A
AuditIQ
Audit inquiry platform
Terms · Privacy

Security overview

Last updated: July 24, 2026 · Written for audit-firm vendor due diligence.

AuditIQ handles sensitive audit evidence — fraud inquiries, legal matters, recordings of client personnel. The platform is built so that the controls an auditor would expect of a vendor are implemented in the product itself and verifiable from the outside.

Data protection

  • Encryption in transit: all traffic is served over TLS; HSTS is enforced in production.
  • Encryption at rest: data lives in a managed Postgres service (Neon) with storage-level encryption.
  • Credential storage: passwords are hashed with scrypt (N=16384) and unique salts; they are never stored or logged in plain text. Password minimum length is 10 characters.
  • Token storage: session tokens and respondent link tokens are 256-bit random values stored only as SHA-256 hashes — a database compromise does not yield usable credentials or links.

Access control

  • Tenant isolation: every query is scoped by firm ID at the SQL layer; cross-tenant access attempts return 404, and isolation is covered by automated tests.
  • Sessions: database-backed, HttpOnly, Secure, SameSite=Strict cookies with a 12-hour expiry; sign-out destroys the server-side session.
  • Respondent links: single-respondent, expiring (default 14 days), revocable at any time, with access logged. Timing-safe comparisons are used for all secret checks.
  • Operator console: separated authentication realm; operator sessions cannot access firm APIs and vice versa.
  • Rate limiting: per-IP limits on sign-in, signup, and interview endpoints to blunt credential stuffing and scripted abuse.

Application security

  • Security headers: a restrictive Content-Security-Policy (first-party only — no CDNs, no third-party scripts, no analytics), X-Content-Type-Options, X-Frame-Options DENY, frame-ancestors 'none', Referrer-Policy, and a Permissions-Policy limiting camera/microphone to this origin.
  • Input handling: parameterized SQL everywhere; HTML escaping on all rendered user content; upload filenames sanitized against path traversal; request body and recording size limits enforced server-side.
  • Dependencies: a deliberately small dependency footprint (Express, the Postgres driver, the Anthropic SDK, and pdfkit) to minimize supply-chain surface.

Recording consent, retention, and audit trail

  • Consent-gated recording: the server refuses audio uploads without recorded audio consent and video uploads without separate video consent. Every consent decision (grant or decline) is stored with a timestamp.
  • Retention: recording content is purged automatically after the engagement's configured retention period (default 365 days, 1–3650 configurable); certified transcripts are preserved as audit evidence.
  • Audit trail: an append-only event log records link issuance and access, consent decisions, respondent turns, certifications, review actions, invoice events, and exports — visible to the firm per engagement.

AI safety controls

  • Mandated inquiry questions are asked verbatim from a fixed library; the model cannot alter them.
  • Follow-ups are capped server-side (default 3 per inquiry).
  • Deterministic, negation-aware rules flag fraud/legal content and force escalation to the human engagement team regardless of model output; escalated matters end AI probing immediately.
  • A rule-based interviewer keeps the workflow functional if the AI provider is unavailable.
  • Firm and respondent data are not used to train models.

Infrastructure and continuity

  • Hosted on Vercel's managed platform (SOC 2 Type II) with a managed Postgres database (Neon, SOC 2 Type II) providing automated backups and point-in-time recovery.
  • Stateless application tier: any instance can serve any request; database failure degrades to clear 503 responses rather than data corruption, with automatic retry on transient faults.
  • Firms can export their full evidence (CSV/JSON/memo) at any time — no lock-in of audit documentation.

Subprocessors

Vercel (hosting), Neon (database), Anthropic (AI), and optionally Deepgram (speech-to-text), ElevenLabs (voice synthesis), Resend (invoice email). Details of what each receives are in the Privacy Policy.

Responsible disclosure

If you believe you have found a vulnerability, please report it to the platform operator with enough detail to reproduce it. We ask that you avoid accessing other tenants' data, and we commit to acknowledging reports promptly and not pursuing good-faith research.

© 2026 AuditIQ · Terms · Privacy · Security