Security and privacy decision

Recalled

A single competent developer can build a useful self-hosted minimal audit log (ingest, signed chain, search, embeddable UI) in about a week; vendor advantages are hosting, SLA, polished UI and managed compliance features.

Visit website

Built by Benjamin | Product Builder, who ships 4 products in this index

You pay

$9/mo

$108/yr

Read off the official pricing page.

You’d pay instead

$100one-off31 h to build

$60/mo6 h/mo upkeep

On cash alone, building overtakes the subscription at 8 seats.

Open-source builds that already do this

Every project below is open source and already does this job today. Fork one, self-host it, or take the parts you need - the build prompt further down assumes an empty file, and this is the shortcut past that. Licences differ; check the one on each card before you ship. All Recalled alternatives, with the arithmetic →

What a replacement has to do

  • Receive events via a REST endpoint/SDK, persist them off the primary DB, append an HMAC-signed chained receipt, provide search/filter APIs and an embeddable React admin widget plus CSV/JSON export.

What it still won’t have

  • 99.9% uptime SLA and priority support
  • EU-hosting guarantee and vendor-hosted DPA workflow
  • Polished, production embeddable UI with included webhooks and MCP server integrations
  • Tamper-evidence public verification URL and managed cryptographic key handling (operationally simpler in vendor)

What remains hard

  • Product polish and ongoing maintenance
Read the build prompt

First-year cost

Keep paying

Paying is—cheaper in year one.

On cash alone, building overtakes the subscription at 8 seats.

Paid seatsseats

Money you would actually spend

Keep paying
—

Subscription price × seats × 12

Build it
—

AI build —APIs + hosting —

Time you would spend

—

—

What you would spend

What we assumed

The verdict above measures whether you could build it. This one is only about money.

Runnable build prompt

Not run yet
Build a minimal self-hosted audit-log service using Node.js (Express), Postgres, and React. Core features in scope: authenticated REST /events ingest endpoint compatible with simple npm SDK; Postgres event schema with HMAC-SHA256 signature and chained-hash field; GET /events with full-text search, filters (actor, action, resource, date range), cursor pagination; GET /events/verify to verify chain; embeddable React admin widget (list + search + CSV/JSON export); configurable retention job that deletes or anonymizes events by age; logging, error handling and tests (unit for signing/verify, integration for ingest+search). Out of scope: multi-tenant billing, SLA, SOC2 certification, managed webhooks, managed MCP server for agent providers. Provide Docker Compose setup, migration scripts, environment vars for HMAC key and DB URL, and automated tests.
How we checked4 sources · 2/3 runs agreed · evidence score 89

How the score was reached

  • Build verdict base78
  • An open-source build was found+5
  • 4 cited sources+3
  • Price verified on pricing page+3
  • Evidence score89

The base comes from the verdict. Everything under it is a check that either happened or did not, and each one is a fact frozen in this record rather than a judgement made at render time - so the same evidence always produces the same number.

How scoring works →

Cited sources · 4

Every page the run actually retrieved.

Integrity checks

What held up, and what did not.

✓ Price read off the page! 2 of 3 runs agreed; the verdict is the majority✓ Citations limited to fetched pages! 1 moat recorded