7.4.1 Immutable Audit Logs. The Platform generates security, access, and audit logs to ensure system integrity, traceability, and compliance. Such logs may include user actions, authentication events, configuration changes, and approval records.
7.4.2 Separate Retention Logic. Audit logs and compliance records are retained for longer periods than general Customer Data where necessary to meet security, audit, or regulatory requirements (e.g., to reconstruct the details of a financial approval for tax audits).
7.4.3 Restricted Use. Audit logs are used solely for security monitoring, compliance, incident investigation, and audit purposes and are not used for analytics, profiling, or customer-facing features.
7.4.4 Access Controls. Access to audit and security logs is strictly limited to authorized personnel and protected by enhanced access controls.