Skip to main content

The Problem

Regulators don’t just ask whether you were compliant - they ask whether you can prove it. And the burden of proof is increasing. NIS2 requires critical entities to demonstrate integrity and auditability of their information systems. DORA demands operational resilience documentation and incident audit trails from financial entities. ISO 27001 mandates logging and protection of records. In practice, most organisations produce logs - but logs are stored in systems that administrators can access, modify, or purge. When a regulator or auditor examines a log, they are trusting the organisation’s assurance that the log hasn’t been tampered with. That trust assumption is the vulnerability. ROOTKey eliminates it.

How ROOTKey Solves It

ROOTKey anchors each audit event - a configuration change, an access grant, a system action, an incident - to the Polygon blockchain at the moment it occurs. The anchor is:
  • Immutable - no administrator, no breach, no system failure can alter a record after it is anchored
  • Timestamped by the blockchain - the timestamp is set by network consensus, not by your system clock
  • Independently verifiable - regulators, auditors, and counterparties can verify records without your cooperation
This transforms your audit trail from a log that you assure is accurate into a record that anyone can verify is accurate. The difference matters enormously when the organisation producing the log is itself under investigation.

Architecture

ROOTKey integrates alongside your existing SIEM, ITSM, or logging infrastructure. You do not replace your log systems - you add a cryptographic integrity layer that makes each log entry independently verifiable.

Implementation

1

Design your vault structure around audit domains

Create a vault per audit domain - one for access control events, one for configuration changes, one for incident records. This enables granular access control and simplifies providing regulators with evidence scoped to specific systems or periods.Create Vault
2

Anchor each auditable event at emission

Hook into your event pipeline - SIEM, logging agent, application middleware - and send each auditable event to ROOTKey immediately when it is generated, before it is written to any mutable storage.Create File
3

Use Tables for structured, queryable audit records

For structured event data - JSON logs, audit records with typed fields - use the Tables API to store records with schema validation and record-level integrity anchoring. This allows querying specific event types while preserving per-record verifiability.Tables API · Records API
4

Monitor your audit workload with Analytics

Use the Analytics API to track anchoring volume over time. This is useful for demonstrating continuous compliance activity to auditors and detecting gaps in coverage.Analytics - Vault Creation Over Time · Analytics - Files vs Validations
5

Provide verifiable evidence packages to regulators

When a regulator requests evidence, provide the vault ID, file IDs, and on-chain transaction hashes for the relevant period. The regulator can independently verify each record via Polygonscan - no access to your systems required, no trust assumption required.


Key API Endpoints


Compliance Alignment


Get started - free account

Set up a sandbox vault and anchor your first audit event in minutes.

Request a compliance architecture review

Our team will map your regulatory obligations to a concrete ROOTKey implementation and provide compliance documentation support.