Doing the audit?

Three products. One engine.

Luca is a single deterministic evidence engine delivered as three products: the Assurance Desk every engagement runs through, Substantive Testing for the auditor who signs, and full-population Controls Testing for population-scale books. Start with the part that matches your book — each stands on its own.

Deterministic at the door.Verify every finding.Own the opinion.
Delivered on SOC 2 (AICPA TSP 100) and PCAOB AS 2201 (ICFR), with the HIPAA Security Rule and ISO 27001 authored into the same methodology core.
Product one

The Assurance Desk.

The desk is a collection of deterministic evidence tools — no model in any of them — standing at the point every engagement starts: the evidence hand-off. Every file a client drops is checked against the engagement’s observation window and every in-scope requirement of the framework before anyone spends an hour on it, the request ledger stays reconciled, and chain of custody holds from intake to conclusion.

It’s for every firm that takes custody of client evidence: if your engagements begin with a request list and end with your name on a conclusion, the desk is for you, whatever your population sizes.

Evidence-type preflight

Tag each artifact from a vocabulary constrained to your engagement’s framework, and know instantly where every in-scope control stands: testable on the assembled data, missing a specific named kind of evidence, needing manual attestation regardless, or out of scope — plus which client request would most improve coverage.

The window, not just the type

Every dated artifact is checked against the observation window and gaps are named by date range — “this log stops three months short of period end” — so the conclusion you sign rests on evidence that actually spans the period it claims to.

Request ↔ received reconciliation

A deterministic ledger of what was requested, what actually arrived, what is still missing, and what arrived answering no request — so the follow-up to the client is one precise pass instead of rounds of back-and-forth, and corrected files replace deficient ones under the same chain of custody.

Chain of custody, by design

It is the auditor — not an automated integration — who places each artifact into the engagement and declares what it is. The data Luca analyzes is data you took possession of and vouched for, so every conclusion is grounded in something you can point to and personally stand behind.

Firm-level QM monitoring

The desk’s deterministic signals — what was checked, what was covered, what was reconciled, on every engagement — are packaged into the monitored record SQMS No. 1 (and PCAOB QC 1000) requires: engagement-derived, reproducible, produced by doing the audit rather than by documenting that you did.

No agents. No API integrations. And no new system of record — the desk is a checkpoint on the evidence hand-off your firm already makes: the files you already export, dropped once; answers in seconds; a portable output that feeds whatever platform you already run — so the tools you already trust conclude on cleaner inputs.

Product two

Substantive Testing.

The name on the opinion is yours, not the machine’s.

No auditor can sign an opinion on something they can’t verify — professional skepticism is the job, and any system that answers “trust me” should be a non-starter in this profession. Luca is built the opposite way: it puts substantive testing — going to the underlying records themselves — directly in the auditor’s hands, with no SQL fluency required.

Ask in plain language and the copilot drafts the query, grounded in Luca’s hand-written example queries — or write your own. Either way, every query passes a deterministic validation gate before it touches the evidence: locked to read-only, checked against the engagement’s actual schema, and trial-run, so anything that wouldn’t run cleanly is caught and explained first. On every engine finding, one click loads a ready-made “check this yourself” query, labeled in plain English with what it shows and why it supports the finding, and the underlying records appear.

Here, AI enters on your side of the table — and no identifying value ever reaches the model: before any model interaction, identifying values are replaced with consistent cryptographic tokens the model can reason over, join on, and conclude about, and the real values render only on your screen. It looks as if the AI worked the real records. Structurally, it never saw a single identifying value.

Product three

Full-population Controls Testing.

Test the whole population, not a sample of it.

Traditional control testing samples: examine a handful of items and assume the rest resemble them. That assumption is sampling risk, accepted only because testing everything by hand is infeasible. Luca evaluates each control against the entire population of in-scope records — an exact, reproducible N-of-M rate wherever a denominator applies — so sampling risk is removed from the measurement by construction: the near-absolute assurance the profession could never buy by hand, at a marginal fee.

It spans the ICFR spectrum: 404(a) management assessments, FDICIA banks, and Model Audit Rule insurers — real populations on fixed fees, where the mechanical testing is the margin — all the way to full SEC-level SOX 404 and cloud-scale attestation.

