ANA Cohort · Trust

Logs and audits sanitization

ANA Cohort is designed to make operational review possible without exposing more sensitive data than necessary.

Microservice observability

Enough context to investigate, not enough to overexpose

ANA Cohort structures logs, traces, and audit records so authorized teams can investigate system activity without turning observability data into a secondary clinical data store. The goal is to preserve operational context for support, security review, forensic investigation, and compliance oversight while minimizing unnecessary exposure of sensitive data.

On-premise operational and audit views retain the information authorized teams need to investigate system activity. When observability events are forwarded outside the deployment, payloads are sanitized, bounded, and controlled through deployment-level and tenant-level settings.

When enabled, optional forwarding can send sanitized observability events to ANA's EU-based operations monitoring environment, to a customer-managed syslog destination, or to both.

Core principles

How we think about sanitized records

01

Structured before output

Operational events are handled as structured records, allowing service, tenant, request, and trace context to be retained while sensitive fields are minimized or redacted.

02

Bounded audit payloads

Audit payloads are sanitized before they are stored. Sensitive keys are dropped, known PHI patterns are redacted, and unusually large or deeply nested values are bounded.

03

Access leaves a trail

Viewing or exporting operational logs and audit records requires dedicated permissions, and those access events are themselves recorded for later review.

Reassurance for reviewers

Built for review without broad exposure

Our goal is to give users, IT administrators, and security reviewers confidence that system activity can be understood without turning observability data into a parallel repository for clinical information.

For healthcare operations

Support teams can investigate service health, workflow status, and failure context using controlled operational and audit information.

For IT and security reviewers

Audit records preserve accountable actions, timestamps, source services, correlation context, and tenant scope while reducing exposure of identifiers inside payload details.

For observability integrations

Sanitized observability events can be forwarded to ANA's EU-based operations monitoring environment, to a customer-controlled syslog destination, or to both.

Common questions

What information stays on-premise?

On-premise operational logs and audit views retain the context authorized customer teams need for troubleshooting, security review, forensic investigation, and compliance oversight.

What can be forwarded outside the deployment?

Customers can optionally enable forwarding of sanitized observability events outside the deployment. Forwarding can support ANA operations monitoring through EU-based certified service providers, customer-managed syslog collection for internal IT or security workflows, or both.

Are forwarded events raw log copies?

No. Forwarded observability events use sanitized, bounded payloads. They are designed to preserve useful operational signals while reducing exposure of sensitive identifiers and clinical details.

Is external forwarding required?

No. External observability forwarding is optional and configuration-gated. ANA Cohort can be operated with on-premise operational and audit views available to authorized teams.

Who can access logs and audit records?

Log and audit access requires explicit permissions. Viewing or exporting operational logs and audit records is itself recorded for later review.

Disclosure note

We intentionally avoid publishing low-level logging rules, schemas, redaction patterns, and internal forwarding controls in public materials. Those implementation details are handled through customer security review and contractual documentation where appropriate.

Logs and audits sanitization - ANA Cohort Documentation