QNSI platform
What is Audit chain?
QNSI audit-service source defines hash chaining, SHA3-512 Merkle aggregation, and ML-DSA checkpoint signing. Complete ingestion from every producer, root publication, and reconstruction of each historical operation require deployment evidence and remain NOT VERIFIED until recorded.
Decision context
Why Audit chain matters
A cryptographically linked audit chain can make deletion, insertion or modification detectable, but it does not guarantee that every relevant event was captured or that the signer and checkpoint were trustworthy. Coverage, ordering, anchoring, retention and independent verification all remain necessary.
How to evaluate Audit chain
Recompute hashes and tree or chain links from exported records, verify checkpoint signatures against an independently published key, and test missing or reordered events. Trace representative production operations into the chain and confirm retention, tenant separation, rotation and recovery behaviour.
QNSI platform
QNSI platform evidence boundary
QNSI platform terms describe intended control or evidence boundaries. Their presence in documentation is not proof that a customer deployment executed them. Verify the selected service path, tenant policy, custody provider, production record, and independent evidence before relying on the term in an assurance decision.
FAQ
Common questions
What is Audit chain?
QNSI audit-service source defines hash chaining, SHA3-512 Merkle aggregation, and ML-DSA checkpoint signing. Complete ingestion from every producer, root publication, and reconstruction of each historical operation require deployment evidence and remain NOT VERIFIED until recorded.
Why does Audit chain matter?
A cryptographically linked audit chain can make deletion, insertion or modification detectable, but it does not guarantee that every relevant event was captured or that the signer and checkpoint were trustworthy. Coverage, ordering, anchoring, retention and independent verification all remain necessary.
How should Audit chain be evaluated?
Recompute hashes and tree or chain links from exported records, verify checkpoint signatures against an independently published key, and test missing or reordered events. Trace representative production operations into the chain and confirm retention, tenant separation, rotation and recovery behaviour.
More