Coverage
What this product does, what it does not, and where it stops.
Most software pages list what a product can do. The part that decides whether it fits is the other half. Every row below carries a limitation, including the rows where the answer is a straight yes, and the status on each was checked against the running code rather than a roadmap.
Four statuses, and they mean exactly what they say. Available works today. Limited works within a boundary that is written in the row. Partner-supported means someone else does it, not us. Not available means there is nothing there, and no date attached.
| Requirement | Status | What you get | Limitation |
|---|---|---|---|
| IFRS S2 disclosure workflow | Available | All 33 IFRS S2 disclosure items are created for each reporting cycle, grouped by the four pillars, each with its own status, narrative and data points. | The templates cover the standard. Deciding what is material to your entity, and whether a disclosure is complete, remains management’s responsibility. |
| Evidence register | Available | Attach source documents to a figure. Each file is hashed with SHA-256 on upload and the hash is re-verified when the auditor pack is produced. | We verify the file has not changed since upload. We do not read the document, and we cannot tell you whether it supports the figure. |
| Review and approval workflow | Available | A disclosure moves through not started, in progress, ready for review and approved. Only a user holding the approver role can approve. | One approval step, not a configurable chain. Nothing prevents the same person preparing and approving if they hold the approver role. |
| Roles and permissions | Available | Preparer, reviewer, approver and auditor read-only. Enforced in the API rather than hidden in the interface: an auditor read-only account is refused on write. | Enforcement is server-side because the Worker is the only writer. Row-level security covers reads and does not branch on role. |
| Adding people to an organisation | Available | An approver can invite by email, set the role, change it later, or remove someone. Seats follow the plan: one on Practitioner, five on Pro. | One account belongs to one organisation, there is no way to move a person between organisations, and an organisation must keep at least one approver. |
| Append-only activity log | Available | Every create, edit, upload and approval is recorded with the user, the time, and the before and after values. UPDATE and DELETE are revoked at database level. | It proves a record was not altered after it was written. It does not prove the record was right when it was written. |
| Auditor pack export | Available | One export produces the disclosures, the complete activity log as CSV and PDF, every evidence file with its hash, and an index mapping each disclosure to its evidence. | A pack is an input to an assurance engagement, never an outcome of one. Your practitioner performs their own procedures and reaches their own conclusion. |
| Excel import and round trip | Available | Import from a spreadsheet with column mapping that is remembered for next time, and export a working or round-trip workbook to edit and bring back. | The import validates structure and flags what it cannot read. It does not validate whether the numbers are right. |
| Scope 1 and 2 inventory | Available | Import the inventory you already have. Each figure keeps its unit, its calculation method note, and the emission factor with its source. | This is a record, not a calculation. Auditably does not compute emissions and does not check the factor you supply. Bring a verified inventory. |
| Scope 3 | Not available | Nothing. Scope 3 is not modelled in the product. | There is no Scope 3 category structure, no supplier collection and no financed-emissions support. If Scope 3 is in scope for you, this is not the tool for it. |
| Multi-entity consolidation | Not available | Nothing. On Pro you can run several reporting cycles, and you would use one per entity. | There is no group structure, no roll-up, no intercompany elimination and no consolidated view. Consolidation happens outside the product. |
| Jurisdiction overlays | Limited | Each cycle records the jurisdiction you are reporting under, and it appears on the cycle and in the export. | It is a label. It does not change the disclosure templates, add local requirements, or apply jurisdiction-specific validation. Our jurisdiction guides are maintained reference material, not product configuration. |
| XBRL tagging | Not available | Nothing. | There is no XBRL output and no inline XBRL tagging. If your filing requires tagged data, you will produce it elsewhere. |
| ISSA 5000 and ISAE 3000 | Not available | Nothing a standard-setter would recognise as support. We publish reference material on both. | These are standards for the assurance practitioner, not for the preparer’s software, and no tool delivers compliance with them. ISSA 5000 applies to periods beginning on or after 15 December 2026, with early application permitted. |
| AI disclosure drafting | Available | On Pro, draft narrative text for a disclosure using your own OpenAI API key. The key stays in your browser and is never sent to us. | It drafts language. It does not check facts and does not know whether your figures are right. Everything it writes is yours to verify before you publish it. |
| Single sign-on (SSO) | Not available | Nothing. Sign-in is email and password. | No SAML, no OIDC, no directory provisioning. If your security policy requires SSO, we do not meet it today. |
| Multi-factor authentication | Limited | Can be enabled per account through our authentication provider. | It is not enforced organisation-wide and there is no admin control to require it of everyone. Treat it as available per user, not as a policy you can impose. |
| Data residency | Limited | Data is held in managed Postgres in the ap-northeast-1 region (Tokyo), with evidence files in object storage alongside it. | You cannot choose the region, we do not offer in-country hosting, and the location above is where data sits today rather than a contractual commitment. If your policy requires a named jurisdiction, ask before you buy. |
The honest summary
Five rows say nothing is there.
Scope 3, multi-entity consolidation, XBRL, single sign-on, and support for the assurance standards themselves. If any of those is a requirement rather than a preference, this is the wrong product and you have found that out on a public page instead of four calls in.
The product does one thing: it holds the documentation, review record and change history behind figures you have already prepared, and exports them in a form an assurance provider can test. Everything in the Available column serves that. Nothing else is claimed.
Two ways from here
Read on, or ask a person.
Everything stays open either way. The diagnostic is free and ungated, both prices are published, and the coverage matrix lists what the product does not do. If you would rather put a specific question about your entity to someone, that route exists too, and using it unlocks nothing you cannot already read.
Start the free diagnostic →
Talk to a reporting specialist →