Audit & evidence

Audits in minutes, not days.

The Evidence Ledger keeps a tamper-proof record of everything that happens in MahCare AI — what happened, who did it, with what permission, and under which policy. So when an auditor, regulator or patient asks, the proof is already assembled — not scattered across inboxes and shared drives.

What the Ledger records

Six things it records, automatically.

01

Administrative actions

Every administrative action — creates, updates, deletes, state transitions — with actor, timestamp, and source context.

02

Sign-ins

Every sign-in — when, from where, on what device, by what method, and whether it succeeded.

03

Policy changes

Every policy, role, and configuration change with a structured diff and an approver on record.

04

AI decisions

Every AI decision with model, prompt version, source evidence, reviewer, and downstream effects.

05

Workflow transitions

Every workflow state transition linked back to the plan version and rule that allowed it.

06

Patient data access

Read-level auditing: who looked at which record, when, under what authority, and for how long.

Compliance workflows on top

Every compliance chore, ready to run.

The Ledger is not just a log — the compliance jobs you dread are built on top of it, ready to run.

Subject-access requests

Find everything held about a person, compile it, review, redact, approve and export — turning the usual quarterly scramble into a job that takes minutes.

Legal hold

Hold scoped by patient, episode, document, or investigation. Overrides retention, tracks approvers, and releases only on signed authority.

Access review

Dormant-user controls, segregation-of-duties enforcement, privilege session review, and periodic attestation queues.

Automatic retention

Set how long different data is kept — by type, legal basis and country — and let MahCare delete it on schedule, with evidence, instead of manual clean-up.

Emergency access

Urgent access needs a reason, an approval and an expiry — and every such session is reviewed afterwards, with the record kept.

Incident packs

Investigation and corrective-action templates, with the evidence pulled together for you — so responding to an incident never starts from a blank page.

Verification & independence

Proof an outside auditor can check directly.

Independent review

Audit outputs are reviewable without application access. Auditors see evidence directly, not via a staff user in the UI.

Tamper-proof

Entries are locked together so any change after the fact shows up immediately. It is on by default, not an optional extra.

External export

Every record can be exported to outside audit systems in standard formats.

Feeds your security tools

Sends events straight to your security monitoring tools, so your security team never has to ask for a data pull.

Retention evidence

Automated deletion jobs emit structured evidence records: what was deleted, under which policy, on whose authority, with what legal basis.

Deletion evidence

Right-to-erasure, contract-end deletion and offboarding run as productised flows — every removal produces a signed, exportable completion artefact.

Why this matters commercially

Trust as a sales asset, not a liability.

Compliance as product

Compliance becomes productised surface, not a fire drill. You do not build DSAR workflows; you use them.

Audit in minutes

Audit preparation drops from days to minutes. The evidence is already assembled, indexed, and filterable.

On-demand packs

Regulatory evidence packs generated on demand from a single pane. No scavenger hunt across shared drives.

Trust as an asset

Trust becomes a sales asset. You win deals with the audit story, not survive them despite it.

Procurement acceleration

DTAC, DSPT and security questionnaires answered from the ledger directly — evidence pulls replace weeks of manual assembly.

Incident credibility

When something does go wrong, the post-incident pack is already complete: timeline, actors, decisions, remediations. Credibility is defensible.

Evidence Ledger

See a DSAR run end-to-end.

The fastest way to understand the Ledger is to watch a DSAR workflow run on the sample tenant. We demo it live.