Skip to main content
Cresora Commerce
Compliance

Audit Logging for Compliance

Using Cresora audit logs to meet PCI DSS and regulatory requirements.

Cresora maintains comprehensive audit logs to help you meet PCI DSS Requirement 10 and other regulatory audit trail requirements.

PCI DSS Requirement 10

PCI DSS Requirement 10 mandates audit trails for:

  • All access to cardholder data
  • All system administration actions
  • All authentication attempts (successful and failed)
  • Use of and changes to cryptographic keys

Cresora's audit logs cover your API activity and Partner Portal actions, providing evidence for these requirements.

Accessing audit logs

Partner Portal → Account → Audit Log

The audit log is a portal surface: it is read with a signed-in portal session and is not callable with csk_ API keys. Filter by:

  • Date range — from / to, RFC 3339 instants forming a half-open range [from, to)
  • Actor class (actor_type: partner_user, api_key, cresora)
  • Entity (entity_type, e.g. Merchant; entity_id)
  • trace_id — the error_id from a failed response, which makes this the fastest way to find what a failed request actually did

Results are cursor-paginated. The trail is scoped to your own partner account server-side; there is no way to read another tenant's.

Log retention for compliance

The partner audit trail is not pruned — entries remain readable through the portal, with no published fixed horizon. The platform's internal HTTP request logs (CloudWatch) are separate and retained 90 days in production; they are not partner-visible and are not the audit trail.

ℹNote

If your compliance program requires a guaranteed retention window (e.g. PCI DSS Req 10.5: 12 months, last 3 immediately available), do not rely on an unpublished horizon — raise the requirement with your Cresora contact so the archival window is agreed rather than assumed.

Exporting audit logs

There is no export mechanism today — neither a key-authenticated API nor a portal download. The portal view, with its filters, is the access path for audits and evidence gathering; capture what an assessor needs from there. If your program requires scheduled bulk archival in your own immutable storage (AWS S3 with object lock, Azure Blob with an immutability policy, etc.), raise it with your Cresora contact — do not build a process that assumes an export exists.