Loading AuditFlow…
About
AuditFlow is a product of MNB Research. It exists because the hard part of an internal audit is almost never the audit — it is proving afterwards that the evidence was captured properly, by whom, and when. Most tools that solve that assume your evidence is an API call away. Ours assumes it is a photograph of a damaged rack upright, taken in a warehouse with no signal.
ready-to-run templates
compliance frameworks
mapped controls
industries covered
These four figures are computed from the template catalogue itself. A build fails here if any of them is typed by hand anywhere in the product.
We sell to people who assess suppliers for a living, so the useful thing to publish is not a mission statement — it is the rules the product refuses to break. Each of these is visible in the running app, and you can check every one on Essentials.
The peer benchmark returns no rows at all below eight organisations, rather than a comparison drawn from too few. An unavailable figure on a dashboard says it is unavailable instead of rendering zero. The API's rate-limit header is omitted when the counter cannot be read rather than filled with something plausible. A wrong number a customer has already shown a regulator cannot be taken back.
The industry percentiles in this product are our reference targets, and every screen that shows them says so and names their provenance. They are never presented as observed peer data, because they are not. Where we do measure something across organisations, it is computed in the database with a minimum cohort size, so it cannot be lowered for a demo.
Row-level security on every table, keyed to your organisation, so a query cannot return another tenant's rows even if the application asks. Sign-offs, approvals, score overrides, report shares and permission changes are appended to a per-organisation SHA-256 hash chain that the server recomputes on demand; the database revokes UPDATE and DELETE on that trail and refuses them again in a trigger.
If we cannot read every finding behind a board report, you get no report rather than a short one. An audit report prints its own incompleteness on page one. An audit report is rendered against the questionnaire version the audit was actually filled against, so editing a template afterwards cannot change what a finished audit says.
Where a setting is stored but nothing acts on it yet, the page says so in the product rather than implying it works. A feature that is half-built is described as half-built. It is a slower way to write a product page and it is the only one compatible with selling to people whose job is verification.
In India. The database and file storage are hosted on Supabase in AWS ap-south-1, encrypted in transit and at rest. You can export everything — audits, evidence, action items and reports — at any time, including after a downgrade. Deletion happens when you ask for it, not on our schedule.
A DPA, our subprocessor list and a security practices summary are available on request, and we will complete your own security questionnaire.
We are a small team and we answer directly — there is no queue and no tiered support desk between you and the people who build this.
MNB Research · India
Pick a template, walk the floor with your phone, and read the report before you get back to your desk. ₹999/mo, no trial to run out — you keep the workspace.