Who changed what,
On the Record
A tamper-evident trail of the account changes auditors ask about — who created an API key, who changed the IP allowlist, who added a teammate, who touched SSO — each entry attributed and timestamped, ready for your next compliance or vendor-security review.
Last updated on 6th August 2026
An audit log is an append-only record of the security-relevant things that happen in your account — not the day-to-day deployments, but the changes that alter who can access what. Every entry names the person who made the change and when, so months later you can answer "who did this, and when?" without guesswork or a support ticket.
What Gets Recorded
The security-relevant account actions reviewers ask about — captured automatically.
API Keys
When a key is created or revoked, and by whom — so a leaked or forgotten token has a paper trail.
IP Allowlist
Every change to the ranges permitted to reach your account, with the before-and-after captured.
Team & Roles
Members added or removed and role changes — the access changes an auditor will always ask to see.
SSO & SAML
Changes to your identity-provider configuration, so nobody quietly re-points authentication.
Attribution & Timestamps
Every entry is tied to the user who made the change and the exact time it happened — in UTC, unambiguously.
Why It Matters
The difference between "we think so" and "here's the record."
Tamper-Evident by Design
The log is a record of what happened, not a document anyone can quietly edit after the fact. That's exactly the property auditors and security reviewers are looking for.
Answers Vendor-Security Reviews
When a customer's security team asks how you control access and prove changes, the audit log is the artefact you point to — no scrambling, no screenshots.
Clear Attribution
Every change names a person and a time. Access reviews, offboarding checks, and incident timelines stop being detective work.
Ready for SOC 2 & ISO 27001
An attributed trail of access and configuration changes is table stakes for these frameworks — the audit log is where you evidence them.
Built For
The moments a record beats a memory.
Compliance & audits
SOC 2 and ISO 27001 reviewers expect an account-level trail of access and configuration changes. The audit log gives you one place to produce it.
Vendor-security reviews
Your customers' security teams send questionnaires about how you manage keys, access, and authentication. Point to the record instead of writing prose.
Incident investigation
When something looks off — an unexpected key, a new allowlisted range — the log tells you who changed what and when, so you can act on facts.
Find your audit log
Open your account settings
The audit log lives alongside your account's security settings — no configuration needed to start recording.
Review recent activity
Scan API-key, allowlist, team, and SSO changes in one timeline, each attributed to the person who made it.
Hand it to your reviewers
Use it as the evidence trail for access reviews, vendor-security questionnaires, and compliance audits.
Frequently Asked Questions
What does the audit log record?
Security-relevant account actions: API keys created or revoked, IP allowlist changes, team membership and role changes, and SSO/SAML configuration changes. Each entry is attributed to the user who made the change and timestamped. It is not a log of individual deployments — it is the record of changes to who can access your account and how.
What makes it "tamper-evident"?
The audit log is a record of what happened rather than a document anyone can quietly edit after the fact — the property auditors and security reviewers rely on when they ask you to evidence access and configuration changes.
How does this help with compliance and vendor-security reviews?
Frameworks like SOC 2 and ISO 27001, and the security questionnaires your customers send, expect a centralised trail of access and configuration changes with clear attribution. The audit log is the single artefact you point them to instead of assembling screenshots.
Who can see the audit log?
Access to the audit log is scoped to account administrators. If you have specific requirements around who should be able to review it, get in touch and we'll walk through the options for your account.
Which plans include the audit log?
Audit Log availability is shown in the plan comparison on our pricing page — check there for the plans it's included on, or contact us and we'll talk through what fits your team.
Turn "we think so" into "here's the record"
Give your next compliance or vendor-security review a straight answer instead of a scramble.
10-day free trial • No setup fees • Cancel anytime
Explore More Features
Discover all the tools that make DeployHQ the easiest way to deploy your code.
Zero Downtime Deployments
→One-Click Rollback
→Turbo Deployments
→Build Pipelines
→Build Cache
→Scheduled Deployments
→Deployment Availability
→Docker Builds
→Deployment Checks
→Deployment Targets
→Automatic Deployment
→Deployment Templates
→Deploy Behind Firewalls
→SSH Deployment
→Deployment Zones
→Team & Permissions
→Single Sign-On
→Custom Actions
→Server Management
→Audit Log
→CLI & Agents
→Powerful Integrations
→Get started today for just $9/month
That's unlimited deployments and 3 projects.