The prevailing wage audit trail you can prove you didn't edit.
WorkTrac is workforce management software with a tamper-evident audit trail built into the data model. Clock-in punches and task completions (with on-site GPS) are cryptographically signed on the worker's device at the moment of capture and chained to the previous record, so any later edit, deletion, or backfill breaks the chain and is visible to anyone holding the org's published public key. On a Davis-Bacon, state prevailing-wage, or public-works job, that means a contractor can hand a DOL investigator a signed event log they can verify themselves, instead of a timesheet they have to take on trust. Signing runs on the crew's phones, Android and iOS, online or offline, and the verifier is open and public at worktrac.io/verify, so the records stay checkable without WorkTrac's cooperation. Signed coverage starts with clock-ins and completed work and is expanding across the rest of the field record. Included on the Enterprise tier.
How the audit trail actually works
The phrase "tamper-evident" is doing real work here. Most field service tools store records in a database that the vendor, and any admin with the right credentials, can quietly edit. A clock-in time or a GPS coordinate can be changed weeks later with no record of the change. That is the failure mode that loses contractors prevailing-wage audits and costs them dispute resolutions.
WorkTrac signs each captured event on the device using a key generated and held on that device, includes a reference to the previous event in the chain, and stores the signature alongside the record. The server validates each signature on ingest and flags any event that fails as quarantined, with the reason recorded, rather than silently dropping it. After the fact, anyone with the org's published public keys can replay the chain and detect a tampered record by the broken link, without access to the underlying database and without WorkTrac's cooperation.
The result is a record that is honest about its own integrity. A clean chain says "every signed event in this period is exactly what the device captured." A broken link says "something was changed, here is which record, here is when." That single property converts a contractor's evidence file from "your word" to "checkable."
What gets signed in the chain
Today the chain covers the two events that anchor a labor audit: clock-ins and completed work, each signed on the worker's device at the moment of capture. The server already accepts the rest of the field record as chain event types, and on-device signing for those is rolling out next.
The task, a device timestamp, a per-device sequence number, and the previous event's hash, signed on the device at capture.
The task, the on-site GPS when captured, the timestamp, and the signing user, signed on the device at capture.
Clock-outs, photo evidence, OSHA safety incidents, SOS alerts, and timesheet approvals. The server already validates these event types; on-device signing for them is in progress.
Where the audit trail pays off
Prevailing-wage and certified-payroll requests are the canonical use case. A DOL investigator asks for the on-site record on a Davis-Bacon project; the contractor produces the signed chain of clock-ins and completed work for the period; the investigator verifies it against the published key and confirms those records were not altered after capture. That moves the contractor from "take our word for it" to "here, check it yourself." Contractors who can only produce editable timesheets often struggle to defend accurate records, because editable records carry no proof they were not edited, because they cannot prove they did not change them.
Billing disputes resolve faster. A client says "your crew wasn't on-site Thursday." The contractor pulls the signed clock-in punches for Thursday, the client verifies them against the public key, and the dispute closes on checkable evidence rather than an email argument. As signing expands to photos and incident reports, the same applies to disputed work and safety records.
Work proof also neutralizes the small, frequent damage from quiet record-edits. An office admin shifting an inconvenient clock-in by ten minutes now leaves a trail: the edit requires a stated reason, is logged with the original value, the new value, who changed it, and when, the worker is notified, and the signed capture-time event stays in the chain to compare against. Edits inside an approved period are blocked until the period is reopened.
How verification actually works
An admin can export a signed event log for any worker and date range (a payroll period, a DOL request) as a JSON file that bundles every public key needed to verify it, including keys revoked after signing. An auditor or third party verifies it: parse the events in order, check each event's signature against the matching public key, and confirm every chain link matches. The verifier is open and runnable independently of WorkTrac. The fastest path is the public verifier at worktrac.io/verify, which checks an exported log entirely in your browser, with no login and nothing uploaded. The whole point of the design is that the records stay checkable even if the contractor loses access to WorkTrac.
Common questions, answered.
WorkTrac builds the audit trail into the data model as a tamper-evident chain. Clock-in punches and task completions (with on-site GPS) are cryptographically signed on the worker's device at the moment of capture and chained to the previous record. After-the-fact edits, deletions, or backfills break the chain and are visible to anyone holding the exported log, which carries the org's public keys, including a DOL investigator. A Davis-Bacon or state prevailing-wage request is answered with a verifiable signed event log instead of an unverifiable timesheet. Signed coverage starts with clock-ins and completed work and is expanding across the rest of the field record.
Also explore
Clock-in punches are signed at capture; the GPS reading sits on the punch record alongside the signed event.
Records captured in dead zones get the same signature as online events. The chain survives offline gaps.
OSHA incident reports join the work-proof chain as signing expands across the field record.
The same setup for route-based crews: ordered stops, proof at close-out, offline mobile.
See it on your crew, today.
Try the sandbox right now with demo data, no signup, no card. When you're ready, start a 30-day Enterprise trial with every feature included.