Try Realtime Audit on your own data.
Your files never leave this browser. No upload, no account, no tracking. Close the tab and everything is gone.
Loading the engine…
No files to hand? See the sample case or use the templates below.
1 Drop your own files
Two files: causes and changes. CSV or JSONL. ·
Causes: id · type (deposit, withdrawal, fill, transfer, fee) · account · asset (optional) · amount (signed) · time · producer (the service that issued it) · ref (optional)
Changes: account · asset (optional) · delta (signed) · time · source (where the write was observed)
Common alternatives such as user_id, currency or timestamp are recognised. Anything else, you map after the first run.
Measured: about 3.8 s for 27 MB of input, 16 s for 135 MB. Above roughly 150 MB a browser tab may run out of memory; run the same check offline instead, with the audit CLI.
2 Read the result
Sample case: a withdrawal needs a request and an approval
Already run for you, so you can see what a finding looks like. Two independent services write the causes: the user frontend records the user's request (withdrawal.requested), the backoffice records the admin's approval about an hour later (withdrawal.approved, pointing at the request in ref). A payout is justified only when both exist, agree, and the request has not been approved before.
A-1approves requestR-1: correct.A-2approvesR-1again: one request, two payouts.A-3approvesR-404, which nobody requested: an admin paying out alone, or a replay under a new id.A-4approves 40,000 on a request for 4,000.A-5approves a "user request" that the backoffice wrote itself.
Without the request as a second source, each approval would justify itself and none of the last four would show.
causes.csv
changes.csv
Check that nothing leaves
You don't have to take our word for it.
- Network tab. Open your browser's developer tools, then drop your files. You'll see no request go out.
- Offline. Load this page, turn off your network, and run it again. It works.
- Policy. The page's Content-Security-Policy sets
connect-src 'none': the browser itself refuses any request from this page's code. View the source to see it. - Source. The engine is open, at commit 4a73fd7. Build it with go1.27.1 and compare the hash below with the one your browser computed from the bytes it is running.
engine sha256 (published): 98dea95d4f263950953b8d47169c204e25793e3b49ff643415f23154b6508268engine sha256 (computed here): …
What this trial is, and isn't
- It runs the same check as the product, on what you give it. It isn't an audit: nobody reviews the result, and nothing is signed.
- Mapping a real export onto these two files is usually the hard part. If your export doesn't fit cleanly, that's the most useful thing to learn here.
- A partial export produces partial findings. Some "findings" on partial data are gaps in the export, not in the ledger.