Klaai is a double-entry bookkeeping platform where an AI reads the receipts, invoices, and statements and proposes the entries — with a human approving anything ambiguous before it is filed. That design puts customer financial records in front of a model provider, which is exactly the question a SOC 2 auditor and every prospective customer asks first. Type 1 was the way to answer it on the record.
Klaai is a bookkeeping platform built around a simple division of labour: the AI does the reading, the business owner does the deciding. Customers forward receipts, invoices, and bank statements; the model extracts what it needs, drafts balanced double-entry records, and holds anything ambiguous for human review before it is committed to the books.
Underneath that sits a conventional accounting system — a jurisdiction-aware chart of accounts covering VAT, GST/HST, and US sales tax; invoicing with tax applied; receipts and expense categorisation; customer and vendor ledgers; and the standard statement set of balance sheet, trial balance, income statement, and cash flow. It runs from a free single-user tier up to team plans and enterprise, across Canada, the United States, the United Kingdom, and the EU.
Why this is a hard compliance problem: bookkeeping data is not merely confidential, it is the complete financial picture of the customer's business — revenue, payroll-adjacent costs, vendors, and tax position. And a large language model sits inside the processing path, reading documents that were uploaded in confidence. Neither fact disqualifies anything; both have to be described accurately, controlled deliberately, and evidenced.
Klaai's customers include accountants and firms carrying their own client obligations. For that audience, "trust us" is not a procurement answer, and a SOC 2 report is the shortest route to a documented one. The work was to get to a Type 1 without building something that would have to be rebuilt for Type 2.
Iron Fort ran the preparation as the four-stage SOC 2 path the platform is built around — scope and connect, gap and remediate, Type 1 audit, then the Type 2 window — with the evidence accumulating from the first stage rather than the third.
The engagement started by defining what is inside the audited system — application, data stores, cloud infrastructure, and the integrations that move customer documents through it — and connecting that infrastructure so posture is read from the environment rather than described from memory.
Vendor Risk Management tracks the AI provider the way any other subprocessor with access to customer data is tracked: documented purpose, data categories, contractual terms, and review cadence. The point is not to make the AI invisible in the report — it is to make it accounted for.
Policy Authoring & AI Review gave the team an approved starting set mapped to the Trust Services Criteria, with the analyser flagging required elements that were missing or under-specified — considerably faster than drafting a security policy suite from a blank document.
A readiness assessment produced the gap list, and Control Framework Mapping tied each remediation to the criteria it satisfies, so remediation work was prioritised by what the audit actually turns on. Real-Time Control Alerts surfaced drift while the fixes were still fresh.
Evidence — control tests, policy approvals, access reviews, risk decisions — collects continuously into the evidence vault with timestamps, and the Auditor Collaboration Portal gives the audit firm a place to request and receive it directly instead of a chain of email attachments.
Because the same controls keep operating and collecting after the Type 1 opinion is issued, the observation period for Type 2 begins with a system that is already producing evidence, rather than a program restarted for a second audit.
A note on scope: Iron Fort is a compliance management platform. Klaai's customer ledgers stay in Klaai's systems — Iron Fort analyses infrastructure, policies, vendors, and controls, and produces the evidence set the auditor works from.
Klaai went into its Type 1 with a described system, a mapped control set, and an evidence trail that was collected as the work happened.
The audited system defined and documented up front — application, infrastructure, and the integrations that carry customer documents through it.
The model provider inventoried as a subprocessor with its data categories and terms documented, so the hardest diligence question has a written answer.
Control tests, policy approvals, and access reviews collected with timestamps and shared through an auditor portal rather than assembled by hand.
Controls that keep operating after the Type 1 date, so the observation window opens on a live program instead of a restarted one.
Running a compliance program worth writing about? We partner with a small number of customers each year to document the work in depth — and you keep everything we produce.
Cookies on goironfort.com
Essential cookies keep this site working and are always on. With your consent we also load third-party content, such as our review badge, which shares your IP address with that provider. Rejecting keeps everything non-essential switched off. Read our Privacy Policy — you can change your choice any time from the footer.