# AuditKit > Open-source, tamper-evident audit logging for B2B SaaS. Ship immutable, tenant-scoped audit trails in minutes, not sprints. ## What AuditKit Does AuditKit is a drop-in audit logging platform for B2B SaaS applications. It provides tamper-proof event recording using SHA-256 hash chaining and Merkle tree proofs, tenant-scoped log isolation, an embeddable React viewer component, and compliance-ready exports for SOC 2, ISO 27001, HIPAA, and GDPR. ## Free Tools (no signup required) - Compliance Framework Comparison: /tools/compliance-comparison — Compare SOC 2, ISO 27001, HIPAA, GDPR, FedRAMP, PCI DSS, CMMC, DORA, NIS2, SOX, and EU AI Act side-by-side. Up to 4 frameworks at once. Real data sourced from primary regulatory texts (AICPA, ISO/IEC, NIST, 45 CFR 164, PCI DSS v4.0). - All free tools: /tools ## Framework × Industry Matrix Pages (16 pages) High-buyer-intent audit-logging guides for specific framework + industry combinations: - /audit-for/soc2-for-fintech - /audit-for/pci-dss-for-fintech - /audit-for/sox-for-fintech - /audit-for/dora-for-fintech - /audit-for/iso27001-for-fintech - /audit-for/hipaa-for-healthcare - /audit-for/soc2-for-healthcare - /audit-for/gdpr-for-healthcare - /audit-for/iso27001-for-healthcare - /audit-for/soc2-for-edtech - /audit-for/gdpr-for-edtech - /audit-for/iso27001-for-edtech - /audit-for/fedramp-for-govtech - /audit-for/cmmc-for-govtech - /audit-for/soc2-for-govtech ## Key Capabilities - **Tamper-Proof Logging**: SHA-256 hash chain with Merkle tree cryptographic proofs. Every event is linked to the previous one. Any modification breaks the chain. - **Tenant-Scoped Access**: Each customer gets isolated, queryable audit logs. Multi-tenant by design with PostgreSQL advisory locks for concurrency safety. - **Embeddable Viewer**: Drop-in React component that renders audit logs directly in your customer-facing dashboard. - **SIEM Streaming**: Forward events in real-time to Splunk, Datadog, Elastic, and other SIEM platforms. - **Multi-Language SDKs**: TypeScript, Python, Go, and Java SDKs with full type safety. - **Self-Hostable**: Run on your own infrastructure with Docker Compose or use the managed cloud. - **Compliance Exports**: One-click exports formatted for SOC 2, ISO 27001, HIPAA, and GDPR audits. - **GraphQL API**: Flexible querying with filtering, pagination, and real-time subscriptions. - **AI Anomaly Detection**: Detects unusual access patterns and flags suspicious activity. ## Pricing - **Starter**: $99/month — 50K events/mo, SOC 2 control catalog, 15 policy templates, evidence vault, readiness dashboard - **Pro**: $299/month — 500K events/mo, access reviews, vendor tracking, risk register, SIEM streaming, compliance exports - **Business**: $499/month — 2M events/mo, auditor portal, trust center, Merkle proofs, personnel tracker - **Supersize + Milkshake**: $999/month — 10M events/mo, SSO/SCIM, legal hold, 99.99% SLA, unlimited everything ## Competitive Advantages - Only open-source audit logging platform with both hash chaining AND Merkle tree proofs - 5-minute setup vs 2-4 weeks for custom solutions - AGPLv3 with commercial license option for enterprise - Self-hostable with zero vendor lock-in ## Tech Stack - API: Hono on Fly.io - Dashboard: Next.js 15 on Fly.io - Database: PostgreSQL with Drizzle ORM - SDKs: TypeScript, Python, Go, Java - Monorepo: pnpm workspaces + Turborepo ## SOC 2 Audit Prep - SOC 2 Overview: https://auditkit.dev/soc-2 - AuditKit vs Vanta: https://auditkit.dev/compare/vanta - AuditKit vs Drata: https://auditkit.dev/compare/drata - AuditKit vs Spreadsheets: https://auditkit.dev/compare/spreadsheets - AuditKit vs WorkOS: https://auditkit.dev/compare/workos - AuditKit vs Pangea: https://auditkit.dev/compare/pangea - AuditKit vs Retraced: https://auditkit.dev/compare/retraced ## Links - Homepage: https://auditkit.dev - Documentation: https://auditkit.dev/docs - GitHub: https://github.com/AuditKitDev/auditkit - Blog: https://auditkit.dev/blog ## Contact - Email: hello@auditkit.dev - GitHub Issues: https://github.com/AuditKitDev/auditkit/issues