SemantiqWall
PT EN
Entrar Sou fornecedor

← Central de confiança

Logging and Monitoring

Documento em inglês

Versão
1.0
Responsável
Founder
Aprovada por
Murilo Martins (Founder) · 28/09/2026
Próxima revisão
2027-09-28 (annual or on significant change)
Escopo
The application audit log, application logs, web server logs and server logs of the SemantiqWall production environment.

1. Log sources

Source Content Where Retention
Audit log (application) Security-relevant events, one hash-chained sequence per organization plus one for the platform PostgreSQL table audit_events See section 4
Application log Errors and warnings Daily files on the server 14 days (automatic rotation)
Web server log HTTP requests (IP address, time, path, status) Caddy log file on the server Not yet configured (section 4)
System logs SSH logins, fail2ban bans, package updates Ubuntu journal and /var/log Ubuntu defaults

2. What the audit log records (in place)

Each event records: organization, actor type and ID, action, subject, context, IP address, browser user agent, UTC timestamp with microseconds, the previous event's hash and its own SHA-256 hash.

Events include:

Never logged: passwords, MFA secrets, API tokens or other secrets. Agent action parameters are masked before storage (tax IDs, e-mails, phone and card numbers masked; password, token, secret, API key, authorization and cookie fields removed; long text cut).

3. Protection of the audit log

4. Retention

5. Access to logs

6. Time synchronization (in place)

The server clock is synchronized by NTP. All timestamps in the database and the audit log are stored in UTC; the interface only converts them for display.

7. Monitoring and alerts

In place: automatic audit-chain verification (result shown in the panel); fail2ban on SSH; automatic security updates; Hostinger's server-side malware scanner (Monarx) runs on the VPS - who receives its alerts is to be confirmed.

Not in place (disclosed): there is no automated alerting today. Nobody is paged if the site goes down, the disk fills, the scheduler stops or the audit chain fails verification.

Commitments (owner: Founder):

8. Review