Assay
Evidence and assurance
Mission impact
An ordinary log says what the application reports it did. Assay gives your organization a record that can be shown not to have been altered since it was written, and states plainly what that record cannot establish.
What Assay is
Assay is the evidence and assurance platform. It keeps tamper-evident records of the system actions your organization needs to account for, checks their integrity, and exports evidence a reviewer can test rather than accept on trust.
What you get
- Records chained by hash, so a later insertion, deletion or edit breaks the chain and an independent check detects it. With a signing key configured, forging a repair also requires the key.
- Verification that exits non-zero and names the failure class, so it can stop a deployment or raise an alert without parsing output.
- Scheduled verification that records a durable verdict and raises an event on failure without modifying the chain.
- Four named verdicts: a broken chain, an unsigned range, a broken seal and a foreign seal. Each calls for a different operational response.
- Data-minimized evidence export to a destination you nominate. Export stops while verification is failing.
- Key rotation with retired keys retained, so earlier history stays verifiable.
Audit Chain is its published component
Audit Chain is Assay’s published Drupal component, available as open source on drupal.org. Assay is the surface around it: the systems that write to the record, verification as an operating control, independent anchoring where the threat model requires it, and evidence custody and export.
Where it sits
Sentinel decides what an agent may do. Paladin establishes who the principal is. Assay supports verification of the resulting record. Several systems can write to it, including Sentinel, Chronicle, File Gate and Moneta, and coverage and failure behavior are defined for each integration. Assay runs on an estate built with Keystone, and it also installs where Keystone does not.
What the record can establish
Integrity checks detect changes within their defined coverage. They do not prove that every event was captured or that a producer reported the truth. Each integration states its actor source, event coverage, signing mode, key custody and behavior when recording fails. History that cannot be made to verify is sealed and labeled, never re-chained to look verified.
The minimized export does not carry the full event metadata, so it is not a self-contained bundle for recomputing every original record. Some checks still require the source system. Assay does not confer certification, and it is not a write-once store, a records-management policy, a SIEM or a replacement for backups.
The practice behind this platform
Evidence & Assurance Engineering is the practice behind Assay. Compliance & Security Governance owns the policies and control responsibilities those records support.
Key capabilities
Tamper-evident record
Each entry is chained to the one before it, so a later change is detectable.
Verification as a control
A failed check exits non-zero and names the failure class.
Scheduled verdicts
Routine checks record a durable result and raise an event on failure.
Bounded export
Data-minimized evidence goes only where you send it, and stops while verification fails.
Key rotation
Retired keys are retained so earlier history stays verifiable.