For auditors
Verify your client’s evidence yourself — without taking custody of their data.
ZTZK gives auditors signed results they check independently, in the browser, with no access to us or to the client’s systems. Less evidence chasing, nothing taken on the client’s word, and a trail you can re-perform.
What you receive
An audit pack you can re-perform.
- Signed results
- A pass or fail for each control, signed with ML-DSA-65 at the moment it was checked.
- The rule behind each result
- The exact, hash-pinned rule version the check ran against — readable, not a black box.
- Coverage over the period
- Results across the whole period under review, not samples assembled before fieldwork.
- Proofs for sensitive values
- Where data is sensitive, a proof that the check passed instead of the record itself.
- Manual evidence, signed too
- Policies, training and reviews recorded with the owner’s sign-off, on the same ledger.
- Signed resultsPass or fail per control
- Rule fingerprintsThe exact rule version for each result
- The whole periodEvery check, in order
- Proofs for sensitive factsZero-knowledge, not records
- Manual sign-offsPolicies, training and reviews
What doesn’t change
Your judgment. Your opinion. Your standards.
ZTZK doesn’t issue reports, certificates or opinions. It changes what evidence looks like: instead of trusting that client-provided evidence is current and complete, you verify the result yourself. How you rely on it stays your call.
For audit firms
See an audit pack before your client sends one.
We’re working with a small number of audit firms early. If your clients are adopting ZTZK — or you’d like to see what verifiable evidence looks like in an engagement — we’ll walk your team through an audit pack.
FAQ
Auditor questions, answered
Do we need to install anything to verify?
No. Verification runs in the browser. You check signatures against published public keys — without access to ZTZK or to your client’s systems.
Does ZTZK issue reports or opinions?
No. ZTZK produces evidence. Your firm performs the engagement, applies its own standards and judgment, and issues the report or certificate.
Can we re-perform the checks ourselves?
Yes. Each result names the exact rule version it was checked against, and the signature and hash can be verified independently, as many times as you like.
What about controls that can’t be automated?
Policies, training and reviews are recorded with the control owner’s sign-off and signed to the same ledger, so manual evidence has the same tamper-evident trail as automated checks.
Will we see sensitive client data?
Only what your engagement requires. Where a value is sensitive, you receive a proof that the check passed rather than the underlying record.
Request access
Walk through an audit pack.
Tell us about your firm and the engagements you run. We'll show you how verification fits your procedures.
We use your email only to reply to your request. Privacy policy
✓ Request received. We'll be in touch.