NEW RESEARCH: Your Sandbox Is Made of Glass

Read

Trinitite

PricingResearchBlogPodcasts

Glossary / Continuous Audit

Definition

What is Continuous Audit?

Audit as a stream

Continuous audit turns the once-a-year engagement into a signed, rolling stream that internal audit, external audit, regulators, and underwriters consume continuously. Trinitite composes four primitives — Continuous Controls Testing, Continuous Controls Operating Effectiveness, Continuous Attestation, and a Continuous Auditor Agent — into one chain of custody on a deterministic substrate.

The annual cadence was built for systems that change slowly; AI does not. CCT runs scheduled control tests (SQL/Spark/dbt/API probe), each run a signed row; CCOE Merkle-roots four signed inputs each cycle into a KMS-signed workpaper auditors replay independently; Continuous Attestation is a cursor-based chunked verifier that signs anchor receipts as evidence accrues.

The Continuous Auditor Agent compiles a natural-language rule — “no PHI in outbound LLM calls” — into a deterministic llm_rule op bound to a guardian, runs it each period, and signs a DLIR-backed verdict the auditor cites by chain_hash. Distinct from per-event Continuous Assurance; this is the per-cycle control-evidence pipeline, and the two compose on the same substrate.

See Continuous Audit in action.

Run the free 1,000-log pre-audit and get a signed, reproducible report you can verify in a browser — no NDA.