Skip to content

For audit firms · Czechia and the Netherlands

The external confirmation season, built end to end.

Confirmatica is a working platform that runs the audit confirmation season: ledger import, ISA 530 sampling, client e-sign authorization, verified dispatch, zero-login responder intake, AI-assisted extraction with deterministic verification, reconciliation, and working papers — one platform, one evidence trail.

Most confirmation tools stop at delivery: the request arrives, and the work from response back to reconciled, documented evidence stays manual. Confirmatica was built to own that last mile: the seven stations below are stations in one platform, not separate tools stitched together.

Five kinds of request — bank, receivables, payables, legal and general — in Czech, English and Dutch for everything a third party reads. Licensed to audit firms, deployed on the firm's own infrastructure, and supported and maintained by Bonfleur s.r.o.

Confirmatica is licensed software, deployed on the licensee's own infrastructure. The screens on this site come from a demonstration instance running synthetic data.

How it works

One season, seven stations

Every step feeds the next: a confirmation cannot be dispatched before the client has signed, and nothing reaches a working paper without either full automated verification or a recorded human decision.

A season on the platform runs like this. A ledger is imported. An ISA 530 sample is drawn and the partner approves it. The client's director e-signs the information-release authorization with a one-time code sent to their mailbox. Letters go out under the firm's own identity. Counterparties answer online, by replying to the e-mail with a document, or off-platform — in which case the firm files what it received with a statement of how it arrived, when, and who received it. A stated balance that agrees reconciles without a person; a difference or an exception waits for a named human. Silence is chased on a calendar and, only after the chase, certified as a non-response, with ISA 505 alternative procedures prepared for the auditor's own conclusion. The season closes into a lead schedule, a working paper per confirmation, and an evidence pack a regulator can read — materiality and the sampling basis stated in it.

Follow it screen by screen

Confirmatica dashboard titled “Dashboard — what needs your attention now”, with counters for exceptions awaiting resolution, open variances, extractions awaiting review, open engagements and the response rate across them, above an “Act on these first” worklist ranked by audit risk then size, and the top of the firm's engagements table.Confirmatica dashboard titled “Dashboard — what needs your attention now”, with counters for exceptions awaiting resolution, open variances, extractions awaiting review, open engagements and the response rate across them, above an “Act on these first” worklist ranked by audit risk then size, and the top of the firm's engagements table.
The audit team's home screen in the fictional demo tenant: extractions awaiting review, open variances and a worklist ranked by audit risk, counted across every engagement in the season.

What is confirmed

Five kinds of request, one platform

Bank

The balance held on an account at the as-of date, addressed to the bank's confirmation desk with the IBAN or account number printed so the account can be located without a phone call.

Receivables

The amount a customer owes the audited company at the as-of date, confirmed by the customer against its own books — the classic positive confirmation of a debtor balance.

Payables

The amount the audited company owes a supplier at the as-of date, confirmed by the supplier — the same letter with the direction of the balance reversed.

Legal

An ISA 501 inquiry to the company's lawyers: pending or threatened litigation, claims and assessments, unbilled fees, and anything else relevant to the audit. It is answered in writing, never as a balance — the platform prints no figure on a legal request and offers none to confirm.

General

Any other balance a file needs a third party to confirm — a loan, a deposit, an intercompany position — using the same letter, the same portal and the same evidence trail.

Every kind goes through the same season — the same sample, the same signed authorization, the same portals, the same review and the same working paper. What differs is what the letter asks and what the counterparty is offered to answer with.

