Append-only, tamper-evident audit records
Prior audit entries are retained rather than overwritten, supporting examination of recorded activity.
SHA-256 content hashing
Supplied artifacts receive content hashes so the version referenced in an assessment record can be identified.
Authenticated access controls
Application access requires authentication and is governed by assigned permissions.
Tenant segregation using Postgres RLS
Postgres row-level security policies support data separation between application tenants.
Preserved classification path
Deterministic risk classification retains the decision inputs and resulting path for examination.
Human-verified evidence relationships
Hybrid evidence candidate mapping is followed by human acceptance, rejection, or qualification.