ssm.ro Docs
Compliance & Data ProtectionCompliance & Audit

Reports Available to Clients

Activity logs accessible to the client's Super User; compliance documents provided on request

Activity Logs — Self-Service Access

User activity logs (including deletion events and other operational events) are available to the client's Super User directly in the platform's client panel and can be exported from there.

FeatureDetails
AccessThe client's Super User, in their own client panel
ContentUser activity: logins, deletions, downloads, other operational events
Retention3 months (Heroku Postgres)
ExportDownload available directly from the panel

Evidence for audit points related to user activity must be extracted by the client from their own tenant — SSM.ro does not provide these reports on the client's behalf.


Signing Audit Trail — AWS CloudWatch Logs

All electronic signing events are automatically logged in AWS CloudWatch Logs:

FeatureDetails
Retention5 years
IntegrityAppend-only, encrypted at rest, IAM-restricted
ContentEach signing operation with signer identity, timestamp, and document hash

This trail is tamper-evident and independent of the application.


Download Logging (On Request)

Logging of report downloads can be added as a new feature alongside the existing operational logs, at the client's request.


Advanced Audit Logging — Enterprise Package

More advanced and granular audit logging can be implemented as part of the Enterprise package. Contact the SSM.ro team for details.


Compliance Documents Provided on Request

The following compliance documents are available to clients as part of external audit or security review processes:

DocumentDescriptionCurrent Version
ISO/IEC 27001 CertificateThe current certificate, its scope, and the Statement of Applicability (SoA)On request
Data Flow Diagram (DFD)Level-1 DFD — data sources, processing, storage, external destinationsv1.0 (2026-04-29)
Architecture DiagramTechnical components, network flows, build & release pipelinev1.0 (2026-04-29)
Risk Register12 identified risks with likelihood, impact, controls, and residual riskv1.0 (2026-04-29)
User Roles CatalogPlatform roles, their scope, and authorized operationsv1.0 (2026-04-29)
WAF Compensating Controls MemoLayered controls in place of a WAF; formally approvedv1.0 (2026-04-29)
Operational SOPBackup, DR, and patching proceduresv1.0 (2026-04-29)

These documents are classified Confidential and are provided for external audit use, under NDA where applicable.