Product tour
One confirmation season, screen by screen.
Everything below is the real product — real screens, real button labels, in the order your team meets them. Four people touch a confirmation: your audit team, your client's CFO, the third-party responder, and the reviewing partner. This page follows the season through each of them.
Chapter 1 · your audit team
Your audit team's season
From client ledger to evidence pack without leaving the platform. Eleven steps, most of them minutes.
Step 1: Set up the client and the engagement
Create the audited entity under Clients — name, IČO, country — and invite the client's CFO as a signer from the same card: Add client, Invite signer (e.g. CFO) by email. Then create the engagement with New engagement: client × fiscal period, currency, materiality and performance materiality (Perf. mat.). PM is not decoration — it becomes the default sampling interval later. The dashboard's attention tiles ("extractions awaiting review", "open variances") track every engagement from day one.
Step 2: Import the client ledger — any Czech or English export
Upload CSV or XLSX straight from Pohoda, Money S3, Helios, or SAP-style exports. The two-step import previews the file, auto-suggests a column mapping from Czech and English headers, and handles "1 234,56", "(500)", and mixed encodings. Re-importing never destroys evidence: prior rows are superseded, not deleted, and the supersession is event-logged.
Import kinds: AR balances · AP balances · Bank balances · Open items · Subsequent receipts.
Step 3: Generate an ISA 530 sample the partner can defend
One click on Generate runs Monetary Unit Sampling over positive balances — systematic PPS with the interval defaulting to performance materiality, top stratum always selected — plus explainable risk rules: round amounts, duplicate counterparty-amount pairs, off-hours postings. Every selected item stores a plain-language reason for the working paper (e.g. "Systematic PPS hit at monetary unit N"), and the random seed is stored, so the exact sample is re-derivable at review. Curate items, then a partner approves — which locks the roster.
Step 4: Build the confirmation batch
Create a batch from the approved sample — one confirmation per included item, carrying the ledger balance — or add confirmations manually for bank, receivable, payable, or legal requests. Set the as-of date and an optional response deadline; each batch carries its own reminder policy and letter language (Czech or English).
Step 5: Assign responders from a verified directory
Every responder contact carries provenance (auditor-entered, client-provided, published channel, AI-suggested) and a verification tier: unverified → MX-checked (the email domain is confirmed to actually receive mail) → auditor-verified → network-verified. Dispatch is refused below auditor-verified unless you record an override reason — which lands on the audit trail. That is the ISA 505 / AS 2310 control, enforced in the data model, not in a policy PDF. A curated global directory of CZ/SK banks and institutions is shared with every firm; role addresses are curated centrally and each one requires a cited published source before it can be used. AI suggest can propose published channels, but suggestions are never used automatically — an auditor must verify first.
Step 6: Send the client authorization for signature
From the batch, Send for signature: the platform generates a bilingual information-release letter listing every counterparty, computes its SHA-256, and emails the client's signer a secure signing link — name, email, title, one click. What happens on their side is a ten-minute story of its own (see "Your client's ten minutes"). Until it's signed, the state machine will not let a single confirmation dispatch.
Step 7: Dispatch — verified, attributable, never undoable
Dispatch authorized confirmations emails each assigned responder a bilingual request letter with a QR code, the secure portal link, and a unique reply-to intake address — with the signed authorization attached. Contacts on paper-only workflows get a print-ready letter that still carries the QR, so even a posted letter can be answered digitally. The result reports exactly what was sent and what was skipped, and why.
Step 8: Track the season from the status funnel
Batch view shows response rate, overdue count, and median days outstanding over a color-coded 16-state funnel: the seven lifecycle phases above expand into 16 tracked states (awaiting authorization, dispatched, pending human review, variance pending, unresponsive, and more). Bounces surface automatically on the affected row. The reminder policy is yours per batch — polite on day 7, firmer on day 14, unresponsive at day 21 by default, editable or pausable — and responders who use their own portals or paper are never chased by automated email. Expanding any row shows its full dispatch and event history, and per-event email notification toggles keep you informed without spam.
