Audit Log Management

Purpose 

The purpose of this policy is to create, store, and analyse log files with the goal of detecting and responding to any suspicious or abnormal events that may occur within the organisation. It also allows for the prioritising, and remediating of any potential vulnerabilities in enterprise systems and software. The audit log management policy provides the processes and procedures for ensuring logs are created and properly analysed. This policy applies to all Evercam departments and critical assets.

Responsibility 

The Engineering and BizOps departments are responsible for all log management functions. Specifically, administrators are responsible for configuring the correct devices to generate, store, and transmit logs. Assigned Team Leads are responsible for informing all users of their responsibilities in the use of any assets assigned to them, such as applying updates in a regular manner or restarting their systems. All Evercam assets are required to comply with this audit logging procedures.

Policy 

Generation

  1. Establish and document a company-wide strategy to manage and maintain an audit log process. 

  2. Review and update the strategy annually or upon significant change.

  3. Specify log contents.

  4. Enable audit logging on Evercam critical assets where practical.

  5. Do not disable audit logs on Evercam critical assets.

Transmission 

  1. Procedures must be developed to move logs from Evercam critical assets to an audit log datastore. 

  2. Logging system (Engineering docs) details the procedures created to move logs from enterprise assets to a remote datastore.

Storage

  1. All Evercam assets (servers, apps, edge devices) generate logs in json format locally.

  2. Promtail is used to collect local logs from different sources (system, apps, files) and push them to logs data store. Loki, a log aggregator, ensures logs management, querying, storage, and retention, etc.

  3. Sufficient storage space must be allocated for audit logs for the period of time required for analysis and retention. 

  4. Sufficient space must be allocated to store audit logs on all Evercam assets. 

  5. Sufficient space must be allocated to store audit logs on any centralised audit log datastore. 

Review and Analysis 

  1. Respond to all high-severity events immediately, following the defined audit log management process.

  2. Define audit log retention periods in accordance with the Evercam data management process.

  3. General Retention & Availability:

    • Logs are retained for a minimum of three (3) months.

    • The most recent month's logs are immediately available for review and analysis.

    • Logs from the previous two (2) months are archived.

  4. Access and Integrity:

    • Implement strict access controls to prevent unauthorised modification of audit logs.

    • Logs, once stored, must be immutable (cannot be modified).

    • The only authorised interface for querying general logs is Grafana (with implemented access control).

  5. Specific audit logs (e.g., Camera logs) must be retained and available for the entire duration of the project they support. Access to these logs is limited to Evercam employees via the Evercam Admin.

Disposal 

  1. All audit logs must be stored for a period of time specified by the audit log management process. 

  2. Archived logs can be available for analysis.

  3. Disposal of audit logs should be in accordance with the Evercam data management process.

Summary of Evercam Log management Systems

Log management system

Purpose (Use case)

Who reviews it (Teams)

Review process

Retention period

Evercam Software Admin

Internal admin console for managing Evercam projects, cameras, and user accounts.

Project & camera configuration logs

User/account management activity

Engineering

Reviewed via the Admin interface


Dashboard on Grafana

12 months as per SOC2 requirement

  • 1 month in queryable state.

  • Retained for 12 months as archives.




Evercam Software Dash

Customer-facing dashboard where clients view camera feeds and project data.

User access & activity logs

Client-facing usage tracking

Engineering & CS


Reviewed via the Dashboard analytics


Dashboard on Grafana

12 months as per SOC2 requirement

  • 1 month in queryable state.

  • Retained for 12 months as archives.



Heroku (databases)

Hosted database platform used for select Evercam services.

Database access logs

Deployment & release logs

Engineering

Reviewed via the Heroku dashboard


Dashboard on Grafana

12 months as per SOC2 requirement

PostgreSQL (own-databases)

Self-hosted PostgreSQL instances managed directly by Evercam.

Database access & query logs

Schema/config change logs

Engineering

Reviewed via database logs/audit extensions


Dashboard on Grafana


12 months as per SOC2 requirement

SeaweedFS

Distributed file storage system used for camera images/video and other files.

File storage access logs

Upload/retrieval activity

Engineering

Reviewed via SeaweedFS logs


Dashboard on Grafana


12 months as per SOC2 requirement

—————————————————————

Created by: Compliance Manager (ISMS team)

Creation date: 17.02.2023

Last modification date: 24.09.2026

Document approver: Chief Technology Officer