Insights
Audit log
The audit log is your gap-free chronicle of all changes to compliance-relevant data: who edited a product when? Which values were changed in the packaging-register report when? Which DOC was created when — and at which version? Audit-safe, not editable, exportable.
Plan upgrade required
Why do you need the audit log?
- Audits: Auditors often want to see your data has been maintained consistently. The audit log is the proof.
- Internal reviews: Colleagues can trace which values were changed by whom and when — important in data conflicts.
- Compliance checks: On authority requests you can show within seconds when a particular DOC was created.
- Error hunting: When a value suddenly looks wrong, the audit log helps find the cause.
What is logged?
Reguly logs every mutation in the following areas:
- Master data (brand, products, substances, packaging components)
- PPWR data (roadmap status, quantity reports, DOC generations)
- DPP data (creation, publication, update)
- Vault operations (upload, delete, restore)
- Data hub actions (requests, answers, updates)
- Account changes (plan, members, roles)
What is not logged
Pure read actions (open page, view report) are not logged. The audit log focuses on content changes.
How do I use the log?
- Filter by area (PPWR, DPP, master data …), by member, by period.
- Detail view: per entry you see old and new values (diff view).
- Export as CSV or PDF (e.g. for handing over to an audit).
- Search full-text: quickly find when a particular GTIN or supplier was changed.
Tamper-resistance
Audit-log entries cannot be edited or deleted — not even by admins. Every entry is signed with a hash; on audit handover Reguly issues a certificate of authenticity on request.
FAQ
Are password changes logged?
Account security events (login, password reset, session expiry) are kept in a separate security log — separate from the compliance audit log. Both are visible to admins.
How long is audit data kept?
7 years. Reguly thereby meets the retention requirements of most European compliance regimes. When you need longer periods, export the data regularly.
Can external auditors get access?
Yes — you can generate time-limited 'audit links' that allow an external auditor read-only access without their own Reguly account. The link expires automatically after the configured period.
What happens when I cancel?
We recommend a full export of audit data as CSV before cancelling. Reguly then keeps the data 30 days in read-only mode; after that it is deleted.
Related pages

