Audit log
Every decision Vulnify makes is written to the audit log, including human reviews. The log is the record of what was allowed, sent to review, or blocked, and why.
The app’s audit log is the history of those decisions. Sources shown there include the API (including test keys), the gateway, and human review. Sandbox events from TEST keys are kept out of the main dashboards. The compliance export of recent security events also excludes sandbox runs.
Hash chain
Section titled “Hash chain”Each decision is appended to a per-organization SHA-256 hash chain. Verification recomputes the chain and reports the first entry that does not match. In the app, open the audit log and run Verify audit chain. The compliance report shows the same check: either the chain verified, or verification failed.
The chain is how Vulnify makes the trail tamper-evident. A successful verification means the stored entries still hash together. It is not a certification of your organization, and it is not a claim that the underlying systems are impossible to compromise.
The public OpenAPI document does not include an audit-log download. With an API key you can read one decision at a time with GET /v1/events/{id}. Vulnify can also POST decision, anomaly, and test deliveries to an endpoint you register. See Webhook deliveries.
In the app, an owner or an admin downloads recent security events from Compliance with GET /compliance/export. That route uses the app session, not an API key, so it is not part of the public machine contract. The download is a JSON or CSV export. Omitting format returns JSON. CSV is GET /compliance/export?format=csv. The file leaves out sandbox runs. Account and organization downloads from Settings do not include these events. See Your data (export and deletion).
What a record contains
Section titled “What a record contains”Records hold action metadata: agent, action, resource, destination, record counts, timestamps, risk results, review decisions, and notes. They are not a copy of the customer records the agent read or exported. Optional content sent for scanning is not stored. Findings may be stored as types and LGPD categories. See Risk engine.
Retention
Section titled “Retention”Decision events are deleted automatically after your plan’s retention window (Developer 7 days, Team 30 days, Business 365 days). The deletion job runs regularly. Enterprise retention follows your contract; there is no automatic deletion unless agreed. When an event is deleted, its audit-log entry (the decision, risk score and related metadata) is kept for as long as the organization exists, because the audit log is append-only. Deleted data can remain in encrypted backups for up to 30 days. GET /public/plans publishes those windows as retentionDays. See Plans.
After the account ends, customer data is deleted except what the law requires Vulnify to keep. Details are in the privacy policy.

