Audro logo
Financial Analysis · Document Processing Files

Audro

Audro is an AI agent for Swedish statutory audit. It runs the engagement from SIE file to sign-off, covering risk assessment, sampling, cut-off, VAT and F-skatt checks, while the licensed auditor approves every decision.

Active GDPR compliant Contact Sales No public API Verified by Guidaio
Overview

What is Audro?

Audro is an AI agent built for Swedish statutory audit, published by Audro Technologies AB in Stockholm. Its stated division of labour is blunt: the agent does the grunt work, the auditor keeps the judgement and the signature.

The tool drives a complete engagement from the SIE file to sign-off, planning, testing and documenting as it goes. Work begins by connecting the client, pulling the SIE file and supporting documents straight from Fortnox or uploading them manually. Audro then analyses the accounts, flags risk items against the materiality threshold and proposes an audit plan. Nothing is tested until that plan is approved. Once it is, the agent carries out substantive testing along the plan: cut-off checks, audit sampling that follows the standards, invoice-to-voucher matching, and VAT and F-skatt controls, with every finding backed by audit evidence. The auditor then reviews the findings, approves or rejects each one, and exports finished working papers into the engagement file.

Underneath sit six building blocks: automated SIE parsing, a configurable sampling methodology, automatic invoice matching, risk and anomaly detection against the firm's own rules, systematic VAT and periodisation checks, and full evidence traceability. Judgements are anchored in a knowledge base of ISA standards retrieved while the agent works, rather than in whatever a general-purpose model happens to remember, and an append-only register records what was examined, why a conclusion was reached and which standard was applied.

The design is deliberately interruptible. The agent proposes rather than acts, and material judgement calls, such as materiality, policy choices and requests for client documents, pause and wait for the auditor. Requests to the client are sent from the auditor's own Microsoft 365 mailbox rather than a shared vendor inbox.

The scope is narrow and openly so: K2 and K3 frameworks, SIE files, Swedish VAT and F-skatt, and the Swedish business register. Access is through a browser at app.audro.se, with roles for organisation admin, company admin and member. There is no API, no mobile application and no published price, so evaluation starts with a demonstration.

What it does

  • Run a complete Swedish audit engagement from SIE file to sign-off
  • Assess risk against the materiality threshold and propose an audit plan for approval
  • Perform substantive testing: cut-off checks, audit sampling, invoice matching, VAT and F-skatt controls
  • Match every transaction to its supporting document automatically
  • Trace each conclusion back to its evidence and to the standard applied
  • Send client document requests from the auditor's own Microsoft 365 mailbox
  • Export finished working papers into the engagement file
Audience

When to use Audro / When not to

A quick filter to help you decide if Audro is the right fit.

When to use Audro

  • Swedish audit firms running K2 and K3 engagements for small and mid-sized companies
  • Authorised auditors who sign off on SME accounts and want the substantive testing prepared for them
  • Independent, sole-practitioner auditors working without a large support team behind them
  • Financial controllers carrying out internal audit work inside their own organisation
  • Audit teams already working from SIE files and Fortnox ledgers

When not to use Audro

  • Auditors working outside Sweden: the tool is built on SIE files, K2 and K3, Swedish VAT and F-skatt, with no other national framework announced
  • Firms that need an API or an on-premise deployment, since Audro is a browser-only web application
  • Anyone hoping for a fully autonomous audit: the workflow deliberately stops for human approval and the vendor rejects the autopilot framing
  • Buyers who require a published price, standard terms of service and a self-serve sign-up before they will evaluate a vendor
  • Procurement teams that insist the vendor itself hold SOC 2 or ISO 27001, because Audro holds no certification of its own
Get started

How to use Audro

A typical end-to-end flow, from setup to results.

  1. Request a demonstration: there is no self-serve sign-up, so access starts with a conversation with the vendor
  2. Sign in to the web application at app.audro.se; nothing is installed locally
  3. Distribute roles across the firm: organisation admin, company admin and member
  4. Connect the client, pulling the SIE file and supporting documents from Fortnox, or upload them yourself
  5. Let Audro analyse the accounts and flag risk items against your materiality threshold
  6. Review the proposed audit plan and approve it, since nothing is tested until you do
  7. Let the agent run the substantive testing: cut-off, sampling, invoice matching, VAT and F-skatt controls
  8. Answer the judgement calls the agent pauses on, such as materiality, policy choices and client requests
  9. Send document requests to the client through your own Microsoft 365 mailbox
  10. Go through the findings, approve or reject each one, then export the finished working papers to the file
Quick read

Pros & Cons

Pros

  • Auditor-in-the-loop is structural rather than cosmetic: nothing runs before you approve the plan, and judgement calls pause the workflow
  • Every conclusion is traceable from finding to evidence to the standard applied, in an append-only register
  • Judgements are grounded in a retrieved ISA standards base rather than in what a general model happens to recall
  • Customer data is never used to train models and never written into the knowledge base, stated consistently across three pages
  • Tenant isolation is enforced in the database itself with PostgreSQL row-level security, not only in application code
  • Security and data protection documentation is unusually detailed: eight named sub-processors, described data flows and a DPA on offer
  • Data is stored in the EU by default, with a US region available on request

