Your audit trail is our only product.
DecisionChain is built to be the record that survives a regulator's request. This page is maintained by DecisionChain to answer common security and privacy questions about the platform.
Tamper-evident by design
Every audit record is hashed and chained to the previous one. Alteration breaks the chain and every downstream signature, provably.
Encryption in transit and at rest
TLS 1.2+ for all traffic. AES-256 at rest. Data is encrypted before it hits our storage layer.
Customer-managed keys (Enterprise)
Bring your own KMS. Rotate keys on your schedule. We never see plaintext for records under CMK.
Regional isolation
US and EU regions available. Data does not leave the region you provision, including backups and evidence exports.
External anchoring
The chain head is periodically anchored to an external witness so tampering is detectable even in the case of a full compromise.
Least-privilege access
SSO and SCIM for Enterprise. Audit-role separation so viewers, exporters, and admins are distinct.
Compliance framework references
DecisionChain produces evidence your compliance team submits. We are not a substitute for a certification — we make the evidence work tractable.
- EU AI Act — Article 12. Automatic recording of events across the lifecycle of high-risk systems.
- ISO/IEC 42001. AI management system evidence for controls, monitoring, and human oversight.
- SOC 2 (Type II). Security, availability, and processing integrity attestations for the service.
- NIST AI RMF. Govern · Measure · Manage — mapped to our logging, monitoring, and evidence workflows.
Report a vulnerability
Found a security issue? Email hello@decisionchain.dev with reproduction steps. We respond within one business day and coordinate disclosure with reporters.