We were 4 months into our SOC 2 audit when the auditor asked a question that stopped us cold: "How do you prove that your audit logs haven't been modified after the fact?"

We looked at each other. Our audit logs were in a PostgreSQL table. Anyone with database access could UPDATE or DELETE rows. We had no mechanism to detect if someone had...