Audit evidence
Proof you can hand an auditor, not just claims.
Anyone can say a deletion happened. From 2028, you have to show it to an independent auditor. Lethe builds evidence that someone outside your company can verify, which is the difference between a record and a defensible record.
The problem
A log you control by yourself proves nothing to a skeptic.
Most compliance tools keep a local log of what they did. The trouble is that a log on a machine you control can be edited or regenerated, and an auditor knows that. If the only thing backing your deletion history is your own word, you have a record that is easy to keep and hard to rely on.
The fix is a witness outside your control. Lethe chains each cycle's record so any edit to an old entry breaks the chain, then anchors the head of that chain to a neutral third party that cannot be backdated. Now the record is not just internally consistent. It is provable to an outsider.
Evidence grades
Four grades, each labeled for exactly what it proves.
Lethe's verifier never prints a bare pass. It tells you the grade and what it rests on, so a green result means the same thing to your auditor as it does to you.
| Grade | Mechanism | What it proves |
|---|---|---|
| A | Publicly anchored (public timestamping chain) | Independently verifiable by anyone, with no party you control involved. |
| B | TSA anchored (RFC 3161 timestamp authority) | A neutral third-party time notary. The default, and what most audits accept. |
| C | Hardware-rooted (air-gapped, TPM or HSM counter) | Strongest on-premise option. Tamper-evident against anyone who cannot rewind the hardware. |
| D | Internal chain only | Tamper-evident against edits, but self-witnessed. An honest floor, not a passing grade. |
A fully air-gapped broker cannot have public proof, because nothing leaves their network. We will not pretend otherwise. We give them the strongest on-premise grade and state its ceiling out loud, so no one mistakes Grade D for something it is not.
The verifier
Anyone can check the proof. That is the point.
The checker is open
The tool that verifies an audit package is free and shareable. Your auditor, your lawyer, or a prospect can run it themselves and get a pass or fail. The tool that generates a package stays licensed.
Not just the local chain
Verification confirms the external anchor, not only the internal chain. It tells you which, because internal-chain-intact is a weaker statement than anchored-and-verified.
The audit is the deadline
The first independent audit lands in 2028 and recurs every three years. You cannot reconstruct two years of compliance after the fact. The evidence is generated cycle by cycle, starting now.
No green it would be wrong to trust
The verifier reports the grade and the underlying mechanism every time. We would rather show a modest, accurate result than a confident, misleading one.
Find out what your current evidence is worth.
A readiness assessment includes an honest read on whether what you have today would survive the 2028 audit.