#Compliance #Audit

Effective date: August 1, 2026

12.1 Purpose

To maintain a reliable, tamper-evident record of sensitive actions taken across the Platform, supporting transparency, accountability, regulatory compliance, and effective incident investigation.

12.2 Events Captured

  • All authentication events: successful and failed login/logout attempts, password resets, OTP verification attempts.
  • Any modification of sensitive data: password changes, payment/payout detail updates, permission/role changes.
  • All booking lifecycle events: creation, price adjustment approval, payment, cancellation, completion, dispute filing.
  • Denied or unauthorized access attempts to any protected resource.
  • Any internal Personnel access to Level 3 or Level 4 data (per the Data Classification Policy), including read-only access during support or investigation activity.
  • Administrative actions: account suspension/termination, refund issuance, manual data exports.

12.3 Log Record Contents

Each audit log entry captures: precise date and time (UTC + local), the identity of the acting user/system/service account, the action type, the outcome (success/failure), the affected resource, and the originating IP address/device identifier.

12.4 Log Protection

Audit logs are themselves classified as Level 4 (Restricted) data. Logs are written in an append-only format and cannot be edited or deleted by any individual, including system administrators, to guarantee their integrity as a source of truth during investigations.

12.5 Retention and Review

  • Audit logs are retained for a minimum of one year, and longer where retained specifically as evidence under Section 10.
  • Automated monitoring rules flag anomalous patterns (e.g., repeated failed logins, unusual-hours access to Restricted data, mass data-export attempts) for real-time alerting.
  • A manual review of high-risk log categories (Level 4 access, administrative actions) is conducted on a regular scheduled basis by the designated security owner.

12.6 Access to Audit Logs

Access to the audit log system itself is tightly restricted and subject to the same dual-approval controls described in the Access Control Policy (Section 8.5), given the sensitivity of the information it contains.