Self-serve audit
In-browser · no upload · up to 10,000 rows

Run VeraStream on your own ledger.

Drop a CSV or paste rows. The eight production detectors run against it locally — no upload, no signup, no trace leaves your tab.

Tested with up to 10,000-row exports. Above that,VeraStream slices the input with a warning so the run stays responsive. Share findings via a compact, URL-safe summary link (no raw ledger in the URL).

Expected columns

We auto-recognize the typical aliases — amount / amt / total, vendor / payee / supplier, date / posted date, invoice #, and so on. Minimum for a run: amount + vendor + date.

datevendoramountinvoice_numbercategorysubmitterapproverpayment_methodgl_codebooking_dateattendees_countdescription

Security & trust

SOC 2 Type I in progressTLS 1.2+ in transitAES-256 at restUS data residencySub-processor list disclosed
Read our security & trust details →

Frequently asked

/audit FAQ — what runs, what doesn't, and what gets shipped

The five questions the self-serve tool draws most — what touches your data, which rules fire, and how to share findings safely. Plain HTML answers — no JavaScript required to read.

Does /audit upload my CSV anywhere?

No. /audit parses and scans your CSV entirely in the browser — the file never leaves your tab. There is no backend ingestion on this surface, no signup, and no account row written against your ledger.

Which detectors actually run on my CSV?

The same eight production VeraStream detectors — policy / SOD, duplicate invoice, expense anomaly, vendor risk, threshold gaming, round-dollar, duplicate payment, and ghost employee. Every rule that fires ships the workpaper (the receipt, the rule that tripped, the override applied) — not just a black-box score.

How big can my CSV be?

Tested with up to 10,000-row exports. Above that, VeraStream slices the input with a warning so the run stays responsive in your browser. Larger continuous feeds are covered by /pilot and the production tier, which connect to ERP sources directly.

Do I need to sign up to use /audit?

No signup, no account creation, no email gate. Drop a CSV or paste rows and the eight detectors run immediately against your local copy. The only thing the run produces is a compact, URL-safe summary link and a PDF export you can save.

Can I share the findings with my auditor or finance lead?

Yes. Each /audit run produces a compact summary link (no raw ledger in the URL — your numbers are never embedded in the share token) and a PDF export with the full workpapers. Both are safe to forward internally; access is by possession of the link, and links do not expose data you did not already choose to flag.