For auditors

Verify your client’s evidence yourself — without taking custody of their data.

ZTZK gives auditors signed results they check independently, in the browser, with no access to us or to the client’s systems. Less evidence chasing, nothing taken on the client’s word, and a trail you can re-perform.

What you receive

An audit pack you can re-perform.

Signed results
A pass or fail for each control, signed with ML-DSA-65 at the moment it was checked.
The rule behind each result
The exact, hash-pinned rule version the check ran against — readable, not a black box.
Coverage over the period
Results across the whole period under review, not samples assembled before fieldwork.
Proofs for sensitive values
Where data is sensitive, a proof that the check passed instead of the record itself.
Manual evidence, signed too
Policies, training and reviews recorded with the owner’s sign-off, on the same ledger.
Audit packSigned
  1. Signed resultsPass or fail per control
  2. Rule fingerprintsThe exact rule version for each result
  3. The whole periodEvery check, in order
  4. Proofs for sensitive factsZero-knowledge, not records
  5. Manual sign-offsPolicies, training and reviews
Verifiable without access to ZTZK or to your systems.

What doesn’t change

Your judgment. Your opinion. Your standards.

ZTZK doesn’t issue reports, certificates or opinions. It changes what evidence looks like: instead of trusting that client-provided evidence is current and complete, you verify the result yourself. How you rely on it stays your call.

Client-provided evidence.Exports and attestations, taken on their word.
Signed results.Verified by you, independently.

For audit firms

See an audit pack before your client sends one.

We’re working with a small number of audit firms early. If your clients are adopting ZTZK — or you’d like to see what verifiable evidence looks like in an engagement — we’ll walk your team through an audit pack.

Request a walkthrough

FAQ

Auditor questions, answered

Do we need to install anything to verify?

No. Verification runs in the browser. You check signatures against published public keys — without access to ZTZK or to your client’s systems.

Does ZTZK issue reports or opinions?

No. ZTZK produces evidence. Your firm performs the engagement, applies its own standards and judgment, and issues the report or certificate.

Can we re-perform the checks ourselves?

Yes. Each result names the exact rule version it was checked against, and the signature and hash can be verified independently, as many times as you like.

What about controls that can’t be automated?

Policies, training and reviews are recorded with the control owner’s sign-off and signed to the same ledger, so manual evidence has the same tamper-evident trail as automated checks.

Will we see sensitive client data?

Only what your engagement requires. Where a value is sensitive, you receive a proof that the check passed rather than the underlying record.

Request access

Walk through an audit pack.

Tell us about your firm and the engagements you run. We'll show you how verification fits your procedures.

We use your email only to reply to your request. Privacy policy

✓ Request received. We'll be in touch.