Skip to main content
Introducing packages.sweber.dev
All packages
BetaMIT + Pro

LogarithmA self-hosted audit log for SaaS apps: who changed what, and when. Field-level diffs in your own Postgres or SQLite, and a ready React view for your customers' admins.

pnpm add @sweberdev/logarithm @sweberdev/logarithm-react

Sooner or later a B2B customer asks who changed what in their account, and security questionnaires, ISO 27001 and SOC 2 audits ask the same. Logarithm records it with one call: actor, action, targets and a field-level diff computed from the state before and after. Passwords, tokens and card numbers are never stored, also inside nested objects.

Events live in your own database: Postgres 13+ (also Neon and Supabase) or SQLite (better-sqlite3, node:sqlite, Bun). Every event belongs to a tenant, and a scoped log cannot read other tenants. A Fetch API handler serves Next.js, Remix, Hono or Workers, and the React view shows your customers' admins an activity log with search, filters, day groups and diffs, in English and German. No external service, MIT-licensed.

Example

A short exampleCopy it into your project.

app/projects/actions.ts

import { createAuditLog } from "@sweberdev/logarithm"
import { postgresStore } from "@sweberdev/logarithm/postgres"

const audit = createAuditLog({ store: postgresStore({ client: pool }) })

await audit.with({ tenantId: org.id, actor: { id: user.id, name: user.name } }).record({
  action: "project.updated",
  targets: [{ type: "project", id: project.id, name: project.name }],
  before: project, // { plan: "free", smtpPassword: "…" }
  after: updated,  // diff: plan free → pro, smtpPassword [redacted]
})

Features

What you getFree under MIT, with Pro on top.

Free, MIT

  • Record events in one call: actor, action, targets and a field-level diff from before and after
  • Passwords, tokens, API keys and card numbers stored as [redacted], also in nested objects and metadata
  • Stores for Postgres 13+ (Neon, Supabase) and SQLite (better-sqlite3, node:sqlite, Bun), or your own
  • Multi-tenant by default: a scoped log cannot read other tenants
  • Filters by actor, action prefix, target, time and text, with keyset paging
  • Fetch API handler for Next.js, Remix, Hono and Workers, with your own access check
  • React activity view with search, filters, day groups and diffs, in English and German

Pro

  • Tamper evidence: an HMAC hash chain per tenant and a verifier that names changed, removed or reordered events
  • Retention periods per customer with archiving, GDPR and Swiss FADP erasure and access requests
  • Streamed CSV, NDJSON and JSON export for your customers
  • Forwarding to signed webhooks, Splunk and Datadog

Compare

Free and ProSide by side.

FeatureFreePro
Events, diffs and redactionIncludedIncluded
Postgres and SQLite storesIncludedIncluded
Tenant-scoped queries and API handlerIncludedIncluded
React activity viewIncludedIncluded
Tamper evidence (hash chain and verifier)Not includedIncluded
Retention with archivingDelete by dateIncluded
GDPR/FADP erasure and access requestsNot includedIncluded
CSV/NDJSON export and SIEM forwardingNot includedIncluded
LicenceMITPer person
SupportGitHub issuesAgency and Lifetime

Pro

Pro packagesAdd-ons on top of the core.

Live demo

Try the themes, browse the catalog and read a real scanner report. The demo also shows the GTM container check, the monitoring of many client sites and the catalog changes per project.

  • @weber-development/logarithm-integrity

    HMAC hash chain per tenant and a verifier that shows which event was changed, removed or reordered.

  • @weber-development/logarithm-retention

    Retention periods per customer with archiving, erasure with a stable pseudonym and access-request export.

  • @weber-development/logarithm-export

    Streamed CSV, NDJSON and JSON downloads, forwarding to signed webhooks, Splunk and Datadog.

Pricing

PricingPrices are in CHF.

Freelancer

For one developer.

CHF 290

per year

2 months free

  • 1 person
  • No support entitlement
Subscribe

Team

Recommended

For teams of up to ten named people, one price.

CHF 890

per year

2 months free

  • Up to 10 people
  • Support included
Subscribe

Lifetime

Pay once for up to ten people and keep updates and repository access.

CHF 2'990

one-time

  • Up to 10 people
  • Support included
Buy lifetime licence

11 people or more: get in touch

  • After cancelling, every version you already received keeps working. Only updates and repository access end.
  • No licence key, no phone-home. The packages never contact a server to check your licence.
  • The licence covers the people who build with Logarithm Pro. The users of your SaaS app need nothing.
  • Checkout, invoices and VAT are handled by Polar as merchant of record.
Read the licence terms

FAQ

QuestionsShort answers.

Why not a hosted audit log service?

Audit events contain personal data and say a lot about your customers. With Logarithm they stay in the database you already run and back up, and there is no per-event bill.

Which databases are supported?

Postgres 13 or newer, including Neon and Supabase, and SQLite 3.38 or newer via better-sqlite3, node:sqlite or Bun. Other databases work by implementing a small store interface.

Can a customer see another customer's events?

Not through Logarithm. The API handler takes the tenant from your access check, and a log scoped to a tenant adds it to every query.

Is the log tamper-proof?

The free version stores events like any other table; restrict the app's database role to INSERT and SELECT. Logarithm Pro adds a hash chain that makes later changes visible, even to someone with database access.

What about GDPR and the Swiss FADP?

Secrets are never stored and you control retention. Logarithm Pro handles erasure with a stable pseudonym and collects a person's events for access requests. This is not legal advice.

Can I use the open-source part on its own?

Yes. @sweberdev/logarithm and @sweberdev/logarithm-react are MIT-licensed and complete without Pro.

Articles

ArticlesGuides and release notes.