Home › Features › Audit Trail
Features · append-only, indefinite

Every movement, with its whole story

The audit that writes itself — append-only, retained indefinitely

Each transaction request carries a per-transition trail: created, policy-evaluated, approved by whom, broadcast, mined — timestamped at every step. Fund and key actions land in an append-only log that is a platform invariant, not a feature toggle.

Share the Trust, Guard the Keys

Create accountLive on testnet in an afternoon
Compare PlansIncluded in a plan, not an add-on
The problem

An audit trail assembled after the fact is a reconstruction, not evidence

When a reviewer asks who moved $2M on a Tuesday, screenshots and a group chat are not an answer. Vaultody records each transaction request as it happens — its policy evaluation, who approved it, when it broadcast, when it mined — and exports it in a form your auditors can read without you in the room.

  • Per-request, per-stateEvery state transition is recorded with its timestamp, not summarised at the end.
  • Approvals attached to the movementThe approval that authorised a transfer is part of that transfer's record, not a separate log to correlate.
  • Exportable, not screenshot-ableTransaction history exports as CSV for reconciliation and for the auditor's own tooling.

How it works

Evidence, pre-assembled

A transfer's record includes its policy evaluation and each approver's decision — the exact artifact compliance reviews ask for. Operational logs (deliveries, logins, events) are retained indefinitely with no purge.

  • Immutable by invariant — no edits, no deletions
  • Who initiated, which rule fired, who confirmed, when it mined
  • CSV export and API access for reporting pipelines
one transfer — full trail
created 09:14:02 · api-key ops-1 policy >$100k → 2 approvals required approved 09:16:44 · maria · mobile co-signer approved 09:21:03 · james · mobile co-signer broadcast 09:21:09 · 0x9d2e… mined 09:22:31 · block 21384402
Specification

What is recorded

Plus the one place the coverage is still thin.

Transaction lifecycleCreation, policy evaluation, each approval, broadcast and mining — with timestamps.
ApprovalsWhich user approved, under which rule, and the quorum that applied.
Access historyLogin history including source address and device metadata, retained for years.
Webhook evidenceCallback logs record what we sent to your endpoint and what it answered.
ExportsCSV transaction exports per vault and per period.
API statisticsAPI request statistics are retained on a rolling window of roughly 90 days.
ImmutabilityRecords are append-only — states are added, never edited away.
Honest gapA single unified log of every dashboard administrative action is not complete today; transaction, access and delivery evidence are.

Frequently asked questions

Get answers to commonly asked questions.

How far back does history go?

Transaction and operational logs are retained indefinitely — no scheduled purge.

Can we pull it programmatically?

Yes — via API and CSV export, per-tenant.

Which plans?

All of them.

Share the Trust Guard the Keys

When the auditors come, the evidence is already assembled.