Auxilius
Auxilius is a German enterprise platform where AI agents write and maintain deterministic control code, letting internal audit, internal controls and risk teams run hundreds of continuous, full-population checks without ever writing a line themselves.
What is Auxilius?
Auxilius is a continuous assurance platform for governance, risk and compliance, driven by AI agents and built by the German company Auxilius.ai GmbH for internal audit, internal controls and business risk functions. The site offers three doors into it, For Internal Audit, For Internal Controls and For Business, but they describe one product seen from three angles.
The premise is a familiar constraint: risk coverage has always been capped by how much testing an audit team can physically perform by hand. Automating one isolated assurance task is easy; doing it for hundreds of controls, tested continuously, is what Auxilius says has become possible. Its agents write and maintain the code behind each control, adapt it to every process, edge case and local entity, and update it whenever a rule moves. The intended operator is deliberately non-technical: the headline claim is that a non-technical auditor operates thousands of continuous controls, without writing code.
Three arguments repeat on every page. Controls are anchored to company objectives rather than to a checklist. The code is the evidence, with agents producing deterministic scripts that are re-runnable, version-controlled and defensible, and an explicit claim of no black box. And change is absorbed by the machine, the site promising hundreds of controls updated in hours rather than months when a threshold, process or regulation shifts.
What comes out is framed as continuous decision support rather than a dashboard to interpret. Every run generates a full chain from objective to decision, risk, control and evidence, straight from the data. On the Internal Controls page, failures surface as they happen rather than at period close, and coverage and the preventive/detective balance are assessed. On the Business page, controls execute inside the process instead of alongside it, so decision support becomes a by-product of controls that already run. Audit, the company insists, stays independent while the evidence is produced.
The product itself is a web application behind an authenticated login, with a sample audit report embedded on the home page. There is no public API, no mobile app and no self-service sign-up. Auxilius came out of the ABN AMRO and Techstars Future of Finance accelerator and says it is already running with its first enterprise customers in regulated industries.
What it does
- Assess risks and controls against the company objectives they are meant to protect
- Generate and maintain the deterministic code behind every control, per process, edge case and local entity
- Run controls continuously across the full population instead of testing periodic samples
- Surface qualitative and quantitative risk impact, with root cause, at the moment of decision
- Refactor, retest and redeploy controls whenever a rule, threshold or regulation changes
- Produce, for every run, a complete chain from objective to decision, risk, control and evidence
- Weigh the balance between preventive and detective controls and assess overall coverage
When to use Auxilius / When not to
A quick filter to help you decide if Auxilius is the right fit.
When to use Auxilius
- Internal audit functions in regulated enterprises that must cover hundreds of controls with a fixed headcount
- Internal controls teams that want continuous controls monitoring instead of periodic sample testing
- Non-technical auditors who need heavy automation but will never write or maintain code themselves
- Multi-entity, multi-country groups where every local subsidiary runs its own variant of the same process
- Risk and compliance leaders who need defensible, re-runnable evidence rather than a dashboard to interpret
When not to use Auxilius
- Small businesses and independents: the product is positioned exclusively for large regulated enterprises
- Buyers who want to sign up, test and pay online, since there is no self-service, no free plan and no trial
- Teams that need a published price before they can open a budget line
- Developers looking for a public API, mobile apps or documented third-party integrations, none of which exist
- Procurement functions that require a SOC 2 or ISO 27001 certificate up front, as Auxilius publishes only a management ISMS commitment
How to use Auxilius
A typical end-to-end flow, from setup to results.
