SureThink/Product/Pillar 05

Pillar 05 · Audit-ready logs

Nine months later,
it replays exactly.

The question an auditor asks is never “what did you decide”. It is “show me how”. Most firms answer it by reconstruction — from memory, a spreadsheet, and an email thread nobody wants to read aloud.

0unaudited actions
Sealedon submission
Pinnedto its pipeline version
Canadadata residency

One decision, written down in full.

This is the whole record for case #4471 — not a summary of it. Everything an auditor, a reinsurer or a regulator would ask for is one object, and it was written as the case happened rather than assembled afterwards.

✓ Approved with conditions — immutablesha256 · 9f2c…41ab

Case

#4471 · Meridian Builders Ltd.

Exposure

$1,280,000 performance bond

Signed by

K. Osei · senior underwriter · limit $2M

Counter-signed

M. Webb · compliance director

Correction recorded

contingent_liability → $184,200

Pipeline had read

~$184,000 · inferred · note 9

Rule pack

contract_surety v1 · in force 8/4/26

Pipeline version

surety_intake v14 · frozen 8 Sep

09:41:06 intake 14 files · 62 pp · email_watch
09:41:29 classify 12 types recognised · 2 correspondence
09:43:22 extract 11 fields · 7 read · 2 derived · 1 inferred · 1 absent
09:45:01 gate CS-038 → refer · confidence below threshold
09:45:01 park approval_tray · routed to K. Osei · within limit
16:22:14 sign K. Osei · approve with correction · 1 field changed
16:22:14 gate four_eyes required · K. Osei excluded from second signature
16:31:40 counter-sign M. Webb · four-eyes satisfied
16:31:41 seal sha256 9f2c…41ab · chained to 8c11…9d02
16:31:42 emit letter.pdf · obligation set · POST /bonds/4471 → 202

Seven hours of it is one line: the case waiting for a person. That gap is the most important thing in the log, and it is the thing a throughput dashboard would hide.

Hash-chained

Tamper-evident,
not merely logged.

Each sealed decision carries the hash of the one before it. Altering a record in the middle of the chain changes its hash, which breaks every link after it — so the tampering is visible without anyone having to notice the content changed.

Immutable

Superseded, never edited

A decision that turns out to be wrong is replaced by a new decision that references it. The original stays, because what you believed in September is part of the story.

Attributable

A name on every line

Every figure names its source page. Every decision names its signer. Every correction names who made it and what was there before.

Verifiable

Anchored, not self-attested

The chain is verified independently of the application, so “the system says it wasn’t changed” is not the only assurance on offer.

Replay

Under its own rules, not today’s.

This is the part most audit trails get wrong. Re-running an old case through current logic tells you what you would decide now — which is not the question. The pipeline version is pinned to the case, so the replay is the decision as it was actually made.

replay · case #4471 exact match
Pipeline version usedsurety_intake v14 · frozen 8 Sep 2026pinned
Rule pack usedcontract_surety v1 · in force 8/4/26pinned
Authority map usedas at 18 Sep 2026pinned
Source documents14 files · hashes matchintact
Fields re-derived11 of 11 identicalmatch
Today’s pipeline wouldv16 · refer on 2 fields, not 1differs

The last row is shown on purpose. The rules changed in October, and the replay reports both — what was decided, and what would happen now — without pretending they are the same thing.

Security & residency

Where the file lives,
and what it is used for.

Two questions every risk committee asks in the first meeting. Here are the answers in plain terms, before you have to ask them.

QuestionAnswerWhere
Data residencyYour documents, extractions and decision records are stored in a Canadian region and stay there.always on
Model trainingYour files are never used to train a model — ours or anyone else’s. There is no setting for this because there is no other mode.always on
Tenant isolationRow-level security on every table, enforced in the database rather than the application layer, so a query cannot reach another organisation’s rows.always on
Access controlCapability-based, not role-name-based. What someone can do is resolved per action, and an owner cannot lock their own organisation out.always on
Two-factorTOTP on every account, and enforceable for the roles you choose — signing authority being the obvious one.configurable
Audit logEvery mutation — not just decisions — writes an audit row with the actor, the before state and the request id.always on

What we don’t claim. No certification badges on this page. If your process needs SOC 2 or ISO 27001 evidence before a pilot, ask us directly and we will tell you exactly where that work stands rather than showing you a logo.

Start with one workflow

Bring the question
your auditor asked last.

Thirty minutes. We run a real case end to end and show you the record it produces — then replay it, under its own rules, in front of you.

  • A schematic of your workflow, yours to keep
  • The rule pack it would screen against
  • Your authority map, role by role
  • A sample decision record and a cost per file

No deck. We’ll ask you to bring one real file, redacted however you need it.