Overview
PCI-DSS (Payment Card Industry Data Security Standard) v4.0 applies to all entities that store, process, or transmit cardholder data. Requirement 10 mandates comprehensive audit logging of all access to system components and cardholder data - and critically, that those logs be protected from modification. The challenge is structural: the systems that administrators use to manage infrastructure are the same systems that house the audit logs. A malicious insider, or an attacker with elevated access, can modify logs to conceal their activity - leaving no evidence of the compromise. ROOTKey anchors log entries to the blockchain at emission, before they reach any mutable storage. This creates a tamper-evident record that is verifiable independently of the cardholder data environment.Requirement 10 - Log and Monitor All Access
Requirement 10.2 - Audit Log Capture
Requirement 10.3 - Protect Audit Logs from Destruction and Modifications
This is where ROOTKey provides direct, structural compliance:PCI-DSS Requirement 10.3.2 specifically calls for “change-detection technology” for audit log files. Blockchain anchoring is the strongest available implementation of change-detection: any modification produces a hash mismatch that is verifiable by any party with the transaction ID, including the QSA.
Requirement 10.5 - Retain Audit Logs
QSA Verification
PCI-DSS assessments are conducted by Qualified Security Assessors (QSAs) who must verify that controls are operating effectively. ROOTKey anchors provide QSA-verifiable evidence:Architecture for CDE Log Protection
Request a PCI-DSS architecture review
We’ll design a ROOTKey log anchoring implementation that satisfies Requirement 10 and produces QSA-verifiable evidence.
Regulatory audit trails use case
Full implementation guide for tamper-evident audit logging.

