Audit & Compliance

Audit Trails with Hash Chain — Traceably Documented

Append-only audit log with SHA-256 hash chain, pseudonymisation of personal fields based on a defined rule set, role-based audit access. Built for companies with high traceability requirements.

Mock Dashboard

Hash chain

Changes become traceable

Every audit entry contains the SHA-256 hash of the previous entry. This way the integrity of the audit chain can be verified. Append-only at the database level supports a traceable record of changes.

  • SHA-256 hash of the previous entry in every row
  • Append-only at the database level
  • Verification endpoint for the audit role
Mock Dashboard

Logging

What is logged

Who? When? What? Why? — four questions every audit entry answers.

  • Who?

    User ID and IP address of the person triggering the action.

  • When?

    Server timestamp in UTC — not client time, so time-zone tricks are ruled out.

  • What?

    Before/after snapshot of the affected data row, fully reconstructable.

  • Why?

    Justification as a mandatory field on every manual intervention.

GDPR Art. 17

Pseudonymisation instead of destruction

When employees request the erasure of their data, lumen.hr pseudonymises the personal fields while the legally retained bookings remain intact. Both obligations are met — GDPR and commercial-law archiving.

  • Personal fields are pseudonymised
  • Booking-relevant data is retained as legally required
  • Traceably documented: timestamp, trigger, scope
Mock Dashboard

Compliance

Compliance foundations

  • Privacy features

    Pseudonymisation of personal fields based on a defined rule set.

  • Append-only

    Audit log without update rights, only inserts possible.

  • SHA-256

    Hash chain across all entries, tamper-evident.

  • Hosting in Germany

    Application and database on Hetzner servers in Nuremberg and Falkenstein.

Audit architecture

Three technical building blocks

SHA-256
Hash algorithm of the audit chain
100 %
Append-only, no modifications possible
16
German states with holiday logic

Demo

Show us your compliance requirements

FDA, GMP, German authorities: we will show you in an audit-focused demo how lumen.hr provides the technical foundations for audits.