Why Your VPN Needs an Access Trail

Connectivity without visibility is a compliance liability. Access logs are the documented proof that your network controls are operating and auditable.

Regulatory Compliance

GDPR, SOC 2, ISO 27001, and Cyber Essentials all require evidence of who accessed your network and when. Access logs are the foundation of that evidence trail.

HR and IT Investigations

When an incident occurs - a data leak, unauthorised access, or a policy violation - access logs let you reconstruct exactly what happened and when.

Due Diligence for Regulators

Proving to a regulator or insurer that you monitor network access requires more than intent. Exportable access logs are the documented proof that your controls are operating.

Incident Response

When a breach or suspicious activity is detected, time matters. Access logs let your team immediately identify affected sessions, scope the incident, and take action.

What PrivyNet Captures in Every Session

Every VPN session - from connection to disconnection - is recorded with the following fields, automatically, with no configuration required

User

The account identifier of the user who established the session

Session Start

Precise timestamp of when the VPN connection was established

Session End

Precise timestamp of when the VPN connection was terminated

IP Address

The static dedicated IP address assigned for that session

Duration

Total connected time for the session, to the nearest second

Node

The VPN node used to service the session

Read-only and tenant-scoped

Access logs cannot be edited or deleted by any user. All records are scoped exclusively to your tenant - there is no cross-tenant visibility.

Export Logs in Your Preferred Format

Pull your access records into your existing compliance, SIEM, or reporting workflows without any manual transformation

CSV Export

Download your session log as a flat CSV file. Open directly in Excel or Google Sheets, import into your compliance tool, or feed into your reporting pipeline with no transformation required.

  • Human-readable, spreadsheet-compatible
  • One row per session - all fields included
  • Ideal for compliance reports and HR investigations

JSON Export

Export structured JSON for programmatic processing. Feed directly into your SIEM, log aggregator, or custom compliance tooling with full field fidelity and no parsing guesswork.

  • Machine-readable, integration-ready
  • Full field structure with typed values
  • Ideal for SIEM ingestion and automated workflows

Both export formats are available directly from the PrivyNet dashboard. No API key required for manual exports - select your date range and download.

How PrivyNet Logs Support Compliance Frameworks

Access logs directly address the network access monitoring requirements across the most widely adopted compliance frameworks

FrameworkRequirementPrivyNet Coverage
GDPRAccess records & accountability
Full session logs per user
SOC 2Logical access monitoring
Per-user session audit trail
ISO 27001Access control evidence
Exportable logs with timestamps
Cyber EssentialsNetwork access control
Full session visibility per node

PrivyNet provides a Data Processing Agreement (DPA) as part of every subscription. Combined with your access logs, this gives you the documentation layer required by GDPR and ISO 27001 auditors.

Frequently Asked Questions

Common questions about VPN access logs and compliance evidence

What information does PrivyNet capture in each VPN session?

PrivyNet logs the user account, session start and end timestamps, the static dedicated IP address used, the total session duration, and the VPN node that serviced the connection.

Can users edit or delete their own access logs?

No. Access logs are read-only. Only administrators can view logs and they cannot be modified or deleted by any user, including admins. This ensures the integrity of your audit trail.

Are access logs scoped to my organisation only?

Yes. Access logs are fully scoped to your tenant. There is no cross-tenant visibility - your logs contain only sessions from your organisation's users and VPN nodes.

Can I export access logs for compliance reporting?

Yes. Logs can be exported from the PrivyNet dashboard in CSV and JSON formats, giving you the flexibility to feed them into your own compliance tooling, SIEM, or reporting workflows.

How long are access logs retained?

Access logs are retained in the PrivyNet platform for your review at any time. Contact support for details on your retention policy and any extended retention options.

Do PrivyNet access logs support GDPR compliance?

Yes. PrivyNet's per-user session logs provide the access records and accountability documentation required under GDPR's accountability and access control principles. We also provide a Data Processing Agreement (DPA) as part of your subscription.

Start Logging Every VPN Session Today

Every session recorded. Every record exportable. Every log tamper-proof. PrivyNet gives your team the access trail your compliance frameworks require, without any extra configuration.

Full session logs
CSV & JSON export
Compliance-ready