Private by architecture: the model works only from a de-identified description of your data — its structure and statistical profile — and binds it to Luca’s hand-written tests; deterministic database code reads the records and returns only aggregates. And because AI cost tracks the number of controls, not the number of records, ten thousand rows and ten million cost the same in inference — full-population rigor at sampling-level economics.

Luca measures; it does not opine. The thresholds that turn a rate into a severity or a finding are configured by the auditor, where professional judgment belongs. Every finding becomes an auditor-owned record — classified in the engagement’s own regulatory vocabulary under an append-only history, with disagreement first-class — and the deliverable is a self-contained collection of reports a reviewer can match back to a fresh pull of the data: tested rows carry identifying values in a reverse-matchable masking — the first and last few characters visible, the interior asterisked, the convention Big 4 reviewers already know.

What full population costs by hand

The assurance nobody could ever buy.

Testing a control across a real population manually is arithmetic nobody bills: the population, times minutes per record, times a blended senior rate. On a representative 10,000-record co-source population, at a conservative two minutes a record and a $150 blended rate, that is $50,000 of manual testing on a single engagement. At flagship population scale it runs to seven figures — several times the engagement’s own fee.

That is what full population costs by hand — which is exactly why nobody has ever bought it, and why the profession accepted sampling risk instead. Luca delivers the near-absolute assurance at a marginal fee.

~$50,000
manual-equivalent testing on a representative 10,000-record co-source engagement
Seven figures
manual equivalent at flagship population scale

Representative modeled magnitudes — population × minutes per record × blended senior rate — not a quote.

Why it holds up

You take custody of the evidence.

Unlike tools that wire into the auditee’s systems and pull the evidence for you — where a clean-looking opinion can rest on data no one inspected — Luca has you take direct custody: you export the evidence and label it, so every conclusion rests on data you possessed, can inspect, and can personally stand behind. In a profession where your signature carries statutory weight, that chain of custody is the foundation, not an inconvenience to automate away.

FAQ

Questions auditors ask.

What is the Assurance Desk?
A collection of deterministic evidence tools — evidence-type preflight, observation-window coverage, request ↔ received reconciliation, and chain-of-custody intake — that checks every artifact a client sends against the engagement’s framework and observation window the moment it lands, with no model in the path. A firm-level quality-management layer packages the desk’s signals into the monitored record SQMS No. 1 and PCAOB QC 1000 require.
Can I run Luca if my populations are small enough to sample by hand?
Yes — that is exactly what the Assurance Desk and Substantive Testing are for. The desk does not care how big your populations are; it cares that you conclude on evidence a client sent you. Full-population Controls Testing is the third product, for population-scale books, and you can skip it entirely.
What is full-population control testing?
Luca evaluates every in-scope record against a control’s criteria instead of a sample, so sampling risk is removed by construction — the result is a measured exception rate, not one inferred from a subset.
Does Luca’s AI see our client evidence?
No. In controls testing the model works only from a de-identified description of your data — its structure and statistical profile — and binds it to Luca’s hand-written tests; deterministic database code reads the records and returns only aggregates. In the substantive workspace, identifying values are replaced with consistent cryptographic tokens before any model interaction, and the real values render only on the auditor’s screen.
Is an AI-assisted audit defensible?
Yes — because Luca puts a human in the loop at every decision point instead of burying the judgment in a black box. You take custody of the evidence; Luca surfaces each exception with the records behind it; you verify it and set the thresholds that turn an exception rate into a finding. Every one of those steps is captured in a fully exportable audit trail — so you can prove to yourself, and to a regulator, that the work product holds up before it ever enters your workpapers. Luca measures; you own the opinion.
Which compliance frameworks does Luca support?
Delivered on SOC 2 (AICPA TSP 100) and PCAOB AS 2201 (ICFR) today; the HIPAA Security Rule and ISO 27001 are authored into the same methodology core and maturing behind them.
Get started

Run Luca on your next engagement.

Tell us about your practice and the standards you test against, and we’ll set you up with a founding-cohort engagement. On the other side of the audit? See Luca for SaaS audit-readiness.