Step 9: Review what the AI couldn't prove
Responses run through OCR, extraction constrained to a fixed set of fields, and a verbatim verifier: a number "found" must literally appear in the document text, and validators check currency, as-of date and line-item arithmetic. Only a full validator pass with an exact ledger match auto-accepts. Everything else lands here — source document beside the extracted-versus-ledger comparison — for Accept as extracted, Accept with corrections, or Reject. Each item is locked to one reviewer, so two reviewers can't double-process it. There is no synthetic confidence percentage anywhere.
Step 10: Reconcile, explain variances, close non-responders
Reconciliation is deterministic first — exact, within-tolerance, currency-mismatch — with semantic name matching (legal suffixes stripped, similarity scored) when the responder states a different name. For variances, the platform scans open items and subsequent receipts for classic in-transit and timing candidates and drafts an explanation the auditor must rewrite or confirm: the amber label reads AI draft — not audit evidence until you confirm or rewrite it. Non-responders flow to alternative procedures with auto-assembled subsequent-receipts evidence and a coverage percentage — and a conclusion the platform refuses to write for you.
Step 11: Working papers and the evidence pack
Per-confirmation working papers (PDF and XLSX) are regenerated live from the hash-chained event log on every fetch — a stale copy is never served. Batch lead schedules summarize per-books, confirmed, difference and status per row. Closing the engagement with Close & export evidence pack exports one ZIP: manifest, a fresh chain-verification verdict, signed authorizations and certificates, dispatch letters, response documents, and all working papers — designed to ISA 505 / AS 2310 documentation requirements.
Chapter 2 · your client’s CFO
Your client's ten minutes
The authorization is the legal hinge of the whole season. Confirmatica makes it a magic link, not a vendor envelope.
Step 1: The invitation
The CFO receives a unique signing link by email — no account, no download. The link is single-purpose, expires after 30 days, and is stored server-side only as a cryptographic digest, so a leaked copy of the database cannot be used to mint working links.
Step 2: Read the actual document
The consent letter renders inline as a PDF — every counterparty listed — in Czech and English, with its SHA-256 digest printed on the page. What you sign is exactly what the auditor sends, and both sides can prove it.
Step 3: Prove it's you
Send verification code emails a 6-digit code to the signer: possession proof, valid for ten minutes, capped at five attempts per code with hard issuance limits, and failed tries persisted so they cannot be reset by a rollback. Signer IP and user agent are captured at view and at signature. Every step — sent, viewed, code verified, signed — is appended to a database-append-only signature log and the firm's hash chain.
Step 4: Sign — or decline with a reason
Sign the authorization seals a certificate page (its own SHA-256 recorded) into the signed artifact and moves every awaiting confirmation to authorized; the audit team is notified. Decline to sign is first-class: it requires a reason, returns the batch to draft, and notifies the audit team — nothing proceeds on silence. The evidence model follows eIDAS advanced-electronic-signature characteristics — it is deliberately not a qualified signature, and there is no per-envelope vendor cost.
Step 5: Keep the certificate
Signers who take up the portal invitation see every authorization for the companies they sign for, with a downloadable signed certificate — theirs to file, not locked in the auditor's system.
Chapter 3 · the third-party responder
The responder's two minutes
Response rate is won by removing friction. A responder never creates an account, never installs anything, and never has to be told twice how to answer.
Step 1: One letter, three reply channels
The request letter arrives by email — or on paper — with a reference number, a QR code, a secure portal link, and a unique reply-to address. Answer through the portal (confirm, upload, or type a balance), reply to the email, or scan the paper letter's QR code; every channel ends in the same evidence store. Banks that run their own confirmation portals get a workflow type that respects their process and never chases them with automated reminders.
Step 2: The portal: confirm, upload, or type
Three tiles: Confirm as stated (one click, name recorded), Upload our statement (PDF, scans, images, text, CSV or Excel — everything a statement export actually is — capped at 25 MB with content-type verification so a fake PDF never enters evidence), or Type the balance with discrepancy notes. Czech and English, auto-detected, switchable.
