Who?
User ID and IP address of the person triggering the action.
Audit & Compliance
Append-only audit log with SHA-256 hash chain, role-based access and traceable change logs. Built for companies with high requirements for documentation and traceability.
Hash chain
Every audit entry contains the SHA-256 hash of the previous entry. This way the integrity of the audit chain can be verified. Append-only at the database level supports a traceable record of changes.
Logging
Who? When? What? Why? — four questions every audit entry answers.
User ID and IP address of the person triggering the action.
Server timestamp in UTC.
Before/after state of the affected data row, fully reconstructable.
Justification as a mandatory field on every manual intervention.
Privacy
When personal data is no longer needed in clear text, identifying fields can be pseudonymised. Booking-relevant data can be retained where legal retention obligations or legitimate evidentiary purposes apply.
Compliance
Pseudonymisation of personal fields based on a defined rule set.
Audit log without update rights, only new entries possible.
Hash chain for integrity verification across audit entries.
Application and database on Hetzner servers in Nuremberg and Falkenstein.
Audit architecture
Demo
We'll show you how lumen.hr supports audit logs, role-based access and traceable change logs. An audit-focused demo is available on request.