Skip to content
github-actions[bot] edited this page Sep 28, 2026 · 2 revisions

Navigation: Home > Pages

ThemisDB Audit Hub and Canonical Map

Author: ThemisDB Contributors Created: 2026-09-13 Last Updated: 2026-09-14 Status: active Repository Metadata: VERSION=2.4.0-alpha Canonical Rule: /audit/** is the audit source of truth; /docs/** is downstream publication/legacy mirror unless explicitly marked otherwise. Source-verified status: The production audit logger exists in source, but design-level Wave-C pass claims remain provisional until validated against the real production sink and persistence path.

Baseline rule (2026-09-07): Root audit documents without direct date reference in filename (AUDIT.md, README.md, WAVE_C_AUDIT_EVIDENCE.md) are synchronized to the latest consolidated baseline report and source-verified implementation status.


Scope Lock

  • Authoritative audit stack: audit/
  • Downstream docs mirror/publication: docs/
  • Historical/archive: audit/docs/audit-reports/v1.4.1/, audit/docs/audit-framework/evidence/v1.4.1/, audit/docs/ARCHIVED/
  • Non-canonical working evidence: ai_working/** (draft/evidence only; never release/security source of truth)

Current Audit Set (Authoritative)

Document Purpose
THEMISDB_AUDIT_MATURITY_SECURITY_MONETARY_REPORT_2026-08-31.md Consolidated source-verified audit, maturity, security, and monetary update
AUDIT.md Central security/compliance/release audit summary
MATURITY_REPORT_2026-08.md Monthly maturity and gate posture
IMPLEMENTATION_AUDIT_2026-09-14.md Current implementation sync report
IMPLEMENTATION_AUDIT_2026-09-13.md Prior implementation sync report
IMPLEMENTATION_AUDIT_2026-08-26.md Earlier implementation sync report
IMPLEMENTATION_AUDIT_2026-08-12.md Historical implementation sync report
IMPLEMENTATION_AUDIT_CORRECTED_2026-08-08.md Historical deep-dive delta report
IMPLEMENTATION_AUDIT_2026-08-08.md Historical raw delta report
IMPLEMENTATION_AUDIT_2026-08-07.md Historical base snapshot
BSI_C5_2026_THEMISDB_AUDIT.md BSI-C5-2026 delta audit and actions

Inventory Matrix (/audit ↔ /docs)

Topic Canonical (/audit) Downstream (/docs) Status
Root audit navigation ../AUDIT.md β†’ audit/AUDIT.md n/a βœ… synced
EU AI Act compliance set docs/compliance/EU_AI_ACT_*.md (inside audit/) ../docs/compliance/ currently does not mirror these files 🟑 divergence tracked
Audit framework runbook/templates docs/audit-framework/* (inside audit/) ../docs/audit-framework/* 🟑 mirrored with overlap; /audit authoritative
Legacy Audit topic docs docs/Audit/* (inside audit/) ../docs/Audit/* (inventory/gap-analysis docs) βœ… scope-separated (no same-file duplicates)
Versioned audit bundles docs/audit-reports/v1.4.1/* (inside audit/) ../docs/audit-reports/v1.4.1/* 🟑 historical mirror; archival-only framing required

Quick Navigation

Compliance & Governance (canonical in /audit)

  • docs/compliance/EU_AI_ACT_COMPLIANCE.md
  • docs/compliance/EU_AI_ACT_RISK_MAPPING.md
  • docs/compliance/EU_AI_ACT_EVIDENCE_BUNDLE.md
  • docs/audit-framework/AUDIT_GOVERNANCE_STRUCTURE.md
  • ../docs/de/compliance/compliance_full_checklist.md

