I built a tool to prove my own evidence store wasn't altered.

Compliance evidence has a trust problem that nobody asks about until the wrong day. The question is simple: how do we know this audit log wasn't edited after the fact?

Opencomplai's evidence-vault service stores every piece of compliance evidence, scan results, eval reports, sign-offs, as content-addressed immutable artifacts. An entry's address is a hash of its content. Change the content later and you get a different address, not a changed record. Same idea Git uses for objects, applied to legal evidence instead of source code.

An immutable store is only as trustworthy as your ability to prove it is behaving like one. That's what tools/verify-ledger is for. A standalone verifier. It walks the evidence chain and confirms nothing was tampered with, and it doesn't depend on the service that wrote it.

You don't have to take my API's word for it. Run the verifier yourself against the raw ledger.

This matters because most "audit trail" features in GRC products are an admin-editable table with a timestamp column. I've been on the security side of enough incidents to know what a timestamp is worth when someone with database access wants to reclassify a system after the fact. Nothing. A content-addressed chain with an independent verifier is worth something.

If you're building anything where "prove this record hasn't been altered" is a real requirement, compliance or not, read how the chain and verifier are structured: github.com/Opencomplai/opencomplai, under services/evidence-vault and tools/verify-ledger.