Skip to main content

Overview

Auditability & AI Governance covers transparency, accountability, audit readiness, and evidence sources for Zylon deployments. It is separate from platform security: security protects the platform; auditability explains how customers can show what happened, preserve evidence, govern AI usage, and support assurance workflows. Use this section when security, risk, compliance, legal, works-council, or audit teams need to understand what Zylon records, how evidence can be preserved, which controls are customer-configurable, and how Zylon can provide evidence for customer governance programs.

Capability areas

Start here

Logging, Evidence, and SIEM Delivery

Governance view of Zylon logs, evidence preservation, data residency, control mappings, retention, and SIEM delivery.

Log Delivery Configuration

Technical settings for internal storage, syslog delivery, HTTP delivery, filtering, queues, TLS, and retention cleanup.

Backoffice Logging API

Read-only retrieval endpoints for stored platform, gateway, security, workspace, backoffice, and AI usage logs.

Hard Delete and Retention

Configure permanent deletion windows and stored-log cleanup behavior.

Suggested governance workflow

  1. Classify your AI use cases and decide which events, prompts, responses, usage metrics, and operational records must be retained.
  2. Enable the required audit and logging capabilities, then configure retention windows and external delivery.
  3. Send logs to a customer-controlled SIEM, archive, or data lake when independent retention or tamper-evidence is required.
  4. Define who may retrieve logs with the operator role and how and when they were exported.
  5. Map collected evidence to your control framework, such as EU AI Act, ISO 27001, SOC 2, DORA, NIS2, or GDPR.
  6. Review retention, masking, prompt/response handling, and user-rights processes before production rollout.

Security boundary

Security documentation remains focused on hardening the deployment: network isolation, airgap operation, encryption, access controls, and platform protection. Auditability & AI Governance focuses on proof and accountability: traceability, evidence, monitoring, control mapping, AI usage review, and regulatory readiness. Many programs need both sections during procurement and production assurance.