- Start from the fact that nothing is self-service: the site publishes no price, no trial and no sign-up button
- Pick your angle on the site, For Internal Audit, For Internal Controls or For Business, to see how the product is framed for your function
- Open the example audit report embedded on the home page to judge the format of the output
- Fill in the “Interested, but want to learn more first?” form with your name, business email, area of interest (Internal Audit, Internal Controls, Business and Operational Risk, or Something else) and an optional message
- Or book the 30-minute “See it on your data” slot through the Calendly link; the site promises follow-up with relevant information and no obligation to meet
- Work through scoping, contracting and the connection to your source systems directly with Auxilius, since no installation or getting-started guide is published
- Once live, sign in through the dedicated customer login on the reports section of the site
- Describe the control you need; the agents write the deterministic script, test it and deploy it, so you never write code yourself
- Let the controls run continuously across the full population and review failures as they surface rather than at period close
- Read the generated audit reports, each carrying the chain from objective to decision, risk, control and evidence
Pros & Cons
Pros
- Evidence is auditable by construction: deterministic, version-controlled, re-runnable scripts, with an explicit no-black-box claim
- Continuous, full-population coverage replaces sample-based testing
- Meant to be operated by a non-technical profile, a claim repeated on all three positioning pages
- Control maintenance is automated against regulatory change and country-by-country variation
- Audit keeps its independence while the evidence is being produced
- EU-based publisher working under the GDPR and the German BDSG, with a named supervisory authority
- Credible founders for the field, a CEO who was an EY Equity Partner with 15 years in GRC and a CTO from Sopra Steria CSS, backed by ABN AMRO/Techstars and funded by HTGF
Cons
- No public pricing whatsoever: no amount, no plan, no range
- No terms and conditions online, so contractual commitments cannot be reviewed before contacting sales
- The privacy policy explicitly covers the website only; nothing public describes how the platform handles customer data
- No security certification on display, neither SOC 2 nor ISO 27001; the ISMS page is a management commitment, not a certificate
- No product subprocessor list, and nothing published about model training or any opt-out
- No public API, no mobile app, no named third-party integration, and no product documentation, case study or named customer
- Very young company with a small team, a single generic info@ address and no dedicated support channel
Pricing & Plans
No price is published. Auxilius displays no amount, no currency and no billing unit anywhere on its website, and an exhaustive reading of the sitemap confirms that no pricing page exists at all. Neither a free plan nor a free trial is mentioned. The only way to obtain a figure is to approach the company commercially, through the enquiry form carried on each positioning page or a 30-minute appointment booked from the site. Pricing is therefore available on request only, in line with the enterprise positioning and the regulated-industry customer base.
Data, GDPR & hosting
A consolidated view of how Auxilius handles your data.
GDPR overview
GDPR implementation is documented and concrete. Auxilius.ai GmbH, Beta-Str. 10a, 85774 Unterföhring, Germany, is the controller, represented by managing directors Christian Hoppe and James Barnes; data protection enquiries go to Christian Hoppe at info@auxilius.ai. The policy, effective 2 June 2026, cites the GDPR together with the German BDSG, names an Art. 6 legal basis for each purpose, and lists the rights of access, rectification, erasure, restriction, portability, objection and withdrawal of consent. The competent supervisory authority is named: the Bayerisches Landesamt für Datenschutzaufsicht in Ansbach. Transfers outside the EEA rely on an adequacy decision or EU Standard Contractual Clauses, with safeguard details available on request. Auxilius states it is not required to appoint a data protection officer under Art. 37 GDPR / §38 BDSG. No Art. 27 representative applies, the publisher being established in the EU.
Who owns the data?
Auxilius publishes no terms and conditions, so no clause states who owns customer data. The privacy policy is explicit that it applies to the website only, and that use of the Auxilius platform by customers is governed by separate contractual agreements that are not public. For website and applicant data, Auxilius.ai GmbH acts as controller, states that it does not sell personal data and does not use it for automated decision-making within the meaning of Art. 22 GDPR, and limits internal access to staff who need it. The product claim that scripts are deterministic, version-controlled and re-runnable concerns the quality of the evidence, not the ownership of it.
Reuse rights
No terms and conditions are published, so nothing states whether a customer may reuse the platform's output freely, and the privacy policy covers the website alone. What is documented is the website side. Server logs (IP address, date and time, browser, operating system, referrer) rest on legitimate interest, Art. 6(1)(f). Contact and demo requests, covering name, business email, company, role and message content, rely on Art. 6(1)(b) and (f). Newsletter sign-ups use double opt-in consent under Art. 6(1)(a), through Sender.net acting under an Art. 28 agreement. Job applications (CV, contact details, qualifications, correspondence) rest on Art. 6(1)(b) and §26 BDSG, handled on the JOIN Solutions AG platform. Analytics use Ploy's native tools and only run after consent given through the cookie banner, under Art. 6(1)(a) and §25 TDDDG. Recipients are Auxilius's own processors under Art. 28 agreements covering hosting, email, newsletter and recruitment, plus professional advisers and authorities. Nothing at all is published about what the platform does with customer data.