Facts about the product

What is independently verifiable

16

states a confirmation moves through

one status per confirmation, from ledger import to a signed-off working paper

2

responder reply channels, zero logins

portal — reached by link or by scanning the paper letter's QR — and plain e-mail reply; both land in the same evidence store

3

languages a third party is served in

Czech, English and Dutch — the letters, the responder portal, and every e-mail that leaves the platform for a counterparty

ISA 505

the standard the workflow is built to

ISA 530 sampling in front of it, alternative procedures behind it for the counterparties who never answer

Human judgment, enforced

A result is auto-accepted only on an exact ledger match, with the responder's currency stated and no deterministic check failing, from a sender the request was actually addressed to — everything else goes to a human. No synthetic confidence percentages anywhere. How review works

Controls that cannot be skipped by accident

Dispatch to an unverified contact is refused unless a written override reason is recorded on the audit trail — and the dispatch dialog counts the rows it will skip, and says why, before anything is sent. The partner's controls

A file that shows its own history

Every action on a confirmation is attributable to a named person and the time it happened, and the file cannot be altered afterwards without it showing. The working paper prints that history beside the evidence it belongs to, for a reviewer years after the season closed. The audit trail

Run before it is released

The whole season on this site — from a ledger file to an evidence pack, with a third party answering — is run end to end on the real product before a release, in Czech, English and Dutch. Not a slide of it: the season itself. The season, screen by screen

Architecture and security documentation is available under NDA.

The boundary

Where the AI stops

The confirmed balance is verified verbatim: it must literally appear in the source document, in some printable variant, or the extraction fails review. Line items are checked by arithmetic — they must foot to that balance — alongside currency and the as-of date.

AI-drafted variance explanations are labeled in the product itself: AI draft — not audit evidence until you confirm or rewrite it. Finalizing requires the auditor's own words. Alternative-procedure conclusions quote ISA 505.12 — the judgment cannot be automated.

Licensed software, deployed on the licensee's own infrastructure

Confirmatica is licensed software. The showcase at this domain runs on synthetic demonstration data. A licensee deploys on their own infrastructure and is the operator and controller of their instance. Bonfleur s.r.o. provides the licence, customization and maintenance.

Nothing an audit firm holds in its own deployment reaches Bonfleur: the instance runs on the licensee's stack, under the licensee's control. There is no trial tier, no pricing page and no funnel behind this site — an enquiry reaches a person, and the demonstration runs on the synthetic tenant shown throughout these pages.

Everything a counterparty receives comes from the firm, not from a vendor: the letter and the e-mail carry the firm's registered name, seat and registration number — its register entry and audit licence too, where the firm has recorded them — and every letter encloses the information-release authorization the audited company's director signed — the document that lets a bank or a counterparty answer the auditor at all.

The Czech and Dutch realities are engineered in, not localized after: the platform reads real Czech and Dutch ledger exports, and everything a third party receives — the letters, the portals, the outbound e-mail — works in Czech, English and Dutch.

Contact us

How a firm gets it

From a demonstration to a supported deployment

  1. Step 1: A demonstration

    The season described on this site, run on a demonstration instance holding synthetic data. No firm's data is on it.

  2. Step 2: A licence

    A written licence agreement with Bonfleur s.r.o. The licence conversation covers the terms, source escrow, an inventory of every third-party component the software depends on, the deployment runbook and the maintenance agreement — under NDA, alongside the architecture and security documentation.

  3. Step 3: The customizations the firm wants

    Letter wording, the firm's own directory, the ledger formats its clients export, and the storage and e-mail providers of the firm's own stack — scoped and agreed with the firm before deployment, not guessed at in advance.

  4. Step 4: Deployment on the firm's own infrastructure

    The instance runs on the firm's own infrastructure, under the firm's control. The firm is the operator and controller of it; nothing it holds reaches Bonfleur.

  5. Step 5: Support and maintenance

    Bonfleur s.r.o. maintains and supports the deployed instance under the maintenance agreement — updates, fixes and the next season's changes reach the firm's own instance.

No step is self-serve and none is skipped: a person reads the enquiry, a person runs the demonstration, and the licence is a written agreement before anything is deployed.

How a firm comes to run Confirmatica

An enquiry names the firm and roughly how many confirmations its season carries, and a person reads every one. What follows is a demonstration on the synthetic tenant, then a licence, the customizations the firm wants, and deployment onto the firm's own infrastructure — supported and maintained by Bonfleur s.r.o. from then on.

Licensed software, deployed on the licensee's own stack. No trial tier, no self-serve signup.