ENGINEERING · AUDIT CHAIN

An audit chain for the paranoid

Every auth event and admin action commits to a hash-chained, tamper-evident log — because trust should be verifiable, not requested.

2026-10-08 · SIDDANI BLOG

Most platforms keep logs. Logs can be edited. Siddani keeps a hash chain: every record commits to the previous record's hash, so any edit, deletion or reordering breaks the chain visibly. The console shows chain integrity as a first-class chip — intact or broken, computed live.

What goes in the chain

Registrations, OTP issues, sign-ins and failed sign-ins, password resets, every admin action (verify, suspend, role and plan changes, forced re-verification), exchange syncs and balance snapshots. The actor, the target, the IP, the user agent, the timestamp.

What that buys you

When an admin changes something on your account, that action is committed immutably. When your own account shows a sign-in you do not recognize, the security feed shows it with its outcome. Nobody — including the operator — can quietly revise history.

Erasure done properly

GDPR erasure removes your personal data without breaking the chain: audit records are kept anonymized, the chain keeps verifying. Sessions, keys, tickets and trading data die with the account.
Start free All posts

Trust should be verifiable, not requested. The chain chip in the admin console is live — verify any time.