Operational security events are recorded for forensics and governance.
Every new audit record is cryptographically sealed against the records that came before it, so any later edit, deletion, or reordering becomes detectable. The result is independently verifiable: a reviewer can confirm that a run of records is intact without having to take our word for it.
At extreme write volumes, the strict ordering of simultaneous records is not guaranteed. Where sequence itself has to survive a contested proceeding, pair the audit trail with serialized ingestion or an external immutable log.