Reguly
Reguly Docs

Insights

Audit log

The audit log is your gap-free chronicle of all changes to compliance-relevant data: who edited a product when? Which values were changed in the packaging-register report when? Which DOC was created when — and at which version? Audit-safe, not editable, exportable.

Plan upgrade required

Why do you need the audit log?

  • Audits: Auditors often want to see your data has been maintained consistently. The audit log is the proof.
  • Internal reviews: Colleagues can trace which values were changed by whom and when — important in data conflicts.
  • Compliance checks: On authority requests you can show within seconds when a particular DOC was created.
  • Error hunting: When a value suddenly looks wrong, the audit log helps find the cause.

What is logged?

Reguly logs every mutation in the following areas:

  • Master data (brand, products, substances, packaging components)
  • PPWR data (roadmap status, quantity reports, DOC generations)
  • DPP data (creation, publication, update)
  • Vault operations (upload, delete, restore)
  • Data hub actions (requests, answers, updates)
  • Account changes (plan, members, roles)

What is not logged

Pure read actions (open page, view report) are not logged. The audit log focuses on content changes.

How do I use the log?

  • Filter by area (PPWR, DPP, master data …), by member, by period.
  • Detail view: per entry you see old and new values (diff view).
  • Export as CSV or PDF (e.g. for handing over to an audit).
  • Search full-text: quickly find when a particular GTIN or supplier was changed.

Tamper-resistance

Audit-log entries cannot be edited or deleted — not even by admins. Every entry is signed with a hash; on audit handover Reguly issues a certificate of authenticity on request.

FAQ

Are password changes logged?
Account security events (login, password reset, session expiry) are kept in a separate security log — separate from the compliance audit log. Both are visible to admins.
How long is audit data kept?
7 years. Reguly thereby meets the retention requirements of most European compliance regimes. When you need longer periods, export the data regularly.
Can external auditors get access?
Yes — you can generate time-limited 'audit links' that allow an external auditor read-only access without their own Reguly account. The link expires automatically after the configured period.
What happens when I cancel?
We recommend a full export of audit data as CSV before cancelling. Reguly then keeps the data 30 days in read-only mode; after that it is deleted.

Related pages