Skip to main content

Audit & Compliance

Immutable, evidence-grade audit trails designed for investigations and regulatory frameworks.

Immutable LogsWORM StorageSIEM ExportCompliance Scoring

Event Logging

Immutable structured event logs covering 30+ event types. Every file operation, user action, policy change, and compliance event captured.

MnemoShare does not log to a database you can edit. Events are immutable structured records covering who, what, when, where, why, and outcome. SIEM export ships logs to your security stack. WORM storage via S3 Object Lock makes them tamper-evident for any retention period your framework requires.

  • 30+ structured event types covering the full platform surface
  • Every file upload, download, delete, and share captured with full context
  • User authentication, permission changes, and policy modifications logged
  • SIEM export to Splunk, Datadog, and other platforms via configurable batch export
  • WORM storage via S3 Object Lock in governance and compliance modes
  • Tamper-evident retention — logs cannot be modified or deleted
  • Configurable retention from 90 days to 7+ years

Compliance Framework

Map your security posture to industry frameworks with real-time compliance scoring and automated evidence generation.

  • HITRUST r2 assessment in progress
  • SOC 2 Type II audit support with control mappings
  • HIPAA technical safeguard coverage with BAA available
  • ISO 27001 aligned controls
  • NIST CSF mapped categories
  • FIPS 140-3 ready — all cryptographic operations designed for validated modules
  • Compliance scoring dashboard with real-time posture assessment

Reporting

Generate audit-ready reports for regulators, auditors, and internal stakeholders with configurable scheduling.

  • Compliance Posture reports with PDF generation (Typst-based)
  • Audit Log exports with filtering by date, user, event type, and outcome
  • Evidence Package generation for auditor review
  • User Activity reports covering logins, file operations, and policy events
  • Configurable report scheduling — daily, weekly, or monthly

Beyond traditional MFT

Most managed file transfer platforms were designed before modern threats existed. Here is how MnemoShare compares.

CapabilityTraditional MFTMnemoShare
Audit trailDatabase logs, often overwrittenImmutable structured events — 30+ types, tamper-evident
RetentionLimited by database storageWORM storage via S3 Object Lock, 90 days to 7+ years
SIEM integrationManual log shipping or noneNative export to Splunk, Datadog with configurable batching
ComplianceManual evidence gatheringAutomated compliance scoring, evidence package generation, framework mappings
InvestigationReconstruct events from fragmented logsStructured events with full context — who, what, when, why, outcome

Real-world use cases

HIPAA audit preparation

Healthcare org generates Evidence Package report covering all file access, DLP findings, and user authentication events for the audit period. WORM-stored logs prove tamper-evident chain of custody.

Incident investigation

Security team investigates suspicious file access. Structured audit trail shows exact sequence: user authenticated (how), accessed folder (which), downloaded files (what), from IP (where), at time (when). No log reconstruction needed.

Continuous compliance monitoring

Compliance officer reviews weekly Compliance Posture report showing 71% score. Dashboard identifies gaps: SSO not configured (30/50 auth score). Officer enables SSO, score improves to 90%.

Frequently asked questions

Are MnemoShare audit logs tamper-proof?
Yes. Audit logs are immutable structured events that cannot be modified or deleted. For maximum assurance, WORM storage via S3 Object Lock provides tamper-evident retention in governance or compliance mode.
What SIEM platforms does MnemoShare support?
MnemoShare exports audit logs to Splunk, Datadog, and any S3-compatible destination. Export is configurable with batch sizing, export intervals, and retention policies. WORM storage ensures exported logs cannot be altered.
What compliance frameworks does MnemoShare support?
MnemoShare provides control mappings for HIPAA, SOC 2, ISO 27001, NIST CSF, and is currently undergoing HITRUST r2 assessment. The compliance scoring dashboard shows real-time posture against these frameworks.
How long can audit logs be retained?
Retention is configurable from 90 days to 7+ years. HIPAA requires 6 years minimum; MnemoShare supports extended retention via SIEM export to WORM-capable S3 storage with Object Lock.

Ready to see MnemoShare in action?

Start a free trial, schedule a walkthrough, or dive into the docs.