Skip to main content

Tamper-Evident Audit Log for Jira

Every change to every Jira ticket — signed, timestamped, and hash-chained into a tamper-evident, independently verifiable audit log.

Install free on the Atlassian Marketplace →  ·  Read the documentation →


What you get

  • Cryptographically signed — every Jira event (issue created, transitioned, edited, commented, attached, linked, watched) is individually signed with ECDSA P-256, the NIST-standard curve used in TLS, SSH, and EU eIDAS qualified electronic signatures.
  • RFC 3161 timestamped — each entry receives a timestamp token from an independent Timestamp Authority, never from the Attestsys server clock.
  • Hash-chained — every entry contains the SHA-256 hash of the previous entry's signed payload. Modifying any past entry breaks the chain in a way that is mathematically detectable.
  • Offline-verifiable — every export bundle ships with a verify.html file that runs entirely in the browser, validating every signature and chain link without contacting Attestsys.

Why it matters

"We logged it" is not a useful answer when someone asks you to prove what happened. Most audit-log apps stop at displaying history — if the underlying data store is mutable, the log is only as trustworthy as the vendor that holds it.

Think of a flight recorder. Investigators trust a black box for one specific reason: it sits outside the operator's control — the airline can't edit it mid-flight. Ordinary application logs don't have that property: they're created and stored under the same administrative control as the systems being investigated. That's fine for diagnosing what happened; it hits a credibility ceiling the moment someone outside your trust boundary — a customer in a dispute, an auditor, a counterparty — asks "how do I know these weren't edited afterwards?"

The same failure shows up in security incidents: once a workspace or account is compromised, its own history can't vouch for itself — every investigator's first question is "which records could the attacker reach?" Attestsys keeps a signed, hash-chained record of every workflow change outside that blast radius, so "what was actually done" stays answerable even when the system itself is suspect.

Attestsys is the black-box recorder for your Jira workflow: every action is individually signed and hash-chained at the moment it happens, so that anyone — your team, your customer, an external auditor — can verify the record independently, without trusting Atlassian or Attestsys. The combination of per-entry signing, hash chaining, RFC 3161 timestamping, and portable offline verification is unusual on the Atlassian Marketplace.

Automation changes records too. Scripts, Jira automation rules, and AI agents now modify tickets alongside humans — and "personalized logins" stop being a complete answer the day an agent acts on someone's behalf. Attestsys signs every change with the acting identity captured at event time, human or not, so the question "who — or what — changed this?" has a verifiable answer.

Who it is for

RoleWhat you get
Security engineers & SREsAn unforgeable record of who changed what in Jira, and when — independently verifiable without trusting Atlassian or Attestsys
Engineering & DevOps leadsA signed change trail across tickets, linked to deploys and approvals — export a bundle and hand it to anyone who needs to review it
Ops and process ownersProof that your change-management process was followed — automatically, without manual evidence collection
Teams doing SOC 2 / ISO 27001 / internal auditsTamper-evident records that eliminate manual screenshot-and-paste audit prep

Try the verifier right now

Hit Verify the sample bundle to watch a real 12-entry signed chain verify in your browser — every signature, hash-chain link, and RFC 3161 timestamp — or drop your own export ZIP in. It runs entirely client-side and shows you exactly what an auditor sees.

Verifying your own export runs entirely in your browser and makes zero network requests. “Verify the sample” downloads our 12-entry demo bundle so you can watch every signature, chain link, and RFC 3161 timestamp check pass.

Evidence that collects itself

On paid editions, the evidence workflow runs without anyone touching it:

  • Scheduled exports — daily, weekly, or monthly signed bundles, generated automatically on your cadence.
  • Delivered to your cloud — connect Google Drive or OneDrive once, and every scheduled bundle lands in your folder. Share that folder with your auditor and it fills itself.
  • Continuous verification — the backend re-verifies your entire chain on a schedule, not just when someone clicks. If a deterministic integrity failure is ever detected, a Slack or Microsoft Teams tamper alert tells you immediately — which workspace, what failed, where to look.

Editions

Full cryptographic stack on every tier. ECDSA P-256 signing, hash chain, RFC 3161 timestamping, and the offline verify.html ship with the free tier — no weakened crypto, no hidden gates. Every event is timestamped instantly on every tier; paid tiers add longer retention, a daily EU-qualified anchor over your audit chain, and operational integrations on top of the same cryptographic foundation.

Free

Genuinely free. Full crypto. Forever.

Retention
30 days
Bundle exports
10 / month
Timestamping
Public RFC 3161 TSANon-qualified, clearly labelled
  • Hash-chain signing (ECDSA P-256)
  • RFC 3161 timestamping
  • Offline `verify.html` in every bundle
  • EU-hosted on certified German infrastructure

Standard

For teams that need a year of history.

Retention
1 year
Bundle exports
Unlimited
Timestamping
Public RFC 3161 + daily QTSP anchorEU-qualified daily checkpoint
  • Everything in Free
  • Continuous chain verification + Slack / Teams tamper alerts
  • Daily EU-qualified anchor over your audit chain
Recommended

Advanced

Compliance teams shipping evidence to auditors.

Retention
Unlimited
Bundle exports
Unlimited
Timestamping
Public RFC 3161 + daily QTSP anchorEU-qualified daily checkpoint
  • Everything in Standard
  • Scheduled exports delivered to Google Drive / OneDrive
  • GRC webhooks (Drata · Vanta)
  • Rovo Companion Agent

Enterprise

Custom contract, custom residency, named support.

Retention
Custom
Bundle exports
Unlimited
Timestamping
Per-event QTSP, selectableChoice of EU Trusted List QTSP
  • Everything in Advanced
  • Per-event qualified timestamping + jurisdiction choice
  • Custom Data Processing Agreement
  • Custom data-residency arrangements
  • Named-account support contact

Free, Standard, and Advanced are billed per-user through the Atlassian Marketplace at the rates published on the listing. Enterprise is a flat-fee contract with a signed Data Processing Agreement.

See the full pricing page for billing details.


Install free on the Atlassian Marketplace →

EU-hosted (Hetzner Cloud, Nuremberg) · GDPR-aligned · RFC 3161 timestamped