AuditKey
E2EE Security Vault for OTPs & Messages
Problem: Sensitive communications like OTPs and verification codes are scattered across insecure channels.

What is AuditKey?
AuditKey is an end-to-end encrypted security vault for one-time passwords and verification messages. It syncs OTPs from a phone or a catch-all mailbox into a zero-knowledge web vault, so an audit team can complete client logins without forwarding codes over chat or email. It is built for chartered accountants, IT auditors and security teams that handle credentials on behalf of many clients.
How AuditKey works
- 01
Capture
A background sync on Android or iOS, or a catch-all email address, picks up incoming OTPs and verification codes. Regex filters decide which messages qualify.
- 02
Encrypt
Messages are encrypted on the device with Curve25519 before they leave it. The web vault never holds a key that can read them — zero-knowledge by design.
- 03
Access
Authorised staff open the vault in a browser with role-based access. Mandatory key-rotation and a full retention window keep the trail audit-ready.
Key Features
Built for Chartered Accountants, Security Teams, and IT Auditors
Designed to fit specific workflows and compliance requirements.
Works best with
AuditKey Pricing
Transparent pricing for security-first organizations.
Professional
Standard package for CA/Audit Practices
- 100 Client Entries / Cases
- 10 Professional Access Devices
- 10 Associate / Staff Accounts
- Unlimited OTP & Evidence Sync
- 365 Days Compliance Retention
- Full Platform Features Included
- Priority Support
Capacity Top-up
Scale your practice as you grow
- 25 Additional Client Entries
- Instant Capacity Expansion
- Maintain E2EE Integrity
- No Additional Device Limits
- Valid for Subscription Term
Enterprise
For Large-Scale Audit Requirements
- 500+ Client Entries / Cases
- Unlimited Device Access
- White-labeled Audit Portals
- Dedicated Infrastructure
- Custom Retention Periods
- 24/7 Priority Support
AuditKey — frequently asked questions
Who is AuditKey for?
Chartered accountancy practices, IT auditors and security teams that need to receive client OTPs and verification codes without sharing personal phones or forwarding messages through insecure channels.
Can ABOSS read the OTPs stored in AuditKey?
No. Codes are encrypted end-to-end on the capturing device using Curve25519, and the web vault is zero-knowledge — it stores ciphertext it cannot decrypt.
How does AuditKey collect OTPs?
Two ways: a background SMS sync on the mobile app (Android and iOS) and a catch-all email inbox for codes sent by email. Custom regex filters control which messages are captured.
How much does AuditKey cost?
The Professional package is ₹9,999 per year and covers 100 client entries, 10 devices and 10 staff accounts. Capacity top-ups add 25 client entries for ₹2,000, and an Enterprise tier is available for large audit practices.