Privacy

Effective 23 August 2026 · Capto Audit

This product is pre-release. It is in active development and is not yet in use on live audit engagements. This text describes how the system behaves today and will change as it is finished.

Capto Audit is software audit firms use to run engagements. Almost everything in it belongs to the firm using it, not to us: their working papers, their conclusions, and the documents their clients send them. This page says what is held, where it is held, and what happens to it.

What is held

  • People who work at the firm — name, work email, and the role that decides what they may do. Sign-in itself is handled by Clerk, our identity provider; if you sign in with Google we receive your name, email address and profile picture and nothing else.
  • Client contacts — name and email, so documents can be requested from them. They never get an account.
  • Engagement records — the audit work itself: checks, conclusions, review notes, comments, trial balances and adjustments.
  • Documents — files uploaded as evidence, stored under a fingerprint of their own contents.
  • A record of what happened — who did what and when.

Where it is held

On Google Cloud in Singapore (asia-southeast1) — both the database and the document storage. Identity is handled by Clerk, which operates its own infrastructure and holds your sign-in credentials; we never see your password.

The record cannot be edited or deleted

This is the part most worth understanding, because it is unusual.

An audit file is evidence. Its value depends on nobody being able to revise history after the fact, so the record of what happened is append-only — enforced by the database itself, not by convention. Corrections are added; they do not replace what was there before. Review notes are cleared with an explanation rather than removed. A recorded override stays on the item permanently.

A practical consequence: a request to delete an individual entry from an engagement record cannot be honoured in the ordinary way, because doing so would destroy the integrity the file exists to provide. Where the law gives you a right to erasure, the firm running the engagement is the party to approach — they decide what their retention obligations permit, and we act on their instruction.

Client portal links

Client contacts reach their document requests through a link rather than an account. Possession of the link is the credential, so it is treated like a password: it is random, only a fingerprint of it is stored, it is scoped to a single engagement, it expires, and it can be withdrawn. Anyone holding the link can see that engagement’s requests — so it should not be forwarded.

What we do not do

  • We do not sell anything held here, and there is no advertising.
  • We do not use engagement content to train models.
  • We do not send email yet — links are shown on screen to be passed on by the firm.
  • Uploaded documents are not virus-scanned yet. Treat the inbox as untrusted.

How long it is kept

Engagement records are kept for as long as the firm’s retention policy requires — audit files typically must be held for years, and the firm sets that period. Once an engagement is sealed, its contents are fixed permanently.

Getting in touch

If you are a client contact, the firm that sent you the link is the one that holds your data and decides what happens to it. Otherwise, write to privacy@captoaudit.com.

Questions about this page: privacy@captoaudit.com