For audit firms · EU-native
The audit confirmation season, end-to-end on one platform.
Confirmatica runs the full cycle — ledger import, ISA 530 sampling, client e-sign, verified dispatch, zero-login responder intake, AI extraction with deterministic verification, reconciliation, and working papers. Verified AI does the work; your auditors and partners make every judgment.
Most confirmation platforms are built around delivery — the request gets there, but the last mile from response to reconciled, documented evidence stays manual. Confirmatica is built to own that last mile.
Access is granted per firm after manual approval — Confirmatica is sold directly, not self-serve.
One timeline, four seats at the table. Follow it screen by screen
Every step feeds the next inside a 16-state lifecycle enforced by a server-side state machine — a confirmation cannot be dispatched before the client has signed, and nothing reaches a working paper without either full automated verification or a recorded human decision.
Who touches it, and for how long
1. Your audit team's season
the whole fieldwork
Import the client ledger, generate a partner-approved ISA 530 sample, dispatch to verified contacts, and watch the status funnel move — without re-keying responses into spreadsheets.
Read the journey2. Your client's ten minutes
designed for ~10 minutes, once
The CFO signs the information-release authorization from a magic link — email code, SHA-256-sealed certificate, done. No account, no vendor envelope fees.
Read the journey3. The responder's two minutes
designed for ~2 minutes
Banks and counterparties confirm as stated, upload a statement as PDF, scan, Excel or CSV, type a balance, or simply reply to the email. Czech and English, no login, ever.
Read the journey4. The reviewing partner
minutes per decision
Sample approval, override visibility, human review of anything the machine couldn't verify verbatim, and a sign-off that lands on a tamper-evident chain.
Read the journeyVerifiable, not asserted
Proof you can check
180+
backend tests in CI
including cross-tenant isolation probes against real Postgres
16
states in the enforced confirmation lifecycle
invalid transitions are refused server-side
3
responder reply channels, zero logins
portal (confirm / upload / type a balance), email reply, paper with QR
100%
of AI calls logged, append-only
model id, prompt and response digests, latency
Human judgment, enforced
A result is auto-accepted only on an exact ledger match with every deterministic check passing — everything else goes to a human. No synthetic confidence percentages anywhere. How review works
Evidence you can re-verify
Every mutation lands on a per-firm SHA-256 hash chain, anchored to write-once storage, that an inspector can re-walk. How the chain is verified
Tenant isolation, proven in CI
Forced Postgres row-level security on every tenant table, probed for cross-tenant leaks on every build. Under the platform
Controls in the data model, not the manual
Dispatch to an unverified contact is refused unless a partner-visible override reason lands on the audit trail. The partner's controls
Where the AI stops
Extraction is verified verbatim: every number the model reads must literally appear in the source document, in some printable variant, or the extraction fails review.
AI-drafted variance explanations are labeled in the product itself: AI draft — not audit evidence until you confirm or rewrite it. Finalizing requires the auditor's own words. Alternative-procedure conclusions quote ISA 505.12 — the judgment cannot be automated.
Every model call — extraction, drafts, contact suggestions — is recorded in an append-only governance log with model id and prompt/response digests, under Vertex AI enterprise privacy terms (no training on customer data), in EU regions.
Request access for your firm
Every firm on the platform exists because it was approved by name. Tell us who you are and roughly how many confirmations you run per season — the invitation arrives by e-mail once approved.
Approval-gated by design. No self-serve signup, no trial tier.