GUIDE · COMPARISON
Audit trail for USB transfers from instrument PCs: the options compared
A result file leaves a standalone instrument PC on a USB stick. Months later an assessor asks what left, what arrived, and how you know they are the same file. Five kinds of tool sit around that moment, and each answers a different question. This page says which.
Written by Taha Bayar, a biologist working on laboratory data handover. Statements about other products are taken from their public pages in October 2026 and may have changed; Kionel is our product, so read that row with that in mind.
The five options
| Option | The question it answers | What it leaves open |
|---|---|---|
| Logbook and SOP | Who says they moved which file, and when | Nothing checks that the file that arrived is the file that left; entries depend on people remembering |
| Device-control software for example Microsoft Defender device control, ManageEngine Device Control Plus | Which sticks and which users may copy at all; often a log of what was copied | Runs on managed, usually networked PCs; says nothing about arrival, and knows no work order or sample |
| Media kiosk for example OPSWAT MetaDefender Kiosk, Honeywell SMX | Is this stick clean before it goes into a protected system | Built for files going in and priced as infrastructure; not a record of a result leaving a laboratory |
| Compliance wrapper for instrument software for example TotalLab AuditSafe | Who did what inside the instrument's software: logins, audit trail, electronic signatures | Covers work on the PC; the handover to another system is outside it |
| Signed record and receipt Kionel | Exactly which file left, for which work order, and that exactly that file arrived, signed by both devices | Does not lock ports, scan content, or encrypt the stick; shows keys and declared operators, not identities |
They are not substitutes
A laboratory under GMP may reasonably run three of these at once: device control so that only approved sticks work, a wrapper so that the instrument software has an audit trail, and a record of each handover. The mistake is to expect one of them to answer another's question. Device control that logs "user copied result.csv" does not show that the LIMS received the same bytes. A signed receipt does not stop someone using an unapproved stick.
Choosing by the question you are asked
- "How do you stop unapproved media?" Device control, and physical port locks.
- "How do you keep malware out?" Scanning, a kiosk, or no media at all: a one-way cable or a screen and a camera.
- "Who changed this result on the instrument?" The instrument software's own audit trail, or a wrapper.
- "What left, what arrived, and are they the same?" A hash taken at the source, checked at the destination, and signed. That is the part Kionel does on a USB stick, and the same part it does by screen and camera.
What the rules ask for
EU GMP Annex 11 asks that systems exchanging data electronically include appropriate built-in checks for the correct and secure entry and processing of data. NIST SP 1334 asks for logs and for hash or checksum verification when files are transported on portable media; we go through it control by control. Neither names a product, and no product makes a laboratory compliant by being installed.