Data retention & training
Hosting summary
Auxilius publishes hosting information for its website only. The privacy policy states that it processes data primarily within the EU/EEA, and that where a service provider processes personal data outside the EEA an adequate level of protection is ensured through an EU adequacy decision or EU Standard Contractual Clauses, with details of those safeguards available on request from info@auxilius.ai. The website itself is hosted by Ploy, Inc. No hosting country is named and no data centre is identified: the declaration stops at the EU/EEA region. That policy also states that it applies to the website alone, so nothing is published about where customer data processed by the Auxilius platform is hosted, a point left to the separate customer contracts. The domain is served behind Cloudflare on an anycast address, which reflects CDN routing and says nothing about where data actually sits. Treat “EU/EEA” as a website-level statement and obtain a written hosting commitment for the platform during due diligence.
Things to keep in mind
Risks and trade-offs to weigh before adopting Auxilius.
- The privacy policy explicitly covers the website only; how the platform processes your business data is governed by contracts that are not public, so get that in writing before sharing anything sensitive
- No security certification: the ISMS page is a management declaration signed by the CEO and CTO, not a SOC 2 or ISO 27001 audit
- No terms and conditions are published, so liability, data ownership and exit terms cannot be checked before the sales conversation
- No product subprocessor list, and nothing at all published about model training or an opt-out; assume nothing on either point
- Automating hundreds of controls can quietly dull professional scepticism: a wall of green results is still machine output, and someone has to keep reading the code the agents write
- Ultimate beneficial ownership is not publicly verifiable, since the German commercial register publishes no shareholder list and the Transparenzregister has been closed to the public since the 2022 CJEU ruling
- The publisher is very young, founded at the end of 2025 and pre-seed funded with a handful of engineers, so check viability and references before a long commitment; note also an unrelated German namesake, Auxilius Services GmbH (auxilius.de)
Setup & Integrations
Technical difficulty
Day-to-day use is meant to be easy: the target user is explicitly non-technical and writes no code, since the agents produce, adapt and maintain the control scripts. Initial set-up is another matter. No installation or configuration procedure is published and no third-party integration is named, so the way the tool connects to source systems is undocumented. Plugging it into company data, as the “See it on your data” pitch implies, means IT involvement and a proper scoping of the control set. There is no self-service path: onboarding necessarily runs through the vendor.
Deployment
Behind Auxilius
Fundraising
Social
Resources
All the official URLs gathered for verification and reference.
Frequently asked questions
What does Auxilius actually do?
Who is Auxilius for?
Do I need to know how to code to use it?
How much does Auxilius cost?
Is there a free plan or a free trial?
How is the audit evidence produced?
What happens when a rule or a regulation changes?
Is Auxilius SOC 2 or ISO 27001 certified?
Is there an API or a mobile app?
Who is behind Auxilius, and is the company funded?
Should you pick Auxilius?
Auxilius arrives with an unusually clear proposition. Instead of another dashboard, it offers controls as deterministic code, written and maintained by AI agents, re-runnable and version-controlled, with an explicit refusal of the black box. For an internal audit or internal controls function that has spent years rationing coverage against available headcount, the promise of full-population testing, continuous execution and hundreds of controls updated in hours when a regulation moves addresses the real constraint rather than decorating it. The founding team is credible on that terrain: a former EY Equity Partner with fifteen years in GRC alongside a CTO from Sopra Steria, backed by the ABN AMRO and Techstars accelerator and by a pre-seed round led by HTGF.
The reservations are just as clear, and every one of them is about what is not published. There is no price, no plan, no range. There are no terms and conditions, so contractual commitments cannot be read before a sales conversation. There is no product documentation, no named customer and no case study. On security, the ISMS page is a signed management commitment rather than a SOC 2 or ISO 27001 certificate, no product subprocessor list exists, nothing is said about model training or an opt-out, and the privacy policy states plainly that it covers the website alone, leaving the handling of customer data on the platform to contracts that are not public.
Maturity matters too: the company was founded at the end of 2025, employs a handful of engineers and describes first enterprise customers rather than a reference base. Auxilius is worth evaluating by an audit function ready to run its own due diligence directly with the vendor, and able to obtain in writing everything the website does not say.
- Choosing a selection results in a full page refresh.
- Opens in a new window.