Skip to content

Compare

What you would use instead, and what it costs.

We are new, and the honest way to sell to somebody who has to keep evidence for seven years is to name the alternatives, publish the prices and let them check.

Side by side

Reldavi Audit.NET WorkOS Audit Logs BoxyHQ Retraced Roll your own
What it is Audit platform, hosted or self-hosted .NET library Hosted audit logs Open-source audit service A side table and a trigger
Automatic EF Core capture Yes Yes No No You write it
Masking before anything leaves your process Yes You implement it No No You implement it
Event store included Yes, columnar You choose and run one Yes Yes, on your cluster Your production database
Dashboard, diff viewer, timeline Yes No Yes Yes No
10 million events a month $199/mo Free, plus your infrastructure ≈$990/mo Free, plus your cluster Engineering time
Stream to a SIEM Included, any number No $125/mo per connection Yes You write it
Self-hosting One compose file N/A — it is a library No Kubernetes It is already yours
Data can stay in Türkiye Yes Your choice No Your choice Yes
Single sign-on OpenID Connect, included No Yes Yes You write it
Retention per resource type Yes No No No You write it
Plain-language search Compiled to a filter, never SQL No No No You write it
Search inside the change itself Values, transitions, thresholds No No No You write it
Embed in your own product Signed, scoped, included No No No You write it
EU AI Act Article 12 agent record Model, tool, authority, full prompt No No No You write it
Cryptographic tamper evidence Merkle root per day, chained No No No You write it
Alert on a saved search Any filter becomes a standing rule No No No You write it
Knows what each account normally does Per-actor baseline, first sightings No No No You write it
Ask for an alert in your own words Compiled once, confirmed, then no model No No No You write it
Proof that does not rest on trusting us Each seal timestamped by a public authority No No No You write it
Proof that nothing is missing Every batch is numbered and checked No No No You write it
Who read the audit log Recorded and shown to you No No No You write it
Limit an account to part of the trail By project, by resource type, on every route No No No You write it
Legal hold Freeze deletion for one matter No No No You write it
A room for your auditor Scoped link, revocable, proof included No No No You write it
Tells you when retention did not happen Both directions, with counts No No No You write it
KVKK destruction evidence Certificate per destruction No No No You write it
Answer a subject access request One field, in their language, in minutes No No No You write it
Works with no platform at all Yes, local file sink Yes No No It is already yours
Licence SDKs MIT, platform commercial MIT Commercial Open source

Competitor prices are the rates those vendors publish, read on 20 September 2026. They change. Check them yourself before you decide anything — we would.

Where we are actually different

Capture and evidence are one product

Audit.NET records the change and stops there; WorkOS stores the record but cannot see your DbContext. Everything between — the masking, the buffering, the retention, the export an auditor accepts — is the part teams spend a quarter building twice.

Masking happens on your side of the wire

A property marked [AuditMask] is projected inside your process, before the event reaches the buffer. The original is never queued, never transmitted and never stored. That is a sentence a security reviewer can verify, not a policy they have to trust.

The same product on our servers or yours

Not a cut-down community edition. One compose file brings up the whole stack, nothing calls home, and there is no licence check to fail at three in the morning.

Seven years for invoices, ninety days for sessions, one tenant

Retention is a contractual term and one contract usually contains several. Set it per resource type and the longer ones keep their partition while the shorter ones are removed on their own schedule. Everyone else makes you pick one number and either store sessions for seven years or delete invoices you were required to keep.

The monthly pack writes itself

A monthly obligation that depends on somebody remembering to press a button is one that fails in the month they are on holiday — and nobody notices until the audit that needed it. Turn it on and each month lands in a directory you control, a few days late on purpose so events that arrived slowly are in it.

The assistant cannot make anything up

Ask a question in your own words and a model chooses a filter — not a summary, not an answer, a filter. The platform runs it against the same tenant-scoped query builder the dashboard uses, and what you read is the events with their ids on them. The model never writes SQL, never picks a tenant, never sees a record and cannot write one. The weekly digest beside it is plain arithmetic over your own last four weeks, so it works with no key and no model at all. And the model can be one of yours: point it at anything speaking the OpenAI shape — including a model on your own network — so a company that may not send a sentence to a third party still gets the feature rather than a disabled checkbox.

Not everyone who needs the dashboard should see all of it

An account can be narrowed to particular projects or resource types, and what it may not read is absent everywhere: the log, the overview, the dropdowns, a pasted permalink, an export. This is usually the question that decides whether a company centralises its change history at all — at forty people, "everyone sees everything" means the support desk can read payroll, and keeping the history scattered starts to look like the safer choice. It is not, and this is why it does not have to be.

A retention policy is watched in both directions

Everybody deletes on schedule. Nobody tells you the schedule stopped, and nobody tells you that something else deleted records you were required to keep — which is the finding that ends an audit, and today it is the auditor who finds it. Reldavi compares what you declared against what your trail actually holds and reports the gap with a number on it.