Cons

  • No published pricing whatsoever: no amount, no tier, no plan, and the only way in is a demonstration
  • No terms of service, no formal privacy policy and no legal notice; the site is five pages and every legal route returns a 404
  • No postal address is published anywhere: the footer gives only the city, Stockholm
  • No API, no mobile application and no self-serve sign-up, so access is browser-only
  • Audro holds no certification of its own; the SOC 2 and ISO 27001 badges belong to its suppliers, as the site itself makes clear
  • AI inference can leave the EU, since the vendor states there is no EU-bounded data zone today for the Claude models it runs
  • A very young and very small vendor: the domain was registered in November 2025, there is no web archive history, and the Swedish register lists a single board member and no employees
Pricing

Pricing & Plans

Audro publishes no pricing. There is no pricing page, and no amount, currency or billing unit appears anywhere on the site or in its application bundle. Neither a permanent free plan nor a free trial is announced. Commercial terms are obtained by requesting a demonstration; the only other entry point on the site is the sign-in screen reserved for existing customers.

Prices and plans listed above may evolve. Always check the official pricing page before subscribing.
Trust & Privacy

Data, GDPR & hosting

A consolidated view of how Audro handles your data.

GDPR overview

GDPR is addressed explicitly, and in unusual detail for a company of this size. The homepage states that Audro complies with GDPR, and a dedicated Data protection and GDPR page, last updated June 2026, sets out the controller and processor split, names eight sub-processors with their purpose, the data they touch and their certifications, and describes how client data flows. A data processing agreement is available to every customer, and Audro undertakes to notify customers before adding or replacing a sub-processor so they can object. International transfers are covered by appropriate safeguards including the EU Standard Contractual Clauses. Data subject requests are handled by the client firm as controller, with Audro supplying the access, export, rectification and deletion functions needed to answer them. Breaches are notified without undue delay. No Article 27 representative is named, which is consistent, since the publisher is established in Sweden.

Who owns the data?

Your firm keeps ownership of everything it puts into Audro. On the published data protection page, the client firm is the data controller and Audro Technologies AB acts only as processor, working on documented instructions. Audro states it processes engagement data solely to produce the result you asked for, and for no independent purpose of its own. Customer data is never used to train AI models and is never written into the vector knowledge base, which holds public ISA standard text only. Embeddings of your own documents stay inside Audro's database. A data processing agreement is offered to every customer.

Reuse rights

Audro publishes no terms of service, so no contractual clause states what you may do with the output. What the data protection page does establish is that the material remains yours: your firm instructs Audro, and Audro's use is confined to producing your result. Finished working papers are exported into your own engagement file, client document requests leave from your own Microsoft 365 mailbox rather than a shared vendor inbox, and access, export, rectification and deletion functions are provided so that you can answer data subject requests as controller. Nothing on the site restricts your reuse of what you export, but nothing grants it in writing either.

Data retention & training

Retention summary
Audro keeps engagement data only as long as it needs it to deliver the service. On request, or when the contract ends, customer data is deleted, and the vendor states that the customer stays in control of its data throughout. No numeric retention period is published anywhere on the site. Because the client firm is the data controller, it handles requests from data subjects itself; Audro's role as processor is to supply the access, export, rectification and deletion functions needed to answer them, and to assist as the GDPR requires. Personal data breaches affecting customer data are notified without undue delay. One residual retention sits outside Audro's control: Microsoft may keep a sample of content for abuse monitoring, with any human review carried out by staff inside the EEA for services deployed there.
Trains on customer data
No
Subprocessors disclosed
Yes
DPA available
Yes

Hosting summary

Audro stores data in the EU by default. The database, authentication and file storage run in an EU region of Supabase, which itself runs on AWS, while the application and processing services run in an EU region of Railway. A US region is available on request for customers who require it. No individual hosting country is ever named: the site speaks in regions rather than jurisdictions. Data is encrypted with AES-256 at rest and TLS in transit, keys are managed by the platform and never exposed to application code, and tenants are separated by PostgreSQL row-level security so a query can only return rows the signed-in user is entitled to. AI inference is a separate matter: it runs on Microsoft Azure, and the page describing where that data rests still carries an unfilled template placeholder. Embeddings of customer documents stay in Audro's own database and are never placed in an external vector service, which holds public standards text only.

Hosting regions
EU
Availability

Where Audro works

Country-level availability.

Available in

SWE
Watch-outs

Things to keep in mind

Risks and trade-offs to weigh before adopting Audro.

