Assurance statement
What this software does, and where your responsibility begins.
Auditably is a workflow and evidence tool. It records where a disclosed figure came from, who reviewed and approved it, and what changed. That is the whole of it. This page sets out the boundary in the terms a preparer, an audit committee and an assurance provider each need, so none of them has to infer it from marketing copy.
What the platform does
Four things, and they are mechanical.
It holds a register of evidence: source documents attached to the figures they support, each hashed with SHA-256 on upload, with the hash re-verified when an export is produced.
It records a review and approval trail: which named user moved a disclosure to ready-for-review, which named user approved it, and when. Approval is restricted to a user holding the approver role, and that restriction is applied by the server rather than by the interface.
It keeps an append-only activity log. Every create, edit, upload and status change is written with the actor, the timestamp and the before and after values. UPDATE and DELETE are revoked on that table at database level, from every role including our own service account. You can test that claim against our live database at the proof page.
It produces an export containing the disclosures, the complete activity log, every evidence file with its hash, and an index mapping each disclosure to the evidence behind it.
What it does not do
It does not make anything true.
It does not calculate emissions. There is no calculation engine in the product. You bring an inventory prepared elsewhere; we record the figure, the unit, the method note and the emission factor you supplied, together with its stated source. We do not check any of them.
It does not validate your data. A figure taken from the wrong invoice, an emission factor from the wrong year, or a unit conversion applied twice will be recorded faithfully and preserved permanently. An append-only log proves a record was not altered after it was written. It says nothing about whether the record was right when it was written.
It does not provide standards interpretation, and it does not provide legal or accounting advice. Our published guides are reference material. They are not advice about your entity and not a substitute for your own advisers.
It does not provide assurance. No software can. Assurance is an engagement performed by an independent practitioner who reaches their own conclusion on their own evidence.
Management responsibility
What stays with you, whatever software you use.
Management remains responsible for the preparation of the disclosures and for the judgements inside them: what is material, which risks and opportunities are reported, how scenarios are chosen and applied, which measurement approach is used, and whether a figure is accurate.
Management is also responsible for the design and operation of the controls around all of that. Auditably records the operation of some of those controls. It does not design them, and it cannot tell you whether the ones you have are sufficient.
Nothing produced by this software transfers any part of that responsibility to us, and using it is not a substitute for independent validation of your emissions inventory.
The assurance standards
Two standards, and what they actually govern.
Sustainability assurance engagements have been performed under ISAE 3000 (Revised), the International Standard on Assurance Engagements for subject matter other than historical financial information.
ISSA 5000, the International Standard on Sustainability Assurance, was approved by the IAASB and applies to sustainability assurance engagements for periods beginning on or after 15 December 2026, with early application permitted. It can be applied to any sustainability topic and any reporting framework, for both limited and reasonable assurance.
Both are standards for the practitioner, not for the preparer’s software. There is no such thing as software that is compliant with either, and a vendor who says otherwise has described a different thing. What a practitioner needs from you is evidence they can test and a record of the controls you operated. That is what the export is for. Whether it is sufficient in your engagement is your practitioner’s judgement, not ours.
Also worth reading
The rest of the boundary.
The coverage matrix, including five rows where the answer is nothing →
Security, data handling and certification status →
Test the append-only claim against our live database →