Security & Trust

Institutional Controls Without Intrusive Access.

Auditor Alpha is engineered so you can connect your financial data with confidence. It reads only what it needs, never writes to your systems without permission, and encrypts everything end to end.

Read-Only by Default

Auditor Alpha connects through the minimum required read scopes. It never alters your live ledgers, creates unauthorised entries, or contacts your clients on its own. Any write level workflow, such as drafting an invoice into Xero, happens only when an administrator explicitly grants permission.

Encrypted End to End

Your financial data is protected with TLS 1.3 encryption while in transit and AES-256 encryption at rest. Both the connection to your systems and the data we process are secured to current industry standards.

Built on SOC 2-Compliant Infrastructure

The platform is built using SOC 2-compliant infrastructure and tooling and follows GDPR-aligned data privacy practices. It has also been independently penetration tested by a third-party cybersecurity firm.

What we can stand behind today

  • TLS 1.3 in transit
  • AES-256 at rest
  • GDPR-aligned data handling
  • Read-only by default
  • Continuous, audit-ready records
  • Independently cybersecurity tested

These reflect the compliance standing of our underlying technology stack, which is hosted on SOC 2 and ISO 27001 certified cloud infrastructure. Auditor Alpha itself has not yet undergone a formal SOC 2 audit. Penetration test scope and reports are available on request as part of an enterprise engagement.

Methodology & measurement

How we measure what we flag.

Auditor Alpha reconciles delivered work in your CRM against invoices in your ledger using a multi-layered matching engine, confidence scoring, and human-in-the-loop governance. Here is what each of those means and what we actually measure.

The multi-layered matching engine

Three layers work together to reconcile operational activity against financial records. All three are operational today.

L1

Deterministic ID Matching

Exact cross-referencing of project codes, purchase order numbers, and client IDs across your CRM and accounting databases.

L2

Semantic Vector Engine

Resolves entity naming variations, for example matching “Acme Corp UK Ltd” in the ledger to “Acme Global” in the CRM, along with custom milestone descriptions.

L3

Heuristic Rules Engine

Evaluates milestone dates, billing windows, contract renewal triggers, and payment terms to highlight discrepancies.

Confidence scoring

Each flagged item carries a transparent confidence rating from 0 to 100%, based on the quality of the parameters that matched. The score is designed to prevent alert fatigue and keep the finance team focused on what matters.

Exact Deal ID + date match95%
Name similarity + value match65%

Human-in-the-loop escalation path

Auditor Alpha runs read-only by default. It identifies and scores discrepancies, but a person always makes the final call.

  1. 01

    Discrepancy flagged

    The matching engine surfaces a potential mismatch between delivered work and the ledger.

  2. 02

    Confidence score assigned

    A transparent 0–100% rating is attached based on parameter match quality.

  3. 03

    Finance team reviews evidence

    Reviewers open side-by-side CRM and ledger evidence links for the flagged item.

  4. 04

    Confirmed or dismissed by a human

    Your team retains full authority to confirm or dismiss every discrepancy.

Key definitions

Revenue Under Assurance (RUA)
The total monetary value of operational transactions continuously cross-referenced and monitored across your CRM and ledger ecosystems.
Transaction coverage
100% of connected transactions are checked continuously, rather than the small fraction a manual, sample-based review typically verifies between cycles.
Potential vs. Validated Revenue
Every alert is explicitly classified as Potential Unbilled Revenue Identified for finance investigation, not as guaranteed cash recovery.
Confidence score (0–100%)
A rating based on match quality. For example, 95% reflects an exact Deal ID plus date match, while 65% reflects a name similarity plus value match.

Data handling principles

Your data stays yours.

Every design decision starts from a simple rule: touch as little of your data as possible, keep your systems in your control, and make it easy to see exactly what happened and why.

Scoped read access

We request the minimum permissions needed to do the job. Auditor Alpha reads the CRM deals and ledger records it reconciles and nothing more. Core auditing workflows never modify your live financial records.

Your production systems stay untouched

The platform runs read-only by default. It never writes, edits, or deletes in your accounting system or CRM. A write level action, such as pushing a draft invoice into Xero, happens only when an administrator explicitly approves it.

Continuous, audit-ready records

Rather than a once-a-year scramble, Auditor Alpha sweeps the CRM-to-ledger pipeline in the background and keeps a clear, timestamped record of every discrepancy it flags and every decision your team makes on it.

GDPR-aligned handling

We follow GDPR-aligned data privacy practices. You can request deletion of your account data and audit history, and revoke any connected integration whenever you choose.

Need the paperwork? A Data Processing Agreement is available on request, and our full list of sub-processors is published for review.

The platform is live

Find the revenue you're losing, free for 7 days.

Auditor Alpha is live. Connect your stack and run a full Revenue Health Check on your own data. No commitment, cancel anytime.

  • No credit card required
  • Live results in minutes
  • Read-only, bank-grade security