Solutions
Products
Resources
Company
Partners
Request a demo

Tamper-Proof Audit Trails: Enhanced Integrity Protection for Your Customers

The new international standard ISO/TS 24574 requires more companies in regulated industries to prove the immutability of their audit records. In response, DocuWare has introduced a feature for audit trail integrity protection. This enables your customers to confidently demonstrate that their document history is trustworthy and complete.

The new feature provides cryptographic security for all audit events. Any tampering—including altered entries, deleted records, or out-of-sequence insertions—is instantly detectable. The optional feature is already available on request and will be rolled out in upcoming releases for both DocuWare Cloud and locally installed systems.

How the new audit trails work

The integrity verification uses two established, complementary cryptographic methods:
 
Chaining of audit entries: Each new audit record is cryptographically linked to the previous one, like the links in a chain. If a record is changed, removed, or inserted, the chain "breaks" at that point and the change becomes visible—making the trail tamper-evident.
 
Anchoring: At regular intervals, the system creates secure "snapshots" of the chain, digitally signs them, and stores them in a separately protected location. These signed checkpoints prove that the audit trail existed in a specific, unchanged state at a specific time—and they cannot be falsified or backdated. In the cloud, this makes the trail even more resistant to tampering.

Easy handling

Your customers can check integrity at any time directly in the auditing interface (DocuWare Configuration > Audit reports). Next to each archive, a checkmark "Integrity verified” appears. With the "Verify integrity" button, a full audit can be performed and a report generated, either confirming the intactness of the audit trail or pinpointing where it was compromised. Both the complete history and selected time periods can be checked.

How your customers can activate protection

Integrity protection is an optional feature, not enabled by default, as it requires additional processing and infrastructure. Currently, customers—or you as the partner—can request activation for the relevant organization via DocuWare Support.

The rollout

Tamper-proof audit trails are available for DocuWare Cloud starting with version 7.15 (fall 2026).
 
Customers with an on-premises DocuWare system will receive the feature with DocuWare version 7.16, planned for spring 2027. The on-premises version reliably detects manipulations by ordinary users and provides full integrity verification. However, as is technically unavoidable in a self-hosted environment, protection is limited against a system administrator with full server access.
 
The DocuWare Cloud variant offers the strongest guarantees here, thanks to its isolated, externally secured infrastructure.

Background: New international standard

Since 2025, the technical specification ISO/TS 24574 includes requirements for "digital safes" in document management applications. Among other things, it demands tamper-proof audit trails and is increasingly used, especially by European companies. Currently, there is no internationally accredited certification for ISO/TS 24574:2025.
 
Tamper-proof audit trails are also a requirement of the French standard NF203. Whereas this feature was once optional, it has since become mandatory for certification. DocuWare was re-certified for NF203 in July 2026—a plus point for your customer conversations.

 

Tip: translate it

Maybe you’d rather read this article in your native tongue than in English? No problem! Your browser can handle the translation work. Learn how



Topics

Show all topics

Recent posts