A tamper-evident log is the foundation of every other promise on this page.
An audit log you cannot edit2
Even an administrator account compromised by a sophisticated attacker cannot delete or modify the audit trail. Postgres Row-Level Security policies block UPDATE and DELETE on AccessLog, AIUsageLog, and GradeChangeLog. Enforced at the database layer, not the application code.
