A technical whitepaper for CISOs, compliance officers, auditors, and technical buyers in regulated enterprise and government.
Every compliance regime on earth rests on a single assumption: that the record of what happened is true. Yet the records most organizations rely on — application logs, audit trails, release histories, AI decision logs — are mutable, vendor-controlled, and unverifiable by the very people who need them most: auditors, regulators, and courts. When the evidence lives in a database the vendor can edit, "trust us" is the whole security model. That is not evidence. That is a promise.
ArmoredLedger replaces the promise with proof. It records what happened, who or what did it, on whose authority, and when — cryptographically. Every record is content-addressed and hash-chained. Every attestation is signed against a trust-anchor allowlist. Every day, the ledger's Merkle root is committed to the Bitcoin blockchain via OpenTimestamps — a third-party-verifiable proof that a record existed at a point in time, backed by the most expensive-to-forge ledger on earth. And anyone can verify any record themselves, in a browser, without trusting Armored Gate at all.
The thesis in four words: trust no one, verify everyone.
Audit logs today are broken as evidence for three reasons. They are mutable — a log in a database, object store, or SIEM is only as trustworthy as the administrator who controls it. They are vendor-controlled — verification means asking the vendor; the auditor cannot independently confirm the record shown today is the record written six months ago. They are unverifiable by the people who need them — an auditor cannot recompute a proprietary log's integrity; a court cannot distinguish a genuine timestamp from a plausible one. The gap is not a lack of logging. It is verifiable integrity.
/v1/authorize, the server-side PDP can prevent restricted activity before it happens.Nearly every modern control framework demands the same capability: a tamper-evident, attributable, time-stamped record of security-relevant events. ArmoredLedger is the substrate that satisfies those requirements. It is the control and the evidence; certification belongs to the customer's system and assessor.
| Framework | Strongest ArmoredLedger fit | Honest boundary |
|---|---|---|
| SOX (§302/§404/§802) | §802 records anti-tampering + change-management provenance as tamper-evident ITGC evidence | ITGC evidence, not a financial-reporting control |
| EU AI Act | Attested AI-action logging + Art. 50 labeling + Art. 14 oversight + model cards | Record-keeping layer, not a conformity assessment |
| NIST 800-53 | AU family (audit generation, protection, non-repudiation) via signed, anchored, append-only records | Validated-module consumer; control selection is the system owner's |
| NIST SSDF / 800-161 / EO 14028 | Build + supply-chain provenance, SBOM linkage, Bitcoin-anchored | Documented crosswalk; pipeline wiring for full coverage |
| CMMC / 800-171 | AU + non-repudiation for CUI environments | Not an assessment; doesn't encrypt CUI at rest |
| SLSA | Emits SLSA v1.0 provenance; exceeds transparency-log immutability via Bitcoin | No numbered level claimed (an orthogonal maturity axis) |
| FedRAMP | AU controls + continuous-monitoring evidence | Audit substrate, not an ATO |
| FIPS 140 | Signing in a FIPS 140-2 Level 3 HSM | Not a CMVP-certified module of ours |
| GDPR | Accountability + integrity; Art. 17 via salted hashes/pointers (never PII) + audited erasure | Correct usage (hash/pointer only) is a customer responsibility |
| HIPAA | Audit controls + a mechanism to corroborate ePHI integrity | Not the ePHI store; doesn't encrypt ePHI at rest |
| PCI-DSS v4.0 | Protect audit logs from modification + tamper/change detection; PDP prevents unauthorized change | CDE must emit the events |
| ISO 27001:2022 | Tamper-protected logging + trustworthy monitoring substrate + crypto integrity | An Annex-A control, not the ISMS |
| 21 CFR Part 11 | Secure, time-stamped audit trails + signatures cryptographically bound to records | System validation (CSV/CSA) is the customer's |
| DORA / SEC cyber | Tamper-evident, time-anchored incident evidence; external "when did you know" timestamp | Evidentiary backbone, not the disclosure decision |
Vendor logs ask you to trust the vendor. Transparency-log approaches still anchor trust in the operator's signed tree heads. ArmoredLedger anchors to Bitcoin — a public chain we don't run, can't edit, and can't take down — and puts verification in your hands. The moat is not "our logs are better," but "you don't have to believe us at all."
Trust no one. Verify everyone. — ArmoredLedger, by Armored Gate. Signing performed with a FIPS 140-2 Level 3 HSM; ArmoredLedger is the tamper-evident control and evidence, not a certification.