Licensed, adapted, and deployed on the firm’s own stack.
AuditSenior is ITGC testing software that an audit firm licenses from Bonfleur, not a hosted service it subscribes to.
The software is demonstrated on synthetic data. Nothing on this site is an offer, no prices appear, and the platform issues no audit opinion, assurance or attestation; the full notice is on the legal page.
What a firm licenses, and what stays with the firm
Licensed
- Software
- The application, with its control library, its automated tests and its database migrations.
- Customization
- Adapting the software to the firm's requirements and to the stack the firm runs.
- Deployment
- Deploying the adapted software onto that stack.
- Maintenance
- Maintenance of the licensed software, delivered as the license agreement sets out.
Stays with the firm
- Operation
- Operating the deployed software, including incident response.
- Audit data
- The firm's audit data. The software sends none of it to Bonfleur.
- Providers
- The accounts with the providers its deployment uses, with their credentials and terms.
- Infrastructure
- The hosting and encryption configuration of the infrastructure the firm deploys on.
- Retention
- The firm's retention policy for its own records.
The reference build runs on the components listed under showcase components on the legal page. Adapting those components to the firm’s own stack is scoped against that stack, as part of customization.
Source escrow and ownership
A source-escrow bundle is built only from a clean commit, and its manifest names that commit. It carries the application with its tests and migrations, synthetic ITGC fixtures, documentation, the CI workflow, the lockfiles, and the rights notice and contribution terms. A scope document classifies every top-level path of the repository as shipped or withheld, and tests fail when a path has not been classified or when the bundle script ships a different list.
| RIGHTS | Bonfleur s.r.o. is the rights holder of the software, including its control library and documentation. Third-party components remain under their own licenses. |
|---|---|
| ACCESS | Access to the source conveys no license. A license exists only under a separate written agreement, negotiated outside this site. |
| ASSIGN | Contributions are accepted only under a signed agreement assigning their intellectual property to Bonfleur s.r.o. |
How the build is checked
- Checks
Checked in continuous integration
On pushes to the main branch and pull requests into it, CI runs the type check, the unit test suite and the production build. The method behind the build is set out on Developments.
- Dependencies
A high-severity advisory fails the CI run
The same run audits the application's production dependency tree at the high and critical levels. The lockfiles ship with the source.
- Services
A preflight for four hosted services
A script checks identity, object storage, the coordination store and model access with the credentials a deployment is configured with, and reports a service with no credentials as skipped, not passed.
How an evaluation proceeds
Read how the file is produced and what it records
The platform page describes the workflow and the file it produces; the assurance page, what that file records about what happened to it.
A demonstration account
By invitation, in one demonstration tenant shared by evaluators, isolated from other tenants and seeded with a fictional engagement. It may be used only with synthetic data, under the demonstration-accounts clause of the privacy notice on the legal page; access may be limited or withdrawn at any time.
The specimen binder, when available
Its current status is on the platform page, and its terms are the specimen terms on the legal page.
A licensing conversation
About the firm's requirements and its stack; a license exists only as § 02 describes.
Customization, deployment and maintenance
As set out in § 01.
A licensing question?
Write with a question about what a firm licenses, source escrow or an evaluation.