Compliance logging for Windows

Compliance logging for Windows: the controls your auditors test, and the evidence to show them.

DPLens is a UK-built, self-hosted log collection and security data pipeline agent for Windows. It supports the logging, file integrity monitoring, data minimisation and delivery controls that PCI DSS, UK GDPR, DORA, NIS2, HIPAA, ISO/IEC 27001 and SOC 2 ask about. Meeting the requirement stays with you.

  • PCI DSS v4.0.1
  • UK GDPR
  • DORA
  • NIS2
  • HIPAA
  • ISO/IEC 27001:2022
  • SOC 2

In short

DPLens supports compliance logging on Windows for PCI DSS v4.0.1, UK GDPR, DORA, NIS2, HIPAA, ISO/IEC 27001 and SOC 2. It gives you the logging, change-detection, minimisation and delivery controls auditors test, and the evidence to show them. On each Windows host it collects event logs and files, scans for file changes every 15 minutes, hourly or daily, masks card numbers and personal data before anything leaves, delivers over TLS with a disk-backed cache, and keeps a tamper-evident audit trail of changes made to the agent itself. DPLens Manager, included in every subscription, configures and monitors the whole fleet centrally.

Not legal or audit advice.

These pages explain how DPLens features relate to published requirements. They are not legal advice and not an audit opinion. Your assessor, auditor, DPO or counsel decides whether your controls meet a requirement. DPLens Ltd holds no certification or attestation for these frameworks, and using DPLens does not confer one.

Last reviewed 1 October 2026 against DPLens 1.0 documentation.

Control mapping

How DPLens supports each framework

Each row names the requirement, what the agent does towards it, and the artefact you can put in front of an assessor. The framework pages go further, with a "what you do" column for every row.

Framework requirements, DPLens capabilities and the evidence they produce
FrameworkRequirementHow DPLens supports itEvidence it produces
PCI DSS v4.0.1 10.2–10.3: audit logs captured, protected and promptly backed up to a central log server Collects any Windows Event Log channel and log files, and delivers them off the host as they are collected. TLS with certificate validation on by default; mutual TLS where the receiver requires it. Disk-backed delivery with optional Splunk indexer acknowledgement. Nothing is dropped silently: every drop is counted. The agent's source and destination settings; per-destination delivery state and cache depth; losses by cause on the Overview page; fleet health in DPLens Manager
PCI DSS v4.0.1 11.5.2: change-detection mechanism that compares critical files at least once weekly and alerts on unauthorised change File integrity monitoring (FIM) of files, folders and wildcards, scanned every 15 minutes, hourly or daily. Changes are reported as events through your pipeline to your SIEM, where you alert on them. FIM change events in your SIEM; an audit-log entry for every re-baseline
PCI DSS v4.0.1 Requirement 3: PAN unreadable wherever it is stored, including logs Card-number masking applies before events reach the disk cache or the network: redact, keep the last few digits, or replace with a keyed hash. Masking rules in configuration; per-rule mask counts; audit-log entries for masking policy changes
UK GDPR Art. 5(1)(c) data minimisation; Art. 25 data protection by design and by default; Art. 32 security of processing Filters drop events you do not need, and masking redacts or pseudonymises email addresses, IP addresses, phone numbers, UK National Insurance numbers and patterns you define, on the host and before egress. No telemetry: event data is never sent to DPLens Ltd. Filter and mask rules in configuration; measured in/out counts per stage; audit log of masking policy changes
DORA ICT risk management, detection of anomalous activity, and ICT third-party risk (Regulation (EU) 2022/2554) Delivery to several destinations at once, ordered failover, per-destination disk cache, and offline operation with no vendor control plane. Output in open formats (syslog, NDJSON, OpenTelemetry's OTLP) keeps your exit options open. Delivery and failover states; signed releases with SHA-256 checksums and CycloneDX and SPDX SBOMs for your third-party assessment
NIS2 Art. 21 cybersecurity risk-management measures, including incident handling, business continuity and supply-chain security (Directive (EU) 2022/2555) Collection and reliable delivery of the Windows telemetry your detection depends on; FIM; tamper-evident record of agent changes; a published, verifiable software supply chain. Collection coverage and losses on the Overview page; the audit log; release signatures and SBOMs
HIPAA Security Rule 45 CFR §164.312(b) audit controls; §164.312(c)(1) integrity; §164.312(e)(1) transmission security Records and forwards Windows activity from systems that hold ePHI; masks identifiers before egress; TLS with certificate validation on by default to your SIEM. Event streams in your SIEM; TLS destination settings; mask counts and audit-log entries
ISO/IEC 27001:2022 and SOC 2 Annex A 8.15 Logging, 8.16 Monitoring activities, 8.11 Data masking, 8.32 Change management; SOC 2 CC7.1, CC7.2, CC8.1 Central configuration in DPLens Manager, with validated, all-or-nothing applies and rollback; a tamper-evident audit trail of who changed what; per-source health and coverage; FIM for configuration drift. The audit trail and its verification status; the agent configuration under your change control

Evidence

What you can show an auditor

Everything below comes from the agent or the release itself. None of it needs a vendor portal.

01

The agent's audit trail

A tamper-evident record of sign-ins and failures, configuration applies and rollbacks, password, certificate, licence and masking policy changes, file-integrity re-baselines and start-up checks. The console shows whether it verifies. Ship it to your SIEM so it outlives the machine.

02

The configuration

One configuration holds every source, stage and destination, managed centrally in DPLens Manager. Keep it under change control and you have a reviewable history of what is collected, what is filtered, what is masked and where it goes.

03

Counts, not estimates

Every drop, mask, aggregation and failover increments a counter shown on the Overview page and attributed to the rule that caused it. Collection coverage shows a channel that is empty or a path that matches nothing.

04

A verifiable release

Authenticode-signed releases with SHA-256 checksums and software bills of materials in CycloneDX and SPDX, for your supplier and software-supply-chain reviews.

FAQ

Questions compliance teams ask

Is DPLens PCI DSS, HIPAA or GDPR compliant?

Software is not compliant on its own; organisations are. DPLens provides capabilities that support specific controls and produces evidence for them. Your assessor or auditor judges whether your controls, of which DPLens may be one part, meet the requirement.

Does any log data leave our network?

Only to the destinations you configure. DPLens has no telemetry, no licensing service and no cloud control plane, and upgrades happen only when you roll them out. The one optional exception is the public-IP enrichment, which is off unless you add it and can point at an endpoint of your choosing.

How is the audit trail protected?

The audit trail is tamper-evident: any alteration or removal of a record shows up, and the console shows whether it verifies. Deliver it to your SIEM as it is written and the record outlives the machine.

Can we run DPLens in an air-gapped or regulated network?

Yes. The licence is verified offline, nothing needs internet access, and DPLens Manager is self-hosted and air-gap capable. See air-gapped log collection.

See it on your own logs

Try DPLens on one Windows server before you talk to anyone.

Book a demo, or request an evaluation licence and install it on a test host. The documentation covers everything from requirements to Group Policy rollout.