The compliance evidence package
For subscriptions that include it, CNX assembles a daily compliance evidence package alongside the DNS service itself — a second, read-only git repository that CNX writes to and your team mirrors. It gives a regulated customer — a bank, for instance — independent, self-contained evidence of change control and key custody for their own audits.
Each day's package includes:
- Activity logs — every zone and DNSSEC-related event CNX's platform recorded for your zones during the day, sourced from CNX's central logging platform.
- HSM key attestation — a cryptographically signed proof that the private key behind your zone's KSK was held inside CNX's protected key-management system at report time.
- An RFC 3161 timestamp — issued by CNX's own Timestamp Authority over a manifest of that day's report files, so the retention copy your team mirrors can be shown not to have been altered after the fact.
See Reports repository format for the exact file layout and schema, and Verifying report integrity for how to check the attestation and timestamp yourself.
For subscriptions that need it, the same activity and DNSSEC events can also be streamed continuously to your own SIEM rather than delivered once a day — including direct support for IBM QRadar collectors. Contact CNX to arrange this integration.