Back to home

Reporting

Audit Logs

Findings, alerts, and enforcement actions logged with a timestamp, device, and actor. 12-month retention, exportable, with full risk history per extension.

What gets logged

Findings

Each extension finding - new detections, score changes, and resolved issues - is logged with the technical evidence behind it: code snippets, network destinations, and the specific behavior that triggered the flag.

Policy actions

Enforcement events - block, warn, exemption granted, exemption revoked - are logged with the policy that triggered them, the device they applied to, and the authenticated actor who reviewed them.

Alert history

A timeline of alerts sent through AIBP - to whom, when, and what action was taken. Closed-loop evidence that your team responded to each finding within your defined SLA.

When did this extension turn bad?

Each monitored extension in your fleet has a timeline: first seen, version updates, risk score changes, and findings. When an incident occurs, you can pinpoint the exact version and date a previously-clean extension started exhibiting malicious behavior - essential for incident response and legal discovery.

Retention and export

  • 12-month log retention as standard
  • Coverage statement confirming which devices were monitored and for what period
  • Exportable as JSON or CSV for SIEM ingestion
  • Filterable by date range, device, extension, or event type
  • Write-once log entries with export hash digest for integrity verification

Full audit trail, no extra tooling.

Logs are available from day one.