Operational disclosure · updated 2026-07-18

Activity Recording & Audit Policy

Damlogics handles Critical Energy/Electric Infrastructure Information (CEII). To protect the integrity of that data — and to meet the compliance expectations that come with it — the platform keeps records of activity. This page describes exactly what is recorded. It exists so recording is disclosed, not discovered.

What is recorded

Changes to content. Every change to project data (creating, editing, or deleting projects, potential failure modes, risk assessments, reference data, documents, and settings) is recorded with who made the change, what was changed, and when.

Editing sessions. For rich-text content (descriptions, assessment sections, notes), we record one entry per editing session — who edited which document and when a session of edits occurred — not every keystroke, and not the text itself.

File access. Every time a file is viewed, downloaded, or deleted, we record who did it, when, and from which IP address and browser. This is a CEII/FERC compliance requirement: dam-safety files are sensitive, and access to them must be accountable.

Sign-in activity. Sign-ins, sign-outs, account creation, and failed sign-in attempts are recorded with IP address and browser. You can review your own recent sign-in activity on your profile page — if you see activity you don't recognize, change your password and contact your administrator.

What is not recorded

We do not record page views or reading activity (other than file access above), the content of your keystrokes, or anything from outside the platform. Failed sign-in records never include the password that was attempted.

How records are protected

Audit records are append-only at the database level — they can be added to, never edited or deleted, by the application. They are visible to no one through the platform except your own sign-in activity on your own profile page.