Audit Trail & Data Retention

Tamper-proof logging with flexible retention periods to meet your compliance needs

Why Audit Trails Matter

OptiCloud records every system action — logins, configuration changes, resource provisioning, cost queries, and administrative operations — in tamper-proof audit trails. These logs are immutable, timestamped, and stored in EU-hosted infrastructure.

Comprehensive audit trails are essential for regulatory compliance, security incident investigation, and demonstrating accountability to auditors and stakeholders.

What We Log

Authentication Events

Login attempts, logouts, SSO sessions, MFA challenges, and failed access attempts

Resource Operations

Provisioning requests, approvals, modifications, and decommissioning of cloud resources

Cost & Billing

Cost report generation, budget threshold alerts, chargeback assignments, and sync operations

Administration

Role changes, permission updates, provider connections, system configuration changes

Data Access

Who accessed which reports, dashboards, and sensitive cost data, with timestamps

API Activity

External API calls, webhook deliveries, and integration events with cloud providers

Retention Plans

Standard

2 Years

Included with all OptiCloud plans

  • Full audit trail for all system events
  • Search and filter by user, action, or date
  • Export to CSV/JSON for external analysis
  • Real-time audit log dashboard
  • Email alerts for critical events

Extended

Add-on
Up to 5 Years

Additional service for regulated industries

  • Everything in Standard
  • Configurable retention (3, 4, or 5 years)
  • Dedicated archival storage in EU data centers
  • Compliance-ready reports (SOX, NIS2, DORA)
  • Priority support for audit inquiries
  • Custom retention policies per data category

Audit Log Security

  • Immutable write-once storage — logs cannot be modified or deleted
  • AES-256 encryption at rest, TLS 1.2+ in transit
  • Stored exclusively in EU-based data centers
  • Cryptographic hash chains for tamper detection
  • Role-based access — only authorized auditors can view logs
  • Automated integrity verification checks

Compliance Frameworks Supported

GDPR (Art. 5, 30)

Records of processing activities and accountability documentation

ISO/IEC 27001 (A.8.15)

Centralized logging with tamper-proof audit trails and monitoring

NIS2 Directive

Incident reporting evidence and security event documentation

SOX / Financial Audit

Change tracking and access logging for financial data integrity

Need extended retention?

Contact our sales team to discuss extended retention options tailored to your organization's compliance requirements.

Last updated: March 2026