What makes an audit trail actually tamper-evident
Most ELNs will tell you they log every change. That's a different claim from tamper-evident, and the gap between them is exactly what an assessor is trained to probe.
Almost every electronic lab notebook on the market will tell you it keeps an audit trail. Say that back to an ISO/IEC 17025 assessor, though, and the next question is never “do you log changes.” It’s “prove I can trust the log.” Those are different claims, and the gap between them is worth understanding before you stake an accreditation on either one.
“Logged” is not “tamper-evident”
A changelog stored in an ordinary database table is only as trustworthy as whoever has write access to that table. In a self-hosted deployment, that might be the lab’s own IT administrator, a database contractor, or — worst case — an attacker who got in through something unrelated to the ELN entirely. Any of them can, in principle, edit or delete a row from an ordinary log table without leaving behind any record that the edit happened. The log’s account of its own history is not protected by anything.
That’s not a hypothetical an assessor invents to be difficult. It’s the actual question a nonconformity gets written against: not whether records exist, but whether their integrity can be demonstrated rather than asserted.
What a hash chain actually buys you
A hash chain answers that question by construction rather than by policy. Every create, update and delete appends a new entry to a per-organization chain, and each entry carries the cryptographic hash of the entry immediately before it. Change or delete anything in that history — even with direct database access, even years later — and the hash of that entry no longer matches what the following entry recorded as its predecessor. The chain breaks at a specific, locatable point, and that break is something anyone can check for themselves by recomputing the hashes, not something they have to take a vendor’s word for.
There’s a smaller, easy-to-miss failure mode this also has to close: two lab members editing records at nearly the same moment could otherwise race to append to the chain, producing two entries that both claim the same predecessor — a fork, which would make the chain ambiguous rather than broken. Serializing every append behind a single database lock per organization is what keeps the chain a straight line instead of a tree, and it’s the kind of detail that’s invisible until the day it isn’t.
This runs on every tier, including the free one, permanently — it isn’t a paid upgrade. What the paid tiers add is the machinery to verify and demonstrate the chain to an assessor on demand: one-click evidence packs and a chain-head export, rather than the protection itself. We don’t think a laboratory should get a weaker guarantee about its own data because it hasn’t bought a licence yet.
Tamper-evidence needs a partner: irreversible finalization
A perfectly tamper-evident trail attached to a record that’s still open for editing only answers half the question. The other half is: at what point does a record stop being a draft and become the thing you’d hand to an assessor? Archon draws that line explicitly — a notebook entry is a draft until someone deliberately finalizes it, which captures an electronic signature backed by password re-authentication and locks the content permanently. Not “permanently until an admin needs to fix a typo” — permanently. A correction after finalization has to be made as a new, separate, chained entry, so the record of what was originally signed off never quietly changes underneath anyone.
Why explain the mechanism instead of just claiming it
Any vendor can print “tamper-evident audit trail” on a feature list — it costs nothing to write. What separates the phrase from the property is whether a customer’s own compliance officer, or an external assessor, could in principle verify it independently rather than trust the sentence. That’s the bar worth holding whichever system you end up trusting your accreditation to, Archon or otherwise. See the lab workflow for how this fits into day-to-day use, or pricing for what each tier adds on top of the chain itself.