For finance and sustainability teams entering their first ISSB-aligned disclosure cycle. Every figure traced from source document to disclosure statement. SHA-256 hash on every evidence file at upload.
An assurer does not test your prose. They pick a figure and ask where it came from, who approved it, and whether it changed after sign-off. Auditably records that chain as the number is entered, so the answer already exists when the question arrives.
See the productCount what a failed first audit actually costs: a remediation sprint measured in hundreds of preparer-hours, a second assurance pass at full engagement fee, a delayed filing, and an audit committee that re-opens every number you file next. Building the trail as you go is a rounding error against rebuilding it under scrutiny.
NSRF, AASB S2, SGX, UK SRS, SB 261: the same IFRS S2 core wearing different jurisdiction rules and dates. Auditably structures your cycle to the standard once, with jurisdiction overlays — so multi-market groups don't run five parallel spreadsheets.
Every reporting cycle is pre-structured to the 33 IFRS S2 disclosure paragraphs across Governance, Strategy, Risk Management and Metrics & Targets — referenced, guided, and tracked to approval. No blank page, no missed requirement.
Every entry, edit, review and approval lands in an append-only activity log — not editable or deletable, even by us. Evidence files are SHA-256 hashed on upload and re-verified on export. That's control an auditor can test, not a policy PDF.
A read-only auditor seat and a one-click auditor pack — disclosures, evidence, hashes and the full log, structured for ISAE 3000 and the forthcoming ISSA 5000. Your first assurance review starts from evidence, not archaeology.
A real, working application — not slideware. Here's what your team actually uses, built around the audit trail from the first click.
Dashboard. Every cycle scored by pillar — exactly what's done, in review, and blocking sign-off.
Disclosure detail. The IFRS S2 paragraph, the structured data point, the evidence, and who touched it — in one place.
| 14:32 UTC | a.tan | approved disclosure · para 6(a)(i) |
| 11:08 UTC | r.rafi | edited narrative · para 29(a)(ii) |
| 09:51 UTC | r.rafi | uploaded evidence · SHA-256 recorded |
| Yesterday | a.tan | submitted for review · para 25(b) |
Audit trail. Every change — who, what, when — written to an immutable log the moment it happens.
Auditor pack. One click. A ZIP your assurance provider can open and trust — disclosures, log, evidence, and a hash manifest.
Every write passes through one service that records the actor, the field, the old value and the new one. UPDATE and DELETE are revoked on the activity table from every role, including ours, with a trigger that raises on any attempt. History cannot be rewritten after the fact.
How the trail worksTell Auditably your jurisdiction, reporting period, and entities in scope. The system loads the right disclosure template — NSRF, UK SRS, AASB S2, ESRS E1, SB 261, or vanilla IFRS S2.
Each IFRS S2 disclosure paragraph appears as its own work item: required data fields pre-defined, evidence slots ready, assigned owner, status tracking. No more "where does this go" guesswork.
Upload source evidence. Enter data points. Draft narrative — or let the AI copilot draft from your structured inputs. Every action is logged: user, timestamp, before-and-after, document hash. Roles for preparer, reviewer, approver, and read-only auditor.
One click. You get a ZIP with: PDF of all disclosures, complete activity log, indexed evidence files, SHA-256 hash manifest, CSV map of every data point to its source. Hand it directly to your assurance provider.
An honest map of the options. The middle column is where a first-cycle, mid-market reporter belongs.
Each evidence item is stored against the data point it supports, with its uploader, timestamp and size. The hash is computed when the file lands and checked again when the auditor pack is built, so a substituted file is detectable.
See the auditor packA cycle opens with the full IFRS S2 requirement set across the four pillars, each paragraph referenced and guided. Progress counts what has been approved, not what has been drafted.
See pricingThe auditor pack is a single ZIP: disclosures as PDF, the activity log as PDF and CSV, every evidence file, an index mapping each disclosure to its evidence, and a manifest listing each file with its hash. Built for ISAE 3000 and the forthcoming ISSA 5000.
Check your assurance dateMalaysia, Australia and Singapore opened their first mandatory periods on FY2025, with later cohorts 12 to 24 months behind and assurance phasing in after disclosure. In Malaysia, reasonable assurance over Scope 1 and 2 becomes mandatory for Group 1 from 1 January 2027.
