Audit logs and compliance

preview

Attribution today, the durable audit trail rolling out for teams, and where our compliance program stands.

Security and compliance teams need to answer two questions: who did what, and can you prove it. This page covers what MobSession records today, the durable audit log we are rolling out, and an honest status of our compliance program.

Preview. Exportable audit logs and the compliance program described below are in early access or in progress. We will not claim a certification we do not hold.

What is recorded today

During a session, every prompt and every reaction is attributed to the person who sent it, and the full transcript is captured as the session runs. That gives you a real-time record of who steered the agent and what they asked for. Today that record lives with the session on the managed backbone and is visible to participants.

The audit log, in early access

We are rolling out a durable, exportable audit log built for review and retention, separate from the live transcript:

  • Membership and access events: who joined a session, when, and from where.
  • Steering events: who submitted each prompt, and which prompts ran.
  • Lifecycle events: session start and end, and orchestrator approvals once the approval gate is enabled.
  • Export: download the log, or stream it to your SIEM.

This pairs with SSO and access control, so audit entries reference verified identities rather than self-entered names.

Compliance program status

We want to be straight about this rather than imply more than is true:

  • We are building MobSession toward SOC 2, and a formal program is in progress.
  • We do not yet hold a SOC 2 report, and this page will state the date and scope when we do.
  • We do not sell session data, and we do not use session contents to train models.

If your procurement process needs documentation, contact us. We will share where things stand, our roadmap, and what we can commit to in writing.

Related