Keys and operations — Audit log

Where: Tools → Audit log.

The log is a short history stored in the vault: sign-in failures and other store events. It is not a Windows Event Log and not a SIEM export.

What you should see

  • Failed sign-in attempts (wrong username or password)
  • After you sign in correctly, the welcome bar also reports failures since the last good login
  • Other vault actions the build records (imports, backup, settings), if those lines appear in your version

An authorized user who mistyped the password can still see those failures after a good sign-in so they know someone tried the lock.

What you will not see

  • Key passphrases or vault passwords
  • Full decrypted message text
  • A guaranteed multi-year archive

If the log looks empty after two bad passwords, sign in with the correct account and open the log again; older bugs missed the write until that path was fixed.

How long it is kept

Entries live with the vault file. Treat the log as limited history on this PC, not a compliance archive. A vault backup includes whatever the log held at backup time. Moving the vault moves the log. Clearing or rotating is only what this build offers in that window (if there is no Clear button, the log just grows with the vault).

If it fails

  • No lines for failures — update to a build that writes FailLog into the vault on a bad attempt, then test two wrong passwords and one good one.
  • Wrong vault file — Settings → Key store path.

Next

Two passwords. Licensing does not use this log. Do not paste log screenshots that include user IDs you do not want in a ticket.