Step 3: Or just reply to the email
Replying to the tokenized intake address routes the message — attachments and all — straight to the right confirmation. If there's no usable attachment, the email body itself becomes the evidence document. Mail that matches nothing is quarantined for the operator, never silently dropped.
Step 4: What their two minutes buys the audit
The moment a real response arrives through a contact, that contact upgrades to network-verified — the strongest provenance tier, earned rather than asserted. The portal footer says what's true: responses go directly to the auditor, with an immutable audit trail. If a responder stays silent, escalating reminders follow the batch policy with the original secure link still valid.
Chapter 4 · the reviewing partner
The reviewing partner
The platform is built around the approvals only a partner can give — and it makes each one inspectable years later.
Step 1: Approvals with teeth
Three things require the partner role and are refused otherwise. Approve (partner) locks the sample roster: items can no longer be included or excluded, and changing the selection means generating a new sample. Alternative procedures cannot be approved without a substantive auditor conclusion — the server-side error quotes ISA 505.12: the judgment cannot be automated. And sign-off is partner-role-gated, allowed only from verified, variance-explained, exception, or approved-alt-procedures states, recorded with user and timestamp on the chain, and cannot be undone.
Step 2: Overrides on the record
Dispatching to a contact below the auditor-verified tier requires a written override reason, written to the audit trail. Editing a verified contact's email resets it to unverified, so the ISA 505 control re-arms itself. Nothing in the directory is deleted: contacts and organizations retire and reactivate, with GDPR Art. 16 rectification logged to the event chain. The design rule everywhere: the machine may propose, verify and assemble — a person decides, and the decision is attributable, timestamped and hash-chained.
Step 3: An audit trail you can re-walk
Every mutation appends to a per-firm SHA-256 hash chain in the same transaction; UPDATE and DELETE are revoked at the database-role level on the event log. Chain heads anchor to write-once storage every 30 minutes, and verification is a button in the console — or a standalone read-only script any inspector can run. Every AI call sits in an append-only model-call log: model id, prompt and response digests, latency.
Step 4: Security your firm controls
TOTP two-factor with ten single-use backup codes (shown once, double-spend-proof), mandatable per role. Sessions carry an epoch: password change, reset, MFA change, role change, or disable revokes every outstanding session at once — not at cookie expiry. Login is rate-limited per IP and per email, with an account-level lockout a spoofed header cannot evade. Three staff roles — auditor, partner, firm admin — gate real actions server-side, and each member chooses which fieldwork events email them.
Under the platform
What holds it all up
Tenant isolation you can test
One schema, forced PostgreSQL row-level security on every firm-scoped table, a runtime role that cannot bypass it, tenant context bound to the session — never client-supplied. CI runs cross-tenant probe suites against real Postgres; a leak fails the build. Background workers run firm-scoped too, so RLS backstops even a forgotten filter.
EU-resident, no-train AI
Runs in Google Cloud europe-west3 (Frankfurt). Document AI and Vertex Gemini process documents in EU regions under Vertex AI enterprise privacy terms — no training on customer data. Every model call is logged append-only with model id, prompt and response digests, and latency.
GDPR in the data model
Directory contacts are rectified (Art. 16) or retired (Art. 17) — never silently deleted from history; the edit screens say so in-UI. The shared global directory accepts institutional role addresses only with a cited published source.
Approval-gated tenancy
There is no self-serve signup. A firm requests access; the platform owner approves and provisions the tenant; an admin invitation follows by email. Every firm on the platform exists because a person approved it.
Evidence-grade file handling
Response documents are stored under SHA-256-named keys with MIME allowlists and magic-byte sniffing; untrusted documents render only in sandboxed frames; CSV exports neutralize spreadsheet formula injection.
Working papers designed to the standards
Selection rationale per ISA 530, verification controls per ISA 505 / AS 2310, documentation regenerated from the event log — designed to those documentation requirements, and packaged for handover in one ZIP.
See it with your own engagements
Access is granted per firm after manual approval. Tell us your firm and your season's volume — the walkthrough happens on the real product.