What is Audit Logs?

An immutable record of who did what in the tool, such as settings changed, findings dismissed, gates bypassed.

Audit logs answer questions after the fact: who suppressed this vulnerability, who disabled that gate, who added an external user. For SOC 2 and ISO 27001 they are table stakes rather than a nice-to-have.

The security-relevant events here are the suppressions and bypasses. A dismissed critical finding with no attached record of who dismissed it and why is a genuine gap, not an administrative one.

Top 20 Audit Logs tools

Every tool in the directory documented as supporting Audit Logs, 17 fully, 3 partially, with what its own documentation says.

Support is not the same as parity, since some implementations are narrower in scope, gated to a higher plan tier, or maintained only for existing customers. The note under each tool is what its own documentation describes.

  1. 1
    CodacyQuality PlatformBusiness

    Org-wide event audit logs with CSV/JSON/API export and 90+ day retention; Business plan only.

  2. 2
    AikidoCode Security PlatformEnterprise

    Comprehensive audit trail of user actions; Advanced/Enterprise plan only

  3. 3
    ChatGPT / CodexAgent Coding ToolEnterprise

    ChatGPT Enterprise supports audit logging; Compliance API adds an append-only log stream for SIEM.

  4. 4
    Checkmarx OneCode Security Platform

    Audit Trail API/UI logs user management, SAST triage, and reporting events; 365-day default retention.

  5. 5
    Claude CodeAgent Coding Tool

    Audit logging listed among cloud/web session execution safeguards for Anthropic-managed VMs.

  6. 6
    CodeRabbitPR ReviewEnterprise

    Searchable admin change history plus REST API for SIEM export; Enterprise plan only

  7. 7
    CodeSceneQuality PlatformEnterprise

    Audit trail with full logging for compliance; audit and logging listed as a recent enterprise improvement

  8. 8
    CorgeaCode Security PlatformEnterprise

    Audit Logs is an Enterprise-only pricing inclusion

  9. 9
    Cursor (Bugbot)PR ReviewEnterprise

    Enterprise audit logs cover Bugbot installs, rules and settings; stream to SIEM, S3 or webhooks.

  10. 10
    DeepSourceQuality PlatformTeam

    Audit logs listed in the Team plan; Enterprise Control Panel adds audit logging for enterprise admins.

  11. 11
    GitHub Advanced SecurityCode Security PlatformEnterprise

    Organization/enterprise audit log plus GraphQL Audit Log API for compliance monitoring and IP protection

  12. 12
    GreptilePR ReviewEnterprise

    Audit logging referenced as an enterprise feature; no scope, retention or export detail

  13. 13
    QltyQuality PlatformEnterprise

    Audit logs listed as Enterprise-only on the pricing comparison table

  14. 14
    SemgrepCode Security Platform

    Timestamped audit logs exportable in JSON covering scans, findings, policy violations and remediation with user attribution.

  15. 15
    SnykCode Security Platform

    Audit logs exist as platform data and can be scoped to a hosting region.

  16. 16
    SonarQubeQuality Platform

    Organization activity, change history, and access/permission modification logs.

  17. 17
    VeracodeCode Security Platformadd-on

    User activity log and audit trails documented for enterprise governance

  18. 18
    CodeAnt AIPR ReviewPartial

    Audit trail for remediation tracking only; no administrative or access audit log documented

  19. 19
    Gemini Code AssistAgent Coding ToolPartialStandard

    Optional Cloud Logging bucket can store inputs and responses; no dedicated admin audit log documented.

  20. 20
    QodoPR ReviewPartial

    'Previous review results' keeps per-commit review history; no admin or access audit log documented

What to look for

  • Retention period, and whether it satisfies your compliance framework
  • Export to your SIEM, via API or streaming
  • Whether finding dismissals and gate bypasses are captured, not just logins
  • Whether logs are tamper-evident

Related terms

FAQ

What is Audit Logs?

An immutable record of who did what in the tool, such as settings changed, findings dismissed, gates bypassed.

How many tools support Audit Logs?

20 of the 20 tools tracked in this directory support Audit Logs, 17 fully and 3 partially, including Codacy, Aikido, ChatGPT / Codex, Checkmarx One, Claude Code. Support is not the same as parity, since some implementations are narrower in scope, gated to a higher plan tier, or maintained only for existing customers. The note under each tool is what its own documentation describes.

What should you look for in Audit Logs?

Retention period, and whether it satisfies your compliance framework. Export to your SIEM, via API or streaming. Whether finding dismissals and gate bypasses are captured, not just logins. Whether logs are tamper-evident.