  • Professional responsibility cannot be delegated: the promise that the decisions stay yours is a design principle, not a published contractual guarantee, and the signing auditor still carries the liability
  • Automation bias is the real human risk: a neatly prioritised list of findings is easy to approve without re-reading, and the file that results carries your signature
  • AI inference may be processed outside the EU even though the data is stored inside it, and Microsoft may retain a sample of content for abuse monitoring
  • The data protection page still displays an unfilled template placeholder where the Azure geography of data at rest should appear, which suggests the page has not been fully finished
  • With no terms of service and no privacy policy published, contractual protection rests entirely on a data processing agreement negotiated case by case
  • The vendor holds no security certification of its own, and every SOC 2 or ISO 27001 mentioned covers only a supplier's processing, not Audro's
  • Supplier concentration risk: a company registered in early 2026 with one board member and no declared employees would be holding a firm's most sensitive client material
Setup

Setup & Integrations

Technical difficulty

Low for the end user, but not self-serve. Audro is a web application, so there is nothing to install or deploy. Getting started means connecting Fortnox to pull SIE files and supporting documents, or uploading them by hand, granting Microsoft 365 access by OAuth so client requests leave from the auditor's own mailbox, and distributing three roles across the firm. There is no public technical documentation and no installation guide, because there is no self-serve route: accounts are opened after a demonstration. The real prerequisite is professional rather than technical.

Deployment

Web app

Integrations

Fortnox Microsoft 365
Company

Behind Audro

Company name
Audro Technologies AB
Founded
INFORMATION_NOT_FOUND
Country of origin
🇸🇪 Sweden
UBO
INFORMATION_NOT_FOUND
UBO country
INFORMATION_NOT_FOUND
Domain registrar country
🇩🇰 Denmark
Official links

Resources

All the official URLs gathered for verification and reference.

FAQ

Frequently asked questions

Does Audro replace the auditor?
No. The agent proposes an audit plan and nothing runs until you approve it, key judgement points pause and wait for your decision, and you can steer the agent or revise the plan mid-engagement. The authorised auditor makes the calls, signs off and keeps the professional responsibility. The vendor states explicitly that Audro is a powerful tool, not an autopilot.
Which accounting frameworks does Audro work with?
Swedish statutory audit, built for the K2 and K3 frameworks, including Swedish VAT and F-skatt controls. Its judgements are anchored in a knowledge base of ISA standards retrieved while the agent works. No other national framework is announced anywhere on the site.
How does accounting data get into the tool?
Through the SIE file and its supporting documents, pulled directly from Fortnox or uploaded manually. Audro parses and structures the data for review with traceability back to the source, then matches transactions to their supporting documents.
Is my data used to train AI models?
No. The vendor states this on the homepage, on its security page and on its trust page. The reusable vector knowledge base holds only public audit standard text and never any client data, and embeddings of your own documents stay in Audro's own database rather than an external vector service.
Where is the data hosted?
In the EU by default: the database, authentication and file storage run in an EU region of Supabase on AWS, and the application and processing services run in an EU region of Railway. A US region is available on request. AI inference runs on Microsoft Azure, and the vendor states that processing may take place in a different geography from where data is stored, covered by the EU Standard Contractual Clauses.
Is a data processing agreement available?
Yes. A DPA is offered to every customer, and the current sub-processor list is published on the Data protection and GDPR page. Audro also undertakes to notify customers before adding or replacing a sub-processor, so that they have the opportunity to object.
Is Audro itself SOC 2 or ISO 27001 certified?
No. The SOC 2 Type II and ISO 27001 certifications named on the site belong to its suppliers, and the vendor states that each certification covers only that supplier's own processing. Audro adds its own internal security reviews of the application and its data flows, but claims no certification of its own.
What does Audro cost?
No price is published. There is no pricing page, no amount, no currency and no billing unit anywhere on the site, and neither a free plan nor a free trial is announced. Commercial terms are obtained by requesting a demonstration.
Is there an API or a mobile application?
No. Audro is a web application reached through a browser at app.audro.se. No API documentation, no public API offer, no iOS application and no Android application were found anywhere on the site.
Conclusion

Should you pick Audro?

Audro is a narrow tool that knows exactly how narrow it is. It targets Swedish statutory audit and nothing else: SIE files, K2 and K3, Swedish VAT and F-skatt, the Swedish business register and a Fortnox connector. Within that scope, the proposition rests on three things a firm can actually check. The auditor stays in command, because the agent proposes a plan and stops at every judgement point. Every conclusion carries its trail, from the finding to the evidence to the standard applied, in an append-only register. And customer data is never used to train models, a claim repeated on three separate pages and backed by a knowledge base that holds public standards text only.

The security and data protection writing is genuinely detailed, and unusually honest about its own limits: the vendor names its eight sub-processors, describes how data flows, states plainly that the SOC 2 and ISO 27001 badges belong to its suppliers rather than to itself, and admits that AI inference may be processed outside the EU because no EU-bounded data zone exists today for the models it uses.

Against that sits a thin commercial surface. There is no published price, no terms of service, no privacy policy, no postal address, no founding date, no API and no team page. The publisher is very young: the domain was registered in late 2025, the site has no web archive history, and the Swedish register shows a single board member and no declared employees. None of that makes the product weak, but it does mean the site alone cannot settle the question. A firm evaluating Audro will have to go through the demonstration and a contractual review, and weigh the supplier risk of entrusting its most sensitive client material to a company this new.