Audit events are hash-chained with Merkle seals. You can verify integrity. You cannot one-click export the ledger today.
Every change script, approval, and production read is attributed. The ledger is hash-chained and Merkle-sealed so tampering is detectable. MCP exposes VerifyAuditIntegrity.
What we do not have: a one-click export button in the UI. If your auditor needs a file, that is currently an operational conversation, not a screenshot of a download control. Say that in the questionnaire. Do not imply SOC 2 from the existence of a hash chain.