
faq-general
What do we hand an auditor or regulator?
General FAQ · Fleet and governance
You hand over an export of the relevant slice of the receipt trail, and the auditor verifies it themselves, offline, on their own machine. They need no access to your infrastructure and no trust in CueCrux's servers or UI; the signatures and hash chain carry the proof.
What the export establishes:
- Every action in scope: who (passport and tier), what (verb and hashes), when, under which grants.
- That the record is complete and unedited: any gap or alteration breaks the chain and the verifier reports it.
- That refusals happened as claimed: signed RefusalReceipts with reason codes prove policy operated, not just that nothing bad was logged.
Where erasure obligations have been exercised, the trail shows receipted scoped-forget operations, so "we deleted it" is itself provable. For the EU AI Act specifics, see the enterprise FAQ.