Check your exact deadlineI kept watching first-cycle reporters do everything right — measure their emissions, draft careful narratives — and still get torn apart in their first assurance review. Not because the disclosure was wrong, but because nobody could show where each number came from, who checked it, or that it hadn't quietly changed.
So I went deep on the standard itself: mapped all 33 IFRS S2 disclosure paragraphs into structured, evidence-linked templates, published deadline guides across nine jurisdictions, and built the free readiness diagnostic and deadline checker on this site. Enterprise platforms solve the trail problem for the Fortune 500; everyone below that tier was left with spreadsheets and a Word template. Auditably is the audit-trail-first system I wished those teams had — structured to the standard, immutable by design, and honest about what it is and isn't.
Persefoni and Watershed are enterprise carbon accounting platforms. They're excellent — and priced from $37,000 to $250,000+ per year. Their buyer is a Fortune 500 sustainability team with mature data infrastructure.
Auditably is the IFRS S2 disclosure system for the next tier down: listed companies entering their first ISSB-aligned cycle, working with leaner teams and a Big 4 advisor. We don't replace carbon accounting platforms at scale. We replace the spreadsheet-and-Word-template workflow that breaks at the first auditor review.
The core product supports IFRS S2 directly, plus jurisdiction-specific overlays for Malaysia (NSRF), UK (UK SRS S2), Australia (AASB S2), Singapore (SGX), California (SB 261), Brazil (CVM), Pakistan (SECP), Nigeria (FRC), Mexico (CNBV), and Indonesia. EU ESRS E1 crosswalk is available on request.
If your jurisdiction is using vanilla ISSB without local modifications, you're fully covered out of the box.
Two ways. First, the read-only auditor seat: invite your assurance provider directly into the platform with view-only access — they can drill into any disclosure, see the data points, view the activity log, and inspect evidence files.
Second, the auditor pack export: one click produces a ZIP containing PDF disclosures, complete activity log (CSV + PDF), all evidence files with SHA-256 hashes, and a master index mapping every disclosure to its underlying evidence. It's structured for ISAE 3000 and the forthcoming ISSA 5000 sustainability assurance standard.
Customer data is held in Supabase (Postgres) with row-level security and tenant isolation. Application infrastructure runs on Cloudflare. Evidence files are stored encrypted at rest with SHA-256 hash verification on upload and export.
SOC 2 Type I attestation is in progress (targeted Q4 2026) — we don't claim certifications we don't yet hold. Custom DPAs and EU data residency are available on request.
Yes. At any time — during your active subscription or your 14-day cancellation window — you can export a full archive of every reporting cycle, every disclosure, every data point, every evidence file, and the complete activity log. CSV, JSON, and PDF formats are all supported.
Vendor lock-in is incompatible with audit-grade software. Your data is yours.
That's typical. The diagnostic is designed for the actual person doing the work — Group Reporting Manager, Sustainability Manager, or ESG Lead. If you're a CFO or Audit Committee Chair evaluating tools, the diagnostic gives you a 12-page report you can hand to your team.
Forward it. We see this every week.
We're early — at the design-partner stage, working directly with first-cycle reporters and their advisors to harden the product against real assurance reviews. We won't pretend otherwise with fake logos or invented "trusted by" numbers.
If you'd rather wait for a longer track record, that's fair. If you'd rather help shape an audit-trail-first tool — and get founder-level attention while you do — this is the moment to start. Run the free diagnostic first; it costs you nothing.
Customer data is isolated per tenant with row-level security in Postgres, served over HTTPS on Cloudflare. Evidence files are SHA-256 hashed on upload and re-verified on export, and the activity log is append-only — it cannot be edited or deleted, even with our own service credentials.
SOC 2 Type I is in progress (targeted Q4 2026). We state security posture plainly and never claim a certification we don't hold.
Your cycle is preserved — locked, with its full audit trail intact — and the data stays yours. Pro accounts can roll forward into the next reporting year and run year-over-year comparisons. Everything you exported (disclosures, evidence, logs) remains reproducible.
You're never locked in: a full archive export is one click away at any time.
Yes. Invite your assurance provider as a free read-only auditor seat — they can drill into any disclosure, inspect the data points and evidence, and read the complete activity log, without being able to change anything. Or hand them the one-click auditor pack. Most teams do both.
Six minutes. Twenty-five questions. A personalised 12-page gap report sent to your inbox. No credit card. No sales call.