Evidence Chain
Tamper-evident, HMAC-sealed hash chain for every event, with checkpoints anchored to an external RFC 3161 timestamp authority. Exports evidence packages (JSON / PDF) you can hand to an auditor.
A stream shows as verified only after you run Verify on it, and the dashboard shows when it was last checked. Integrity is not re-checked automatically.
curl -X POST https://audit-api.qntyx.io/entries/ \
-H "Authorization: Bearer YOUR_API_KEY" \
-H "Content-Type: application/json" \
-d '{"stream_id": "YOUR_STREAM_ID", "actor": "alice", "action": "login", "resource_type": "session", "resource_id": "web"}'
https://audit-api.qntyx.io
| Method | Path | Description |
|---|---|---|
POST | /entries/ | Create a log entry |
GET | /entries/ | List entries |
GET | /streams/ | List streams |
GET | /evidence/{package_id}/json | Download an evidence package (also /pdf, /summary; create one with POST /evidence/generate) |
GET | /stats/ | Dashboard statistics |
All endpoints require a bearer token. See Authentication for details.
Manage this product visually at app-audit.qntyx.io
Learn more at audit.qntyx.io