Platform / Provenance & Audit Trail
Provenance & Audit Trail
A tamper-evident record of every access.
XQ records every access, decryption and policy decision for every protected object in an immutable, HMAC-signed audit log. You get full chain of custody from creation to disposition — and SIEM-ready events in CEF format.
Built for Compliance teams preparing for CMMC, HIPAA or GDPR audits · Security operations teams investigating incidents · Data owners who must prove where their data went
At a glance
RecordsEvery access, decryption and policy decision
IntegrityImmutable and HMAC-signed
FormatCEF, ready for your SIEM
CustodyFrom origin to disposition
Works with Splunk · Microsoft Sentinel · CEF-compatible SIEMs
Know where data went
See who opened each object, from where and when — even after it left your environment.
Evidence auditors trust
Signed, immutable records support compliance audits without manual reconstruction.
Faster forensics
Investigate incidents from a complete access history, streamed to your SIEM.
Why provenance matters
Once data is shared or exfiltrated, most organizations lose all visibility into it. Because every access to XQ-protected data requires a key from XQ, every access is also an event XQ can record — wherever the data is when it’s opened.
What XQ records
- Each access request, with the user, device, location and time.
- Each policy decision — granted or denied — and the rule that decided it.
- Each key release and decryption.
- Administrative changes to policy and access, including revocations.
Records are HMAC-signed and immutable, so any tampering is detectable. Logs capture events and metadata, not the content of your data or key material.
See a full chain of custody for your own data.
Built for audits and investigations
Immutable, per-object audit trails support audits for CMMC, HIPAA, GDPR and data residency laws, and give investigators a complete chain of custody. Events stream to your SIEM in Common Event Format (CEF), alongside the rest of your security telemetry.
Paired with live policy
The audit trail records the decisions made by dynamic policy enforcement, so you can see not only who accessed data but why they were allowed to.
Related resources and articles
FAQ
Provenance and audit trail, answered directly.
What does XQ log?
Every access request, policy decision, key release and decryption for every protected object, with the user, device, location and time, plus administrative changes such as revocations.
Can the audit log be tampered with?
Records are immutable and HMAC-signed, so any change to a record is detectable.
Can we send XQ audit events to our SIEM?
Yes. Events are available in Common Event Format (CEF) for Splunk, Microsoft Sentinel and other CEF-compatible SIEMs.
Do the logs contain our data?
No. Logs record events and metadata, not the content of your data or any key material.
How long are audit logs kept?
You decide. Key and log retention are fully configurable, and logs can also be exported or streamed to your SIEM.
Which compliance requirements does the audit trail support?
Immutable, per-object audit records provide the data provenance and audit trail needed for CMMC, HIPAA, GDPR, FISMA, NIST SP 800-207 zero trust and data residency audits.
Prove where your data went.
See how XQ records every access, everywhere your data travels.