Use Cases
Audit & Compliance
Compliance & Audit
The evidence your compliance team actually needs
Most GPU power changes leave traces in logs anyone with access can edit. When auditors or incident responders ask whether a power-cap change was applied as intended, that is hard to answer.
A Power Event Record gives them a tamper-evident, replayable answer: which GPU, when, the limit before, and the limit the GPU reported after. Records power-limit changes made by other tools, not just its own.
How the hash chain works
Each Power Event Record includes a SHA-256 hash computed over the entry and the previous entry's hash. Every record is signed with Ed25519. Auditors only need the public key. An edit to a stored record breaks the chain on recompute. Anyone with a copy can recompute the chain. Anchors go to a local write-once directory by default, and can be sent to off-site storage you control.
Power Event Record Chain · illustrative
// Entry N-1
{ seq: 14819, entry_hash: "2e57...419f" }
// Entry N (current)
{ seq: 14820,
action: "SET_POWER_LIMIT",
limit_before_w: 350,
readback_w: 300,
prev_hash: "2e57...419f",
signature: "ed25519:9c1e...07ab",
entry_hash: "f33c...8b02" }
// Chain valid — tamper-evident
If any entry is modified:
prev_hash in Entry N+1 no longer matches Entry N's recomputed hash → the chain breaks on recompute
What auditors can check
What auditors can check
What was asked for and what was applied
For each recorded change, the record holds the requested limit where known, the limit before, and the limit the GPU read back after.
How it shows
The read-back value comes from the GPU itself, so the record shows what the GPU reported, not just what was asked for. If a value can't be read, the record marks it missing.
Changes made outside your normal process
Records power-limit changes made by other tools, not just its own. A change made with a different tool shows up next to the rest.
How it shows
Each of those changes gets its own Power Event Record, in sequence with the others.
A timeline of what happened
Records are timestamped and in order, so incident responders can replay the sequence of power-cap changes around an event.
How it shows
The hash chain fixes the order. If a record can't be written, Spark-XC flags it.
Whether stored records were edited
Tamper-evident: edit a stored record and the chain no longer checks out when it's recomputed. Anyone with a copy can recompute it, before relying on any record.
How it shows
Every record is signed with Ed25519. Auditors only need the public key. Anyone with a copy can recompute the chain. Anchors go to a local write-once directory by default, and can be sent to off-site storage you control.
Frameworks
Where records can help with common frameworks
Spark-XC hasn't been audited against any of these. A record can supply evidence relevant to a control, nothing more.
SOC 2 Type II (AICPA 2017 TSC)
CC6.1 — Logical access controls over hardware. CC7.2 — System monitoring for anomalies. CC8.1 — Change management audit trail.
GPU readback · Changes by other tools · Hash chain
ISO/IEC 27001 Annex A
A.12.4 — Logging and monitoring. A.12.1 — Operational procedures and responsibilities. A.14.2 — Security in development and support processes.
Timestamps · Ed25519 signature · Hash chain
NIST SP 800-53 Rev. 5
AU-2 — Audit events. AU-10 — Non-repudiation. SI-7 — Information integrity. CM-3 — Configuration change control.
GPU readback · Ed25519 signature · Hash chain
What you can hand an auditor
What your team can share
The records themselves
Power Event Records live on your hardware, with the hash chain included. Your team decides who gets a copy.
Evidence chain
Power-limit changes
For each recorded change: the limit before, the requested limit where known, and the limit the GPU read back.
GPU readback
Changes by other tools
Records power-limit changes made by other tools, not just its own.
Out-of-band
Timelines
Records are timestamped and in order, so a sequence of changes can be replayed.
Timeline
Chain check
Recompute the chain over any run of records. A mismatch shows where it breaks.
Evidence chain
Metrics
Per-GPU power draw, temperature, applied power limit, control actions, and safety counters are exposed on a Prometheus /metrics endpoint, with a sample Grafana dashboard.
Prometheus
Audit teams
Records your auditors can recompute
Bring a power action and we'll show you its Power Event Record, and walk through how it lines up with your audit needs.