Regulatory Compliance
GDPR, SOC 2, ISO 27001, and Cyber Essentials all require evidence of who accessed your network and when. Access logs are the foundation of that evidence trail.
Most VPNs give you connectivity. PrivyNet gives you connectivity with a complete, exportable record of every session. See exactly who connected, when, for how long, and from which node. Compliance evidence that's ready when you need it.
Connectivity without visibility is a compliance liability. Access logs are the documented proof that your network controls are operating and auditable.
GDPR, SOC 2, ISO 27001, and Cyber Essentials all require evidence of who accessed your network and when. Access logs are the foundation of that evidence trail.
When an incident occurs - a data leak, unauthorised access, or a policy violation - access logs let you reconstruct exactly what happened and when.
Proving to a regulator or insurer that you monitor network access requires more than intent. Exportable access logs are the documented proof that your controls are operating.
When a breach or suspicious activity is detected, time matters. Access logs let your team immediately identify affected sessions, scope the incident, and take action.
Every VPN session - from connection to disconnection - is recorded with the following fields, automatically, with no configuration required
The account identifier of the user who established the session
Precise timestamp of when the VPN connection was established
Precise timestamp of when the VPN connection was terminated
The static dedicated IP address assigned for that session
Total connected time for the session, to the nearest second
The VPN node used to service the session
Access logs cannot be edited or deleted by any user. All records are scoped exclusively to your tenant - there is no cross-tenant visibility.
Pull your access records into your existing compliance, SIEM, or reporting workflows without any manual transformation
Download your session log as a flat CSV file. Open directly in Excel or Google Sheets, import into your compliance tool, or feed into your reporting pipeline with no transformation required.
Export structured JSON for programmatic processing. Feed directly into your SIEM, log aggregator, or custom compliance tooling with full field fidelity and no parsing guesswork.
Both export formats are available directly from the PrivyNet dashboard. No API key required for manual exports - select your date range and download.
Access logs directly address the network access monitoring requirements across the most widely adopted compliance frameworks
| Framework | Requirement | PrivyNet Coverage |
|---|---|---|
| GDPR | Access records & accountability | Full session logs per user |
| SOC 2 | Logical access monitoring | Per-user session audit trail |
| ISO 27001 | Access control evidence | Exportable logs with timestamps |
| Cyber Essentials | Network access control | Full session visibility per node |
PrivyNet provides a Data Processing Agreement (DPA) as part of every subscription. Combined with your access logs, this gives you the documentation layer required by GDPR and ISO 27001 auditors.
Common questions about VPN access logs and compliance evidence
PrivyNet logs the user account, session start and end timestamps, the static dedicated IP address used, the total session duration, and the VPN node that serviced the connection.
No. Access logs are read-only. Only administrators can view logs and they cannot be modified or deleted by any user, including admins. This ensures the integrity of your audit trail.
Yes. Access logs are fully scoped to your tenant. There is no cross-tenant visibility - your logs contain only sessions from your organisation's users and VPN nodes.
Yes. Logs can be exported from the PrivyNet dashboard in CSV and JSON formats, giving you the flexibility to feed them into your own compliance tooling, SIEM, or reporting workflows.
Access logs are retained in the PrivyNet platform for your review at any time. Contact support for details on your retention policy and any extended retention options.
Yes. PrivyNet's per-user session logs provide the access records and accountability documentation required under GDPR's accountability and access control principles. We also provide a Data Processing Agreement (DPA) as part of your subscription.
Every session recorded. Every record exportable. Every log tamper-proof. PrivyNet gives your team the access trail your compliance frameworks require, without any extra configuration.