You can. You should understand exactly what it takes before you decide to, because most teams start down this road, get ninety percent of the way, and ship something that fails the one test it was built for.
Here is the road.
Signing proves two things: the record has not changed since it was signed, and it came from your key. It proves nothing about when it was signed. You hold the key and you hold the clock. You can sign a fabricated record today and stamp it with last December's date, and the signature will verify perfectly. Against the party under review, signing moves nothing. The editor still controls the timeline.
Better. Now reordering and deletion are detectable within the chain. But you built the chain, you hold the chain, and nothing stops you from rebuilding it. Tonight, from scratch, with whatever history serves you, re-signing every link into a smooth continuous record. An append-only log you control is append-only until you decide otherwise. The tamper-evidence is real against outsiders and worthless against the operator, who is the exact party a reviewer is questioning.
Now you are trusting a vendor's claim that they made it immutable. That is genuinely better, because the vendor has less stake in your dispute than you do. But the auditor's question does not disappear, it just changes target. Can the vendor alter it? Can you and the vendor together? Can an administrator with root override the retention policy? The answers, respectively, are yes, yes, and usually yes. Vendor immutability is a policy, enforced by the vendor, revocable by the vendor. It is stronger testimony. It is not evidence, because evidence cannot rest on any party's continued good behavior.
Every one of the steps above fails the same way: the record is anchored to something a party to the dispute controls. That is the whole flaw, and there is only one fix. The record's existence has to be fixed in time by a system that no party to the dispute can reach. This is the entire function of a notary, a public ledger, a trusted timestamp authority. They do not store your record. They witness that it existed, at a time, in a place you cannot alter after the fact.
The moment you require that property, you have three honest options.
You can build tamper-evident logs in a week. Tamper-proof against yourself is a different thing, and it requires a clock you do not own. You can build that clock. What you cannot do is convince a regulator, a court, or an adversary's expert with a record you had the power to rewrite — and until you have solved anchoring, key custody, long-horizon recovery, and independent verification, an in-house build gives you exactly that record and no other.
That hard ninety percent is the part we have already built, operated, and proven in public. Not the signing, which is easy. The recovery seven years later. The destruction with a certificate at the end of the retention window. The verification by a hostile third party who has no account and no reason to trust us.
See a live record verify against a public ledger, in your own browser, right now.
Verify a record →