The AI runs at design time, not at decision time

Ask for an alert in your own words and a model turns it into a filter, once. You read the filter and sign it off, and from then on the thing that fires is a filter — no model on the next batch, none in six months, none at three in the morning. That is why the alerts are defensible in a room with a regulator in it, and it is the opposite of what "AI-powered alerting" usually means.

The thirty-day letter writes itself

A subject access request under KVKK article 11 or GDPR article 15 is answered today by hand — several systems queried, spreadsheets exported and redacted, a letter written, days gone. You already hold every change touching that person, so this is a form with one field in it and what comes out is written for them: plain sentences in their language, the technical record beside each one, and a page explaining what the pack does not contain.

It knows what each account normally does

A SIEM does this for network traffic and nobody does it for application changes, because nobody else holds typed change history with an actor on every row. Each account is measured against its own past, so "svc-payroll has never touched payroll before" is a sentence the product can say — and it refuses to say "first time" until it has enough history to mean it.

You can search what changed, not just what was changed

Every audit product filters by which record, which person, which day. None of them can answer "a discount went above forty per cent" or "a status moved from approved back to draft", and those are the sentences an investigation actually starts with. Five operators over a named property, on either side of the change, in the same query as every other condition.

Your auditor gets a room, not an account

One link, bounded by a period, revocable in a click, with the seals verified on the same page as the records. The alternatives are a dashboard account you have to remember to remove, or spreadsheets that stop being verifiable the moment they leave the building. And because every visit is recorded, you can afterwards show your own board exactly what the auditor looked at.

Your customers can read their own trail

One package mints a signed token scoped to one record, and an iframe shows that customer their own history inside your product. No second dashboard, no accounts with us for your users, no per-seat charge — and the scope lives in the token, so it is a boundary rather than a promise.

Your SIEM connections are not a line item

Splunk, Sentinel, Elastic or a plain endpoint, as many as you like, on every paid plan. Charging a hundred and twenty-five dollars a month for a customer's own data to reach the customer's own tooling prices teams out of the integration that makes an audit trail useful, and the marginal cost of a second connection is an HTTP client.

An AI agent is recorded as what it is

Every other tool on this page records an agent as a user with an odd-looking name. An Reldavi event carries the model, its version, the tool call, whose authority it acted under and whether a person approved it — and the whole prompt and result, not four kilobytes of it. That is what EU AI Act Article 12 asks a high-risk system to keep, and it is sealed with the rest of the day, so an edited model name breaks the root.

The SDK is worth installing before you buy anything

One line points the capture layer at a directory instead of at us, and you get the masking, the buffering and the newline-delimited trail with no endpoint and no key. A capture layer that only works against a paid endpoint is not a competitor to a free library, it is an advertisement for one.

Priced against storage, not against your headcount

Every plan includes unlimited users. Charging your compliance officer to read a compliance tool would be absurd.

When you should not buy this

Three cases where something else is the better answer. We would rather say so here than in a refund email.

You only need history inside your own app

If nobody outside your team will ever read it, use Audit.NET and a table in your own database. It is free, it is mature, and it is genuinely good software.

You run Kubernetes and want to self-host for nothing

BoxyHQ Retraced is open source, has an embeddable viewer and costs nothing but the cluster you already operate. It has no .NET capture, which may not matter to you.

You already pay for WorkOS

If SSO and Directory Sync are already on their bill, their audit logs are one more toggle. Ours are cheaper per event; theirs are fewer vendors.

What is coming

None of this is available yet. It is here because you are about to trust a young product with your evidence, and you deserve to know what it is going to become before you do.

Next

  • SCIM provisioning Single sign-on works today through OpenID Connect, which Entra ID, Okta and Google Workspace all speak. Accounts still have to be created here first; automatic provisioning and deprovisioning is the next step.
  • SAML For the buyers whose security review names the protocol rather than the outcome. OpenID Connect covers every provider we have been asked about so far.

Not yet, and worth saying so

  • SOC 2 Type II We do not have one. The controls are built and documented, the audit period is not behind us, and pretending otherwise would be a strange way to sell an audit product.
  • A second region Data can stay in Türkiye or on your own servers today. A second hosted region is not open yet.

One at a time

The table above answers how five products differ. Nobody has that question — they have one name in mind, usually the thing they already use, and they want to know whether to move. Each of these says when not to.

  • Reldavi vs Audit.NET — Audit.NET is mature, MIT-licensed and does the hard part of capture well. If capture is the problem you have, stop reading and use it.
  • Reldavi vs WorkOS Audit Logs — The real difference is not features. It is that one of them has to be told what happened and the other one watches.
  • Reldavi vs building it yourself — The most common competitor, and the only one that is never evaluated honestly — because the first version takes an afternoon and the bill arrives years later.

Read the architecture before you believe any of this.

The schema, the SDK sources and the security model are open. If a claim here does not survive your review, tell us which one.