Overview & Methodology
Compliance evidence is typically reconstructed retrospectively from logs never designed to serve as evidence. We present an architecture in which attestable artefacts are emitted at the point of action and signed before aggregation, and evaluate storage, verification and retrieval cost against three regulatory regimes with differing retention and reporting-window requirements, including the six-hour CERT-In incident window.
A. Kumar, B. Pancholi, U. Banerjee. Evidence as operational exhaust: continuous compliance artefact generation in sovereign deployments. ACM Digital Threats: Research and Practice, 2026. doi:10.0000/uelement.2026.003
@article{kumar2026evidence,
title = {Evidence as operational exhaust: continuous compliance artefact generation in sovereign deployments},
author = {Kumar, A. and Banerjee, U. and Pancholi, B.},
journal= {ACM Digital Threats: Research and Practice},
year = {2026},
doi = {10.0000/uelement.2026.003}
}This theoretical finding runs in active enterprise production.
Discover how our engineering teams deployed these concepts under real-world operational constraints.
Publication Access
Science translated into battle-tested code.
- ◆2-hour architecture mapping workshop
- ◆Production-grade functional slice in 5 business days
- ◆100% client-owned source code & assets; zero vendor lock-in
- ◆Edge-native performance with zero proprietary runtime bloat
