Reports Available to Clients
Activity logs accessible to the client's Super User; compliance documents provided on request
Activity Logs — Self-Service Access
User activity logs (including deletion events and other operational events) are available to the client's Super User directly in the platform's client panel and can be exported from there.
| Feature | Details |
|---|---|
| Access | The client's Super User, in their own client panel |
| Content | User activity: logins, deletions, downloads, other operational events |
| Retention | 3 months (Heroku Postgres) |
| Export | Download available directly from the panel |
Evidence for audit points related to user activity must be extracted by the client from their own tenant — SSM.ro does not provide these reports on the client's behalf.
Signing Audit Trail — AWS CloudWatch Logs
All electronic signing events are automatically logged in AWS CloudWatch Logs:
| Feature | Details |
|---|---|
| Retention | 5 years |
| Integrity | Append-only, encrypted at rest, IAM-restricted |
| Content | Each signing operation with signer identity, timestamp, and document hash |
This trail is tamper-evident and independent of the application.
Download Logging (On Request)
Logging of report downloads can be added as a new feature alongside the existing operational logs, at the client's request.
Advanced Audit Logging — Enterprise Package
More advanced and granular audit logging can be implemented as part of the Enterprise package. Contact the SSM.ro team for details.
Compliance Documents Provided on Request
The following compliance documents are available to clients as part of external audit or security review processes:
| Document | Description | Current Version |
|---|---|---|
| ISO/IEC 27001 Certificate | The current certificate, its scope, and the Statement of Applicability (SoA) | On request |
| Data Flow Diagram (DFD) | Level-1 DFD — data sources, processing, storage, external destinations | v1.0 (2026-04-29) |
| Architecture Diagram | Technical components, network flows, build & release pipeline | v1.0 (2026-04-29) |
| Risk Register | 12 identified risks with likelihood, impact, controls, and residual risk | v1.0 (2026-04-29) |
| User Roles Catalog | Platform roles, their scope, and authorized operations | v1.0 (2026-04-29) |
| WAF Compensating Controls Memo | Layered controls in place of a WAF; formally approved | v1.0 (2026-04-29) |
| Operational SOP | Backup, DR, and patching procedures | v1.0 (2026-04-29) |
These documents are classified Confidential and are provided for external audit use, under NDA where applicable.