU, UK
Traced record
Proposed amendment to 40 CFR Part 60
Joined signals
- Watchlist 'Clean Air'
- Pipeline 'EHS-Compliance'
- 3 related state bills
What an auditor asks for is a record of your process.
The questions are consistent. Where did this come from. When did you know. Who checked it. What did you do next. A monitoring tool that answers only the first question leaves you assembling the other 3 by hand under deadline.
The stakes are set in statute. Under GDPR Article 83(5) the most serious infringements carry administrative fines up to 20,000,000 EUR, or up to 4% of total worldwide annual turnover, whichever is higher. DLA Piper puts aggregate GDPR fines reported since May 2018 at 7.1 billion EUR as of 10 January 2026, with roughly 1.2 billion EUR issued during 2025.
- Upper GDPR fine ceiling, whichever is higher
- 20M EUR or 4%Upper GDPR fine ceiling, whichever is higherGDPR Article 83(5)
- Aggregate GDPR fines reported since May 2018
- 7.1B EURAggregate GDPR fines reported since May 2018DLA Piper, 8th edition, January 2026
- Logged events per record, each with an actor
- 5Logged events per record, each with an actorMatterwire audit trail
The traceability trio, on every record
Source URL
The address the record was read from, stored in full and resolvable. A response checksum is kept so you can show the page has not been swapped underneath you.
Capture timestamp
ISO 8601 with a timezone offset, written at fetch time rather than at publish time. This is the answer to "when did you know".
Verifier ID
The identity of the person who checked the fields against the source, on every record that went to review. This is the answer to "who checked it".
Retention and export
Retention is configurable to match your regime. Export the full trail as CSV or PDF, or read the same events through the API.
The record, and the trail behind it
The card shows what a reader sees. The log below it shows what an examiner asks for: every event between fetch and delivery, each with an actor and a timestamp.
Traced record
Proposed amendment to 40 CFR Part 60
Joined signals
- Watchlist 'Clean Air'
- Pipeline 'EHS-Compliance'
- 3 related state bills
The log behind that record
Audit trail, record rec_01J8Q4M2X
5 events
- captured
Fetched from federalregister.gov, response 200, checksum stored
monitor/us-federal
- classified
Change type "amendment", confidence 0.912, below review threshold
detect/v4
- verified
Fields checked against source text, confidence raised to 0.994
VER-0148
- correlated
Joined watchlist 'Clean Air' and pipeline 'EHS-Compliance'
correlate/v2
- delivered
POST to customer endpoint, 202 accepted, delivery id dlv_8f21c
act/webhook
Security and SLA
Retention, export and the accuracy SLA
Retention is configurable to match your regime. Export the full trail as CSV or PDF, or read the same events through the API. The measurement methodology behind the 99.5% figure is published in full.
The trail is a by-product, not a project
The log is written as the pipeline runs. There is no separate evidence-gathering step to schedule, staff or forget, because the monitoring itself produces the record of the monitoring.
Answers before the call.
See what you would hand an examiner.
Book a demo and we will run one of your regulations through the pipeline, then export the trail it produced.
No obligation. 30 minutes, on your own jurisdictions.
