Independently audited and certified
Our programs are audited on a recurring cycle by third parties, and the reports are available to customers and prospects under NDA.
Governance, by design
Agents that act on financial records need governance that a security team can inspect, not just a policy document. Every Auditoria agent operates under three properties.
Bounded. Agents act only within defined permissions. Authorization is resolved before an agent reasons on a record, not after it produces an answer. So agents are never exposed to records that are outside of a requester’s scope.
Adaptive. When a policy is changed, agents apply the new rules immediately, including to any work already in flight.
Transparent. Every action carries its reasoning, the records it drew on, and the governance in effect when the action was carried out. Same question, same answer, with the derivation attached.
How we handle your data and our models
- Customer data is not used to train models shared across customers.
- Model providers are reviewed and contracted as subprocessors before any customer data reaches them.
- Answers are grounded in your systems of record, not the open web, with lineage back to the underlying record.
- Human oversight is configurable by workflow. Teams grant autonomy as the work earns it, by policy rather than by transaction.
Guardian: for the strictest security requirements
Auditoria Guardian is offered as an additional security layer for organizations whose security, compliance, and privacy requirements go beyond those of standard enterprise deployments. It deploys Auditoria’s AI agents inside a fully isolated environment.
- Full data isolation. Your data is separated and managed independently in a single-tenant environment, removing commingling as a source of exposure.
- Bring your own key. Per-tenant encryption key management. You hold the keys, monitor how your data is used, and can revoke access at any time. Currently supported for AWS KMS keys.
- Embedded intelligence. AI runs inside the isolated environment on Auditoria’s specialized finance language models, keeping automation and security within a single boundary.
Available for US-hosted deployments.
Where your data lives and what happens when you leave
What we process. Agents read from your systems of record and your AP and AR mailboxes within the scope you authorize. We synchronize the records that agents need to do the work rather than replicating your entire ERP.
Where it’s hosted. Standard deployments are available in the United States, Canada, and EMEA, with the United Kingdom as primary and Ireland as secondary. Guardian deployments are hosted in the United States.
Encryption. Data is encrypted at rest and in transit using standardized, non-proprietary algorithms. Guardian adds customer-managed keys.
Retention and deletion. Retention periods and post-termination data deletion are governed by your agreement with us.
Controls tested regularly across the security program
We cover all reviews thoroughly across:
- Access. Role-based permissions with single sign-on, privileged access logged and monitored, and prompt deprovisioning on any change in employee or contractor status.
- Code. Automated source code analysis detects security defects before production.
- Testing. Annual network penetration testing, with application penetration testing per industry guidance.
- Recovery. Continuity, backup, and recovery mechanisms tested at least annually.
We maintain completed security questionnaires and can turn most vendor assessments around quickly.
Service agreements and documentation
Access any of our standard documentation:
See something? Say something.
Found a vulnerability? We review every report and respond quickly, and we won’t pursue good-faith security research.
View our Responsible Disclosure Policy and contact us at [email protected].
Security is in our DNA
Auditoria’s dedication to enterprise finance and compliance, and security, is at the core of everything we build. Learn more about us and connect with us to get additional information on our infrastructure.
Learn more about what we build
Guide
How Automation Helps CFOs and Controllers Stay Secure
AI Governance
Coverage Is the New Pedigree
AI for Finance
How to Protect Your Finance Team from Business Email Compromise (BEC)
Report