Security overview
Last updated: July 24, 2026 · Written for audit-firm vendor due diligence.
AuditIQ handles sensitive audit evidence — fraud inquiries, legal matters, recordings of client
personnel. The platform is built so that the controls an auditor would expect of a vendor are
implemented in the product itself and verifiable from the outside.
Data protection
- Encryption in transit: all traffic is served over TLS; HSTS is enforced in production.
- Encryption at rest: data lives in a managed Postgres service (Neon) with storage-level
encryption.
- Credential storage: passwords are hashed with scrypt (N=16384) and unique salts;
they are never stored or logged in plain text. Password minimum length is 10 characters.
- Token storage: session tokens and respondent link tokens are 256-bit random values
stored only as SHA-256 hashes — a database compromise does not yield usable credentials or links.
Access control
- Tenant isolation: every query is scoped by firm ID at the SQL layer; cross-tenant
access attempts return 404, and isolation is covered by automated tests.
- Sessions: database-backed, HttpOnly, Secure, SameSite=Strict cookies with a 12-hour
expiry; sign-out destroys the server-side session.
- Respondent links: single-respondent, expiring (default 14 days), revocable at any
time, with access logged. Timing-safe comparisons are used for all secret checks.
- Operator console: separated authentication realm; operator sessions cannot access
firm APIs and vice versa.
- Rate limiting: per-IP limits on sign-in, signup, and interview endpoints to blunt
credential stuffing and scripted abuse.
Application security
- Security headers: a restrictive Content-Security-Policy (first-party only — no CDNs,
no third-party scripts, no analytics), X-Content-Type-Options, X-Frame-Options DENY,
frame-ancestors 'none', Referrer-Policy, and a Permissions-Policy limiting camera/microphone to
this origin.
- Input handling: parameterized SQL everywhere; HTML escaping on all rendered user
content; upload filenames sanitized against path traversal; request body and recording size
limits enforced server-side.
- Dependencies: a deliberately small dependency footprint (Express, the Postgres
driver, the Anthropic SDK, and pdfkit) to minimize supply-chain surface.
Recording consent, retention, and audit trail
- Consent-gated recording: the server refuses audio uploads without recorded audio
consent and video uploads without separate video consent. Every consent decision (grant or
decline) is stored with a timestamp.
- Retention: recording content is purged automatically after the engagement's
configured retention period (default 365 days, 1–3650 configurable); certified transcripts are
preserved as audit evidence.
- Audit trail: an append-only event log records link issuance and access, consent
decisions, respondent turns, certifications, review actions, invoice events, and exports —
visible to the firm per engagement.
AI safety controls
- Mandated inquiry questions are asked verbatim from a fixed library; the model cannot alter them.
- Follow-ups are capped server-side (default 3 per inquiry).
- Deterministic, negation-aware rules flag fraud/legal content and force escalation to the
human engagement team regardless of model output; escalated matters end AI probing immediately.
- A rule-based interviewer keeps the workflow functional if the AI provider is unavailable.
- Firm and respondent data are not used to train models.
Infrastructure and continuity
- Hosted on Vercel's managed platform (SOC 2 Type II) with a managed Postgres database (Neon,
SOC 2 Type II) providing automated backups and point-in-time recovery.
- Stateless application tier: any instance can serve any request; database failure degrades to
clear 503 responses rather than data corruption, with automatic retry on transient faults.
- Firms can export their full evidence (CSV/JSON/memo) at any time — no lock-in of audit
documentation.
Subprocessors
Vercel (hosting), Neon (database), Anthropic (AI), and optionally Deepgram (speech-to-text),
ElevenLabs (voice synthesis), Resend (invoice email). Details of what each receives are in the
Privacy Policy.
Responsible disclosure
If you believe you have found a vulnerability, please report it to the platform operator with
enough detail to reproduce it. We ask that you avoid accessing other tenants' data, and we commit
to acknowledging reports promptly and not pursuing good-faith research.