FAQ

Frequently asked questions

If your question isn't answered here, email info@cloudsquid.io.

The lookback audit

What it reviews, what we need, and what you receive.

What is a lookback audit?

A lookback audit is a read-only forensic review of the previous 12–24 months of finance transactions, checked against the relevant source documents.

Agents review the full scoped population rather than a sample: invoice PDFs against delivery notes, deductions against promotion agreements, and freight bills against rate cards. The output is a findings report showing what leaked, where it happened, why it happened, and what is recoverable. Every finding includes its supporting evidence. This is the first stage of our work: Audit, Recover, Prevent.

Link to this answer
What do we need to send you?

For most audits, we need finance exports and the source documents available to your team.

That usually includes the AP ledger, vendor master, payment runs, open and written-off deductions, freight invoices, and documents such as invoice PDFs, supplier statements, contracts, and rate cards. The audit does not require an ERP integration or an IT implementation. If the data can be exported, we can scope the audit.

Link to this answer
How long does the audit take?

First findings usually appear within a few days after the data is loaded.

In one cloudsquid customer deployment, agents audited 100% of a year's AP transactions in under two hours. That is processing time for a specific customer scope, not a promise for every end-to-end audit; data preparation and validation affect the overall timing.

Link to this answer
What if you don't find anything?

If the audit finds no recoverable leakage, you receive that result in writing.

Worst case, everything is fine, and the audit has documented it. Clean results are less common than many teams expect: AP leakage benchmarks run at 0.3–0.7% of spend (SSON/Xelix analysis of 481M invoices, 2026), while 20–30% of customer deductions are written off without dispute (ProcIndex, 2026). For a broader view, see where cash leakage appears across finance processes.

Link to this answer
Is the audit safe? Will it touch our ERP?

No. The audit is read-only and runs from exports in an isolated workspace.

It does not connect to production, write back, post, pay, or change records in your systems. Data is hosted in the EU and encrypted in transit and at rest. A zero-retention option is available.

Link to this answer
We already use a recovery audit firm. Why this?

Traditional recovery audit firms are a good fit for a one-off, low-involvement review, especially where specialist claims expertise matters.

Their human review model usually samples high-value vendors and transactions. Agents can instead review the full scoped population at line-item level, against source documents, and return first findings within days. The same checks can continue before future payment runs, so the work can move from recovery into prevention. See how cloudsquid compares with recovery audit firms, including when to choose one.

Link to this answer

Control and accuracy

How decisions, evidence, approvals, and process changes work.

What happens when the agent is not sure?

It stops, flags the case, and lists the plausible candidates instead of guessing.

The case reaches your review queue with the evidence arranged for inspection: what matched, what did not, and what information would resolve it. A flagged case means the control is working as designed.

Link to this answer
Do we keep control over what gets posted or paid?

Yes. Nothing posts, pays, or leaves cloudsquid without the required approval.

Critical actions sit behind approval gates that you configure. As confidence develops, routine sign-offs can be delegated to an approval agent that checks each case against the approved process definition. Agents investigate and prepare the case; your finance team controls the decision.

Link to this answer
Is there an audit trail?

Yes. Every case records its source data, actions, reasoning, edits, and approvals.

Reviewers see the source document beside the agent's work, and every finding includes its evidence. The record remains available when internal or external auditors ask how a conclusion was reached.

Link to this answer
How accurate is it, and does it get better?

Accuracy is enforced through evidence per finding, flag-don't-guess behavior, and human approval for critical actions.

When a review exposes a gap, the agent reads the comments and approval outcome and proposes an update to the process definition as a reviewable change. Your process expert approves it, so there is no silent drift. At REPA Group, a cloudsquid customer, agents work 262 orders a week in production and 62% are fully zero-touch. Every case remains reviewable down to its evidence.

Link to this answer
How does the agent learn our process?

Your process expert teaches it through a written standard operating procedure.

The agent drafts a plain-Markdown process definition from real data and identifies the questions it cannot resolve alone. Your expert corrects the document, which is versioned and approval-stamped, and the agent follows the approved version. Changing the process means reviewing a written change, not rebuilding a workflow in code.

Link to this answer
Does cloudsquid replace our ERP or existing systems?

No. Your ERP remains the system of record.

cloudsquid works alongside it, reads evidence the ERP does not contain, and returns reviewed results through the approvals you define. It is a control and investigation layer, not an ERP replacement.

Link to this answer
Does my team need to be technical?

No. Process instructions are written in plain language and can be written in any language.

Your process experts remain the authors of the operating rules. They do not need to write code to change how the process runs.

Link to this answer

Security and compliance

Data handling, access, hosting, and control status.

Is our data used to train AI models?

No. Customer data is never used to train our models or third-party models.

Link to this answer
What certifications does cloudsquid hold?

cloudsquid is ISO 27001:2022 certified and GDPR compliant.

Our controls are SOC 2-aligned; we have not yet completed a SOC 2 audit and will not claim that status before the audit is complete. Supporting documentation is available in the Trust Center.

Link to this answer
Where does our data live?

Data is hosted in the EU and encrypted in transit and at rest.

A zero-retention mode is available, and self-hosted deployment is possible where requirements demand it.

Link to this answer
Who and what can access our data?

Users and agents receive project-specific roles and permissions.

Roles include Reader, Reviewer, and Project Admin, with granular rights within each project. Agents can read only the tables they are explicitly granted; they do not receive superuser access.

Link to this answer

Getting live and commercials

Timing, IT involvement, pricing, ROI, and fit.

How long does it take to go live?

The audit returns first findings within days, while a continuous prevention process usually goes live in about two weeks.

REPA Group moved from kickoff to live order processing in two weeks in a cloudsquid customer deployment. The exact timing depends on scope, data access, and the approvals required by your organization.

Link to this answer
What does our IT team need to do?

For the audit, IT usually approves a read-only data export.

For continuous prevention, the team completes an access and security review, then approves integrations as they are added. Access-controlled tokens and workflow triggers avoid a middleware implementation. Technical details are available in the documentation.

Link to this answer
How does pricing work?

Pricing is scoped around the process and transaction volume, with the audit providing evidence from your own data before you expand into continuous controls.

From there, pricing is per process placed under continuous control. The initial scope is designed to demonstrate its return before a broader commitment.

Link to this answer
How do we measure ROI?

ROI starts with recovered cash: duplicates reclaimed, credits applied, and deductions disputed before their windows close.

Prevented leakage and time returned to the team come next. In cloudsquid customer results, AP monitoring at a US beverage manufacturer surfaced a $50K duplicate invoice, while a construction wholesaler's first audit surfaced $730K in errors and reduced manual reconciliation effort by 90%. The audit report quantifies the opportunity before you decide on continuous prevention.

Link to this answer
Who is cloudsquid for, and who is it not for?

cloudsquid is for CFOs, controllers, finance operations, and shared-services leaders at mid-to-large manufacturers, consumer-goods companies, retailers, distributors, and other audit-heavy organizations.

It is not designed for teams seeking unsupervised autonomy or an ERP replacement. Critical actions retain named approvers, and the ERP remains the system of record.

Link to this answer
How do we get started?

Start with a lookback audit of one real process and 12–24 months of exports.

We return findings with evidence attached, along with the recoverable amount and the process conditions that caused it. If the audit finds nothing recoverable, you receive that result in writing.

Link to this answer

Start with your own transaction history

A read-only lookback audit shows what is recoverable and attaches the evidence your team needs to act.