Audit Logging for Compliance
Using Cresora audit logs to meet PCI DSS and regulatory requirements.
Cresora maintains comprehensive audit logs to help you meet PCI DSS Requirement 10 and other regulatory audit trail requirements.
PCI DSS Requirement 10
PCI DSS Requirement 10 mandates audit trails for:
- All access to cardholder data
- All system administration actions
- All authentication attempts (successful and failed)
- Use of and changes to cryptographic keys
Cresora's audit logs cover your API activity and Partner Portal actions, providing evidence for these requirements.
Accessing audit logs
Partner Portal → Account → Audit Log
The audit log is a portal surface: it is read with a signed-in portal session and is
not callable with csk_ API keys. Filter by:
- Date range —
from/to, RFC 3339 instants forming a half-open range[from, to) - Actor class (
actor_type:partner_user,api_key,cresora) - Entity (
entity_type, e.g.Merchant;entity_id) trace_id— theerror_idfrom a failed response, which makes this the fastest way to find what a failed request actually did
Results are cursor-paginated. The trail is scoped to your own partner account server-side; there is no way to read another tenant's.
Log retention for compliance
The partner audit trail is not pruned — entries remain readable through the portal, with no published fixed horizon. The platform's internal HTTP request logs (CloudWatch) are separate and retained 90 days in production; they are not partner-visible and are not the audit trail.
If your compliance program requires a guaranteed retention window (e.g. PCI DSS Req 10.5: 12 months, last 3 immediately available), do not rely on an unpublished horizon — raise the requirement with your Cresora contact so the archival window is agreed rather than assumed.
Exporting audit logs
There is no export mechanism today — neither a key-authenticated API nor a portal download. The portal view, with its filters, is the access path for audits and evidence gathering; capture what an assessor needs from there. If your program requires scheduled bulk archival in your own immutable storage (AWS S3 with object lock, Azure Blob with an immutability policy, etc.), raise it with your Cresora contact — do not build a process that assumes an export exists.