Press & founder story.
auditRAMP(AI) builds Luca — deterministic, full-population, reproducible control testing for audit and compliance — founded by Ray Karnes in Durango, Colorado.
Luca brings the reproducibility of fault-intolerant systems engineering to audit.
Why I built Luca.
I build systems where being wrong isn’t an option. For fifteen years I’ve worked in fault-intolerant, regulated domains — industrial-control infrastructure at Schneider Electric, healthcare AI at Overjet, hospital cybersecurity at Tausight, FedRAMP-High endpoint security at SentinelOne. The thread through all of it: when the stakes are real, “probably correct” isn’t good enough. You don’t sample and hope — you test the whole system, prove every claim, and get the same answer every time you run it. Reproducibility isn’t a feature; it’s the job.
When I looked closely at how audit and assurance actually work, I saw the opposite. Auditors test samples, not populations, and live with the sampling risk that leaves behind. The work rests on judgment that can’t be reproduced — run it twice, get two stories. And a wave of AI tools is making it worse, not better: they feed sensitive client evidence into black-box models that can’t give you the same answer twice and can’t show their work. For an engineer trained to prove things, that was alarming. We were bolting non-determinism onto a profession whose entire product is trust.
So I asked a different question: what if you brought that discipline to assurance? Test the full population, not a sample. Make every result bit-identical when you re-run it. Never let client evidence touch the model — use AI only to author the test from a de-identified description of the data, then execute that test deterministically. Keep the auditor in control, with a clean chain of custody. That’s Luca.
The name is deliberate. Luca Pacioli gave the profession double-entry bookkeeping more than 500 years ago — rigor as the foundation of trust. Luca is that same idea for the AI age.
My path here wasn’t linear — I taught myself to code in Beijing, came back to formal computer science at CU Boulder, and have spent my career working adjacent to a domain’s core function: the architecture, not the trade; the standard, not the operation. That structural vantage point is what lets me encode a regulatory canon into software faithfully.
And I’m building it in Durango, Colorado, on purpose. Rural America doesn’t have to wait for technology to be handed down from the coasts — it can build it. A venture-scale AI company in the mountains is exactly the kind of thing this place can produce.
The north star is simple to say and hard to earn: an audit gives reasonable assurance, never absolute — and the profession is right about that. But for the controls we can test deterministically across the whole population, we’re closing that gap. Not with a slogan. With a method. We’re early, building alongside design partners — but the engine already does what it was built to do.
Audit’s AI wave has a reproducibility problem.
- The problem
- Assurance rests on two shaky foundations — sampling (which carries sampling risk) and non-reproducible judgment (run it twice, get two answers). The AI tools arriving in audit largely make this worse by ingesting client evidence into models that are non-deterministic and opaque.
- The bet
- Determinism + full-population coverage + zero-evidence-to-model is a structurally higher tier of assurance for the controls it can test — reproducible, auditor-controlled, and privacy-preserving by design.
- The mechanism
- AI authors the test from a de-identified data description; deterministic code executes it across every record; results are bit-identical on re-run; the model never sees client evidence. That removes sampling risk and run-to-run variance — two of the oldest gaps in assurance.
- The honest boundary
- This doesn’t repeal the inherent limitations of audit, and it doesn’t replace the judgment-heavy or scan/pen-test-shaped work. It owns the data-bearing, population-testable core — and there, it can exceed what sampling allows.
Ray Karnes, Founder & CEO.
For fifteen years, Ray Karnes engineered systems for fault-intolerant, regulated domains — industrial-control infrastructure at Schneider Electric, healthcare AI at Overjet, hospital cybersecurity at Tausight, and FedRAMP-High endpoint security at SentinelOne — where results have to be provable and reproducible. He then turned to a profession built on trust but running on sampling and non-reproducible judgment. Luca applies that engineering discipline to assurance: AI authors each control test from a de-identified data description, deterministic code executes it across the full population, and results are bit-identical on every run, with no client evidence ever reaching the model. On engagement-scale synthetic stress-test datasets, the engine has reached 100% precision and recall across all SOC 2 Trust Services Criteria controls, reproduced across back-to-back runs. Karnes taught himself to code in Beijing and holds a B.S. in Computer Science from CU Boulder. He is building auditRAMP in Durango, Colorado, as a deliberate bet that rural America can lead in the AI economy rather than receive it.
The essentials.
- Company
- auditRAMP(AI), Inc. — Delaware C-Corp
- Founded
- 2026
- Headquarters
- Durango, Colorado
- Web
- auditrampai.com
- Product
- Luca — deterministic, full-population, reproducible control testing for audit and compliance
- How it’s different
- “Orchestrate, don’t ingest”: AI authors tests from de-identified data descriptions; deterministic code runs them across the entire population; zero client evidence reaches the model; results are bit-identical on re-run; the auditor stays in control with chain of custody.
- Core capabilities
- Evidence-Type Preflight · Full-Population Control Testing · Substantive Testing (prove it yourself) · Findings → Workpapers
- Frameworks
- SOC 2 · ICFR / PCAOB AS 2201 (delivered); PCI DSS, HIPAA, ISO 27001 (maturing); CASA / ASVS (in progress)
- Use cases
- Controls testing · full-population substantive testing · SaaS audit-readiness
- Proof point
- 100% precision and 100% recall across all SOC 2 Trust Services Criteria controls on engagement-scale stress-test datasets, reproduced back-to-back. (Synthetic stress-test data; no client evidence.)
- Value
- Roughly 40–55 senior hours / ~$10,000–$14,000 of senior time per engagement on the controls-testing case.
- Stage
- Early; building with design partners.
“I came from a world where every claim has to be provable and identical every time you check it. Audit runs on sampling and judgment that can’t be reproduced. Luca brings the other discipline to assurance.”
On the thesis
“Most AI tools in audit ingest your evidence into a model that can’t give you the same answer twice. Luca does the opposite — the model never sees your evidence, and the test runs identically every time.”
On AI in audit
“The number I care about isn’t the 100%. It’s that it repeated. Reproducibility is the whole point.”
On the milestone
“An audit gives reasonable assurance, never absolute. For the controls we can test deterministically across the full population, we’re closing that gap — with a method, not a slogan.”
On the mission
“We’re building a venture-scale AI company in Durango on purpose. Rural America can lead in the AI economy, not just receive it.”
On rural AI
Get in touch.
Ray Karnes — Founder & CEO
For press, analyst, and speaking inquiries.
Media assets
Founder headshot · Logo (PNG). The interactive financial model is available to investors on request.