Bilateral Verification

Audit Invitations: Verify a Deal Without Platform Access

Request a co-signed revenue verification directly from a seller's inbox — no data room, no negotiating platform access up front. The seller connects their own accounts via read-only OAuth, and the resulting report is shared with both sides as one tamper-evident record.

How it works

From one email to a co-signed report

STEP 01

Buyer sends a request

Enter the seller's email and the target domain from your dashboard. The seller doesn't need a ProofCap account and hasn't granted you anything yet.

STEP 02

Seller gets a secure link

One email with a tokenized link — no account creation, no password. It opens straight to a short verification form scoped to that one request.

STEP 03

Seller connects read-only access

Stripe or Lemon Squeezy for revenue, Google Analytics for traffic — via OAuth, or a manual CSV export if they'd rather not connect live. The seller chooses what to share, and can skip a source entirely.

STEP 04

Both parties get the same report

Once submitted, the forensic pipeline runs and the resulting audit trail is shared with buyer and seller alike — the same numbers, the same risk flags, visible to both sides.

If you're the buyer

Request the audit, not the access

  • No data room to negotiate, no waiting on a seller to “prepare an export.”
  • The seller authorizes their own accounts directly — you never handle their credentials.
  • Same plausibility score and risk-vector breakdown as a self-run audit, verified independently by the seller's own OAuth grant.
  • Available on the Portfolio plan for buyers and brokers running multiple deals.
Send your first invitation

If you're the seller

A buyer asked you to connect an account — here's what that means

  • Read-only, always — ProofCap never requests refund, payout, or account-modification permissions.
  • You choose the source: live OAuth for the strongest verification, or a CSV export if you'd rather not connect an account.
  • You can skip a data source entirely if you're not ready to share it yet.
  • Access can be revoked at any time from your connected integrations.
  • You're not handing data over blind — you receive the identical audit trail the buyer sees.
Read our security practices

What gets verified

The same forensic pipeline, source-connected

Revenue

MRR, refund rate, and payment health pulled directly from the seller's live Stripe or Lemon Squeezy ledger — not a CSV they prepared themselves.

Traffic

Google Analytics session and engagement data cross-referenced against reported revenue to catch numbers that don't add up.

See the full scoring model on the methodology page.

Questions

Audit invitations, clarified

Does the seller need a ProofCap account?

No. The emailed link is enough to complete the request — no signup, no password.

What if the seller doesn't respond?

Invitation links expire after 7 days. The buyer can send a new one at any time.

Who can send an audit invitation?

Buyers and brokers on the Portfolio plan. This keeps the feature scoped to serious, active due-diligence workflows rather than open to anyone.

Is a “co-signed” report a legal signature?

No — it's a verified data record, not a contract. “Co-signed” means both parties end up holding the identical, tamper-evident audit trail, not that either side has signed a legal agreement.

Can the seller share only some data sources?

Yes. Payment and analytics connections are each optional and independent — a seller can connect Stripe but skip GA4, or vice versa, or skip both and rely on manual CSV exports.

What does the seller actually see before connecting anything?

The target domain, who requested the audit, and when — before any OAuth consent screen is shown. Nothing is shared until the seller explicitly authorizes it.

Ready to request your first audit invitation?

Available on the Portfolio plan. Free Footprint scans require no invitation and no credit card.