Security & compliance
What is Audit Logs?
An immutable record of who did what in the tool, such as settings changed, findings dismissed, gates bypassed.
Audit logs answer questions after the fact: who suppressed this vulnerability, who disabled that gate, who added an external user. For SOC 2 and ISO 27001 they are table stakes rather than a nice-to-have.
The security-relevant events here are the suppressions and bypasses. A dismissed critical finding with no attached record of who dismissed it and why is a genuine gap, not an administrative one.
Top 20 Audit Logs tools
Every tool in the directory documented as supporting Audit Logs, 17 fully, 3 partially, with what its own documentation says.
Support is not the same as parity, since some implementations are narrower in scope, gated to a higher plan tier, or maintained only for existing customers. The note under each tool is what its own documentation describes.
- 1
Org-wide event audit logs with CSV/JSON/API export and 90+ day retention; Business plan only.
- 2
Comprehensive audit trail of user actions; Advanced/Enterprise plan only
- 3
ChatGPT Enterprise supports audit logging; Compliance API adds an append-only log stream for SIEM.
- 4Checkmarx OneCode Security Platform
Audit Trail API/UI logs user management, SAST triage, and reporting events; 365-day default retention.
- 5Claude CodeAgent Coding Tool
Audit logging listed among cloud/web session execution safeguards for Anthropic-managed VMs.
- 6
Searchable admin change history plus REST API for SIEM export; Enterprise plan only
- 7
Audit trail with full logging for compliance; audit and logging listed as a recent enterprise improvement
- 8
Audit Logs is an Enterprise-only pricing inclusion
- 9
Enterprise audit logs cover Bugbot installs, rules and settings; stream to SIEM, S3 or webhooks.
- 10
Audit logs listed in the Team plan; Enterprise Control Panel adds audit logging for enterprise admins.
- 11
Organization/enterprise audit log plus GraphQL Audit Log API for compliance monitoring and IP protection
- 12
Audit logging referenced as an enterprise feature; no scope, retention or export detail
- 13
Audit logs listed as Enterprise-only on the pricing comparison table
- 14SemgrepCode Security Platform
Timestamped audit logs exportable in JSON covering scans, findings, policy violations and remediation with user attribution.
- 15SnykCode Security Platform
Audit logs exist as platform data and can be scoped to a hosting region.
- 16SonarQubeQuality Platform
Organization activity, change history, and access/permission modification logs.
- 17
User activity log and audit trails documented for enterprise governance
- 18
Audit trail for remediation tracking only; no administrative or access audit log documented
- 19
Optional Cloud Logging bucket can store inputs and responses; no dedicated admin audit log documented.
- 20
'Previous review results' keeps per-commit review history; no admin or access audit log documented
What to look for
- Retention period, and whether it satisfies your compliance framework
- Export to your SIEM, via API or streaming
- Whether finding dismissals and gate bypasses are captured, not just logins
- Whether logs are tamper-evident
Related terms
FAQ
What is Audit Logs?
An immutable record of who did what in the tool, such as settings changed, findings dismissed, gates bypassed.
How many tools support Audit Logs?
20 of the 20 tools tracked in this directory support Audit Logs, 17 fully and 3 partially, including Codacy, Aikido, ChatGPT / Codex, Checkmarx One, Claude Code. Support is not the same as parity, since some implementations are narrower in scope, gated to a higher plan tier, or maintained only for existing customers. The note under each tool is what its own documentation describes.
What should you look for in Audit Logs?
Retention period, and whether it satisfies your compliance framework. Export to your SIEM, via API or streaming. Whether finding dismissals and gate bypasses are captured, not just logins. Whether logs are tamper-evident.