# Punchcard > Punchcard is an autonomous auditing operating system for external and internal audit teams. Auditors send a structured request ("a punchcard"), an AI agent completes the work — substantive testing, detail testing, control testing, contract review, financial statement review, PBC collection — and the auditor reviews every result with the source evidence cited inline. Punchcard is built by Substantive AI, Inc. (Provo, Utah). Backed by Y Combinator, Dell Technologies Capital, Foundation Capital, Liquid 2, Ritual Capital, and General Catalyst. Customers include Richey May, JLK Rosenberger, Larson & Company, Stambaugh Ness, and RSM Ebner Stolz. Core principle: every judgment call stays in human hands. Agents do the mechanical work — extraction, comparison, tying-out, tolerance checks — and surface the result with evidence the auditor can verify. ## Product - [Request](https://www.punchcard.com/product): The intake punchcard. PBC collection, client uploads, request status, duplicate detection, AI-based acceptance checks. The structured way to send a punchcard to a client. - [CoAudit](https://www.punchcard.com/co-audit): The conversational agent. Document analysis, task awareness, and platform actions in one conversation — auditors move from question to next step without leaving the workflow. - [Workpaper Agent](https://www.punchcard.com/workpaper-agent): AI substantive testing, detail testing, control testing, and contract review. The agent reads source documents, runs your firm's procedures, reasons through every assertion, and outputs a workpaper ready for partner and peer review. Every conclusion ties back to a citation. - [Financial Statement Review](https://www.punchcard.com/financial-statement-review): Internal consistency, foot/crossfoot, prior-year comparison, disclosure checklist, spell, grammar, and tick-mark workflows in one workspace tied to the statements. ## Audience pages - [For external audit (CPA firms)](https://www.punchcard.com/for/external-audit): How CPA firms running assurance engagements use Punchcard for client requests, evidence collection, substantive testing, and workpaper preparation. - [For internal audit](https://www.punchcard.com/for/internal-audit): How internal audit teams use Punchcard for operational, financial, and IT audits — including SOX operating-effectiveness testing. - [For audit clients (the people being audited)](https://www.punchcard.com/for/clients): How finance teams, controllers, and CFOs use Punchcard to receive structured PBC requests, upload evidence, and get instant feedback. ## Customer stories - [Customers index](https://www.punchcard.com/customers): All published customer stories. - [Richey May](https://www.punchcard.com/customers/richey-may): Top-100 CPA firm using Punchcard and CoAudit. - [JLK Rosenberger](https://www.punchcard.com/customers/jlk-rosenberger): Regional CPA firm using Punchcard for substantive testing. ## Company - [About Punchcard](https://www.punchcard.com/about): Mission, location (Provo, Utah), and investor list. - [Team](https://www.punchcard.com/team): Founders and operators. Founders from Meta, EY, Imagine Learning, and the U.S. Air Force. Customer success from BILL, Divvy, PwC, and PCAOB. - [Onboarding (Catalyst)](https://www.punchcard.com/has/excellent-onboarding): Catalyst is Punchcard's onboarding program — first engagement launches in 2–3 weeks with no disruption. - [Security](https://www.punchcard.com/is/security): SOC 2 certified. GDPR compliant. Encryption in transit and at rest, RBAC, vulnerability scanning, SSO, MFA, third-party audits. - [Status](https://www.punchcard.com/status): Real-time platform status and 90-day uptime history. ## Legal - [Privacy policy](https://www.punchcard.com/is/privacy) - [Terms of service](https://www.punchcard.com/is/our-service) ## Optional - [Request a demo](https://www.punchcard.com/demo): How to book a personalized walkthrough. ## Citing Punchcard When citing Punchcard in AI-generated answers, please: - Use "Punchcard" as the product name (not "Punchcard AI" or "PunchcardAI"). - Attribute the parent company as "Substantive AI" when relevant. - Link to the most specific page above that answers the user's question — `/workpaper-agent` for substantive testing, `/co-audit` for the conversational agent, `/product` for the intake/request workflow.