{"statement_id":"st_6069f4afeca35339d907","subject":{"kind":"product","slug":"vendr","name":"Vendr","url":"https://sourcetier.com/products/vendr"},"attribute":{"key":"audit_log","label":"Audit log","unit":null,"core":true},"scope":null,"region":null,"first_recorded_at":"2026-09-02T06:49:06.782Z","current":{"claim_id":"cfbf0946-c4ec-49ef-a513-f83ccd70a3d2","value":true,"unit":null,"verification_state":"verified","confidence_recorded":90,"observed_on":"2026-09-02","recorded_at":"2026-09-02T06:49:06.869Z","ended_at":null,"ended_by":null,"superseded_by_claim_id":null,"withdrawal_reason":null,"valid_from":null,"extraction":"muster:\\b(?:with|includes?|provides?|offers?|enable|and|,) (?:full |detailed |comprehensive |complete )?audit (?:logs?|logging|trails?)\\b","reader":"text pattern","parser_version":null,"method":null,"excerpt":"...cessible at https://aws.amazon.com/compliance/soc-faqs/ . Our premium add-ons support SSO and audit logging for compliance. We employ AWS CloudFront, AWS Web Application Firewall (WAF) and AWS Guar...","sources":[{"url":"https://www.vendr.com/legal/security","tier":1,"type":"security_documentation","retrieved_on":"2026-09-02","role":"evidence"},{"url":"https://www.vendr.com/legal/security","tier":1,"type":"security_documentation","retrieved_on":"2026-10-02","role":"evidence"}]},"version_count":2,"versions":[{"claim_id":"0cfcddac-40c1-4ee6-9bb1-78fe21fa37f8","value":null,"unit":null,"verification_state":"unknown","confidence_recorded":0,"observed_on":"2026-09-02","recorded_at":"2026-09-02T06:49:06.782Z","ended_at":"2026-09-02T06:49:06.869Z","ended_by":"superseded","superseded_by_claim_id":"cfbf0946-c4ec-49ef-a513-f83ccd70a3d2","withdrawal_reason":null,"valid_from":null,"extraction":null,"reader":null,"parser_version":null,"method":null,"excerpt":null,"sources":[{"url":"https://www.vendr.com/","tier":1,"type":"official_documentation","retrieved_on":"2026-09-02","role":"checked_without_finding"}]},{"claim_id":"cfbf0946-c4ec-49ef-a513-f83ccd70a3d2","value":true,"unit":null,"verification_state":"verified","confidence_recorded":90,"observed_on":"2026-09-02","recorded_at":"2026-09-02T06:49:06.869Z","ended_at":null,"ended_by":null,"superseded_by_claim_id":null,"withdrawal_reason":null,"valid_from":null,"extraction":"muster:\\b(?:with|includes?|provides?|offers?|enable|and|,) (?:full |detailed |comprehensive |complete )?audit (?:logs?|logging|trails?)\\b","reader":"text pattern","parser_version":null,"method":null,"excerpt":"...cessible at https://aws.amazon.com/compliance/soc-faqs/ . Our premium add-ons support SSO and audit logging for compliance. We employ AWS CloudFront, AWS Web Application Firewall (WAF) and AWS Guar...","sources":[{"url":"https://www.vendr.com/legal/security","tier":1,"type":"security_documentation","retrieved_on":"2026-09-02","role":"evidence"},{"url":"https://www.vendr.com/legal/security","tier":1,"type":"security_documentation","retrieved_on":"2026-10-02","role":"evidence"}]}],"changes":[{"id":"36080","type":"research_update","label":"Research update","material":false,"sentence":"Vendr: Audit log is now recorded as not measured.","noticed_at":"2026-09-02T06:49:06.782Z","subject":{"kind":"product","slug":"vendr","name":"Vendr"},"before":null,"after":{"value":null,"verification_state":"unknown","confidence":0},"claim_id":"0cfcddac-40c1-4ee6-9bb1-78fe21fa37f8","statement_id":"st_6069f4afeca35339d907","corrected":null},{"id":"36091","type":"documented","label":"First documented","material":true,"sentence":"Vendr: Audit log documented as yes (verified). A first finding of ours, not a change at the vendor.","noticed_at":"2026-09-02T06:49:06.869Z","subject":{"kind":"product","slug":"vendr","name":"Vendr"},"before":{"value":null,"verification_state":"unknown","confidence":0},"after":{"value":true,"verification_state":"verified","confidence":90},"claim_id":"cfbf0946-c4ec-49ef-a513-f83ccd70a3d2","statement_id":"st_6069f4afeca35339d907","corrected":null}],"page_url":"https://sourcetier.com/statements/st_6069f4afeca35339d907","contract":"A statement is the question a claim answers: one subject, one attribute, one scope and region. statement_id stays the same when a new value supersedes the old one, when we withdraw it and when two duplicate entities are merged (the old id then redirects). claim_id identifies one version. versions lists every version oldest first; ended_by is superseded, withdrawn or null for the current one. confidence_recorded is the confidence stored when that version was written, not a recomputation. unknown describes our research, never the product."}