Release & Security Evidence

  • THEMISDB_AUDIT_MATURITY_SECURITY_MONETARY_REPORT_2026-08-31.md
  • AUDIT.md
  • MATURITY_REPORT_2026-08.md
  • IMPLEMENTATION_AUDIT_2026-09-14.md
  • IMPLEMENTATION_AUDIT_2026-09-13.md
  • IMPLEMENTATION_AUDIT_2026-08-26.md
  • IMPLEMENTATION_AUDIT_CORRECTED_2026-08-08.md
  • ../docs/security/GA_SANITIZER_EVIDENCE_BUNDLE.md
  • ../security/pentest/GA_PENTEST_EVIDENCE_BUNDLE.md
  • ../docs/governance/GA_PROMOTION_SIGN_OFF.md

Historical / Archival Paths

  • docs/audit-reports/q2-2026-quality-wave-1/AUDIT.md
  • docs/audit-reports/v1.4.1/ (archival package)
  • docs/audit-framework/evidence/v1.4.1/ (archival evidence bundle)
  • docs/ARCHIVED/

Current Status Snapshot

  • The real production audit implementation is present in source: include/utils/audit_logger.h and src/utils/audit_logger.cpp.
  • The current source-backed status is: implemented and substantively present, but not fully end-to-end GA-/production-certified without a live run against the actual sink and persistence path.
  • The Wave-C proof file tests/audit/test_audit_wavec_integrity_export_focused.cpp is a mock-based design validation harness, not a direct proof of the real production backend.
  • For current implementation drift handling, use IMPLEMENTATION_AUDIT_2026-09-14.md first.
  • The dated marker artifacts MARKER_LOCATIONS_2026-08-31.md and MARKER_GAP_CLASSIFICATION_2026-08-31.md are historical snapshots; use IMPLEMENTATION_AUDIT_2026-09-14.md for the current stale-marker assessment and refreshed counts.

Source-Verified Reality Check (2026-09-07)

The audit implementation in source is real and present, but a number of high-level audit claims in /audit need careful interpretation:

  • include/utils/audit_logger.h and src/utils/audit_logger.cpp implement the production audit logger with hash chaining, queue-size guarding, log rotation, fsync support, PKI-signature metadata, encryption fallback, and SIEM forwarding.
  • tests/audit/test_audit_wavec_integrity_export_focused.cpp is a focused production-backed regression harness; it validates Wave-C audit behavior against the real themis::utils::AuditLogger persistence path rather than an in-memory mock logger.
  • Current source-backed state: the audit subsystem is implemented and operational at the core-logger layer, but the strongest Wave-C certification claims should be treated as design-level validation until an end-to-end run against the real production sink and storage path is executed.

Compliance Snapshot

Framework Status Primary Evidence
ISO 27001:2022 βœ… 95% ../docs/de/compliance/compliance_full_checklist.md
BSI C5 (2026 delta) 🟑 92% BSI_C5_2026_THEMISDB_AUDIT.md
GDPR / DSGVO βœ… 98% ../docs/de/compliance/compliance_dpia.md
EU AI Act 🟑 65% docs/compliance/EU_AI_ACT_COMPLIANCE.md
NIS2 βœ… 94% ../docs/de/compliance/compliance_bcp_drp.md
SOC 2 Type II βœ… 90% ../docs/de/compliance/compliance_full_checklist.md

Provenance

  • Root release-readiness status: ../ROADMAP.md
  • Root release trace: ../CHANGELOG.md
  • Final governance gate: ../docs/governance/GA_PROMOTION_SIGN_OFF.md
  • Module-level implementation truth: ../src/*/ROADMAP.md, ../src/*/AUDIT.md

ThemisDB 1.9.0-beta Β· Home Β· Module-Index Β· GitHub Β· Issues

ThemisDB Wiki

🏠 Overview

πŸ“š Compendium

πŸš€ Getting Started

πŸ“– Tutorials

πŸ“— User Guide

βš™οΈ Operations & Security

πŸ“Ÿ Ops Runbooks

πŸ—οΈ Architecture

πŸ“ ADRs

πŸ”§ Contributing

πŸ“‹ Governance

πŸ” Audit

🧩 Plugins

πŸ”Œ Adapters

πŸ’‘ Examples

πŸ“¦ Client SDKs

πŸŽ“ Training

πŸ› οΈ Tools

πŸ€– Developer LLM Wiki

Clone this wiki locally