Live for SOX ITGC & Cloud Security — or bring your own audit program
The audit agent that shows its work
Prufing tests every control against your evidence, cites the exact line it relied on, and holds every verdict as a draft until you sign it. You review results — not chase documents.
- 571
- controls in catalog
- 1028
- tests the agent runs
- 100%
- of findings cited to evidence
- 0
- verdicts auto-accepted
Process
How an audit runs
-
Load the evidence
Upload policies, exports, tickets, and access reviews. Prufing indexes every page so nothing gets tested against thin air.
-
Tally tests the controls
The agent works the control matrix — reads the procedure, samples your evidence, and drafts a verdict for every test in scope.
-
You review, accept, or override
Every verdict arrives with the cited passage it rests on. Agree, override with a note, or send it back — the auditor stays in charge.
-
Export the workpapers
Signed conclusions, evidence trail, and activity log leave the system the way reviewers expect to receive them.
Product
What you get
CIT-01 Citations down to the line
Every finding links to the exact passage in your evidence that supports it. No orphan conclusions.
MTX-02 A control matrix that fills itself
Scope once; watch coverage, exceptions, and review status accumulate across every domain.
HIL-03 Human-in-the-loop by design
Nothing is auto-accepted. A verdict is a draft until an auditor signs it — and the log remembers who signed what.
EVD-04 The original evidence, retained
The real PDF, spreadsheet, or Word file the agent cited stays attached — and renders right in the app.
Workpapers
It ends in a workpaper, not a chat log.
Every engagement exports as an Excel workbook and a matching report: the conclusion for each test, the steps taken against every requirement, and every quote pinned to the file and line it came from — so a reviewer can re-perform the work, not take our word for it.
| Control | Requirement | Found | Quote | Source |
|---|---|---|---|---|
AM-08 | Access revoked within 5 business days of termination | Met | “Access Revoked: YES — 2025-04-16” | terminations.xlsx · line 12 |
AM-02 | Minimum password length of 12 or more enforced | Met | “minimum_password_length = 14” | idp_settings.json · line 61 |
AM-09 | Reviewer sign-off present for the quarter | Violated | “Sign-off: — (blank)” | q2_access_review.xlsx · line 4 |
The originals stay attached, too — click a citation and the spreadsheet it came from opens in the app, on the cited row. And when the agent can’t ground a step in your evidence, the cell stays blank and the finding says so. No invented citations.
Your program
Bring your own framework.
Most audit teams don’t run a textbook framework. They run the program they have refined over years — in a Word document, a spreadsheet, a PDF from the last engagement. Prufing takes that file and turns it into something the agent can actually test. Adopting your own program is an upload, not a project.
- 01 Upload
The Word doc or control matrix you run today.
- 02 Parse
Read into domains, controls and tests.
- 03 Refine
Close the gaps in conversation, not a form.
- 04 Publish
Testable, then live on an engagement.
Difference
An agent that performs the test — not a workflow tool with AI added.
Legacy GRC platforms were designed as forms, tasks, and reminders: software for tracking whether a human did the audit. AI arrived later and was bolted to the side — summarize this document, draft that policy. The testing itself never moved. Prufing starts at the other end. The agent does the test; the workflow exists so you can review what it concluded.
That left column describes a category, not any one vendor. Bring the tool you use today and we’ll run a control side by side with it.
Trust
Built for regulated environments
Workspace isolation
Every engagement is sealed from the next; each request is authorized against membership, not just login.
Evidence is the source of truth
A conclusion the agent can’t trace to a real document is not allowed to pass.
On-prem when you need it
Deploy in your own cloud or air-gapped, bring your own model — evidence never leaves your boundary.
Prove it
Rerun three controls from your last cycle.
Don’t evaluate Prufing on a demo dataset. Evaluate it on work you’ve already concluded — where you know what the right answer was.
- 01 Pick
Three controls from an engagement you have already signed — including one that found an exception.
- 02 Rerun
Upload the same evidence. The agent tests them the way it would on a live engagement.
- 03 Compare
Put its workpaper next to yours, quote by quote. Agreement saves you the hours; disagreement shows you exactly where, cited to the line.