Audit Methodology

How the audit works

What data ProofCap pulls, how the plausibility score is computed, what risk vectors mean, and where the model's limits are. No marketing — just mechanics.

The pipeline

  1. 01

    Connect data sources

    The seller grants ProofCap read-only OAuth access to their payment processor (Stripe or Lemon Squeezy) and their Google Analytics 4 property. No write access is ever requested. If live OAuth is unavailable, a CSV upload is accepted — but the report is flagged accordingly (see Data Integrity below).

  2. 02

    Extract independent signals

    ProofCap queries both sources directly, pulling subscription events, payment history, and traffic/engagement metrics for a trailing window. The data is never modified by the seller after connection — it reflects the live account state at audit time.

  3. 03

    Cross-reference and score

    Revenue figures are tested against the traffic and conversion behaviour required to plausibly produce them. Revenue-per-session, EPMV, engagement rate, traffic source distribution, and historical time-series are combined into a 0–100 plausibility score.

  4. 04

    Identify risk vectors

    The pipeline flags specific structural anomalies — each assigned a severity (LOW / MEDIUM / HIGH / CRITICAL) and a plain-language finding. Risk vectors are independent of the score; a high score can still carry a MEDIUM risk vector worth investigating.

  5. 05

    Generate timestamped report

    A shareable, timestamped report is produced. The seller controls who sees it and at what disclosure level. ProofCap retains the audit so the data can be independently compared against a future re-run.

What we extract

Revenue signals

Pulled directly from Stripe or Lemon Squeezy via read-only OAuth — not from exported files the seller controls.

MRR & ARR

Computed from active subscription events — not from the Stripe dashboard summary, which can diverge.

MRR Bridge

New, expansion, contraction, and churned MRR broken out month-by-month for the trailing 12 months.

Churn Rate

Logo and revenue churn from subscription cancellation and downgrade events.

Refund Rate

Total refund volume as a % of gross revenue. Elevated refund rates are an early fraud signal.

Dispute Rate

Chargeback and dispute frequency. Above ~0.5 % of charges is a Stripe risk flag.

Plan Distribution

Revenue concentration by subscription plan — highlights pricing tier risk and lock-in health.

New vs. Expansion MRR

Proportion of MRR growth driven by new logos vs. expansion of existing accounts.

Payment Failure Rate

Failed charges and involuntary churn indicators.

Revenue Time-Series

Month-by-month MRR or payment totals used to plot trend direction and detect manipulation artefacts.

Traffic signals

Pulled from the seller's Google Analytics 4 property via read-only OAuth. ProofCap confirms the tracked domain matches the site being acquired.

Sessions & Pageviews

90-day trailing window from the verified GA4 property.

Bounce & Engagement Rate

High bounce rate or very low engagement relative to reported conversion volume is a plausibility flag.

Acquisition Channels

Session breakdown by channel (Organic, Direct, Paid, Referral, etc.) with per-channel bounce and duration anomaly detection.

New vs. Returning Users

Ratio used to cross-check claimed growth vs. retention narrative.

Avg. Session Duration

Very short median sessions are inconsistent with high-value SaaS conversion claims.

Traffic Time-Series

Session volume plotted over time to identify artificial spikes or suspicious step-changes near the audit window.

Backlink signals

Link profile data sourced from third-party backlink databases. Used as a secondary corroboration signal — not as a primary valuation input.

Total Backlinks

Absolute link count from the referring domain database.

Referring Domains

Unique domain count — a better quality signal than raw link count.

Nofollow Ratio

A very high nofollow ratio can indicate link-farm or low-quality acquisition.

Spam Score

Aggregate spam signal from the link profile. Above ~50 is flagged.

The score

Plausibility Score (0 – 100)

The score is a probabilistic indicator of structural consistency between the revenue and traffic signals. It answers one question: given the observed traffic volume, quality, and channel mix, is the reported revenue figure statistically plausible?

Key inputs: Revenue-per-Session (RPS), Effective Page Monetisation Value (EPMV), engagement rate, bounce rate, acquisition channel anomalies, and temporal consistency across both time-series. The score is weighted toward the signals that are hardest to fabricate independently.

70 – 100

Plausible

Revenue and traffic signals are broadly consistent. Not a guarantee of accuracy — it means no structural anomalies were detected at the cross-reference level.

40 – 69

Needs Investigation

One or more signals are inconsistent at a level worth investigating. Read the risk vectors. Not necessarily fraud — could be data quality, tracking gaps, or business model quirks.

0 – 39

Significant Inconsistencies

Multiple signals contradict each other at a level that warrants serious scrutiny before proceeding. Review each risk vector and consider requesting additional documentation.

Conversion Plausibility Rating

A second label applied independently of the score, based specifically on whether the implied conversion rate is within the range achievable by a real SaaS business of this type:

HIGH

Revenue-per-session and EPMV sit comfortably within normal benchmarks for the observed traffic volume and channel mix.

MEDIUM

Numbers are within range but one or more secondary signals (engagement rate, source mix) add mild uncertainty.

SUSPICIOUS

Revenue-per-session or EPMV is outside typical bounds in a way that requires explanation.

IMPOSSIBLE

The implied conversion rate or monetisation ratio is mathematically implausible given the observed traffic.

Risk vectors

Named anomalies, not just a number

Risk vectors are specific structural anomalies flagged by the pipeline, each with a plain-language finding and a severity level. A report can show a moderate score alongside a CRITICAL risk vector — read both. Severity levels:

// LOW

Noted for completeness. Unlikely to affect valuation meaningfully on its own.

// MEDIUM

Worth asking the seller about. May indicate a data quality issue or a business model nuance.

// HIGH

A signal pattern that has historically correlated with misrepresentation. Investigate before proceeding.

// CRITICAL

Structural contradiction between data sources at a level that should block any decision pending full explanation.

Data integrity

Live API vs. CSV upload

VERIFIED_LIVE_API

Data pulled directly from Stripe or Google Analytics via OAuth. The seller cannot modify what ProofCap sees after granting access. All reports from live connections carry this label.

UNVERIFIED_MANUAL_CSV

Data came from a file the seller uploaded. CSVs can be edited before upload. ProofCap still runs the cross-reference analysis, but every result screen flags this status prominently. Treat CSV-sourced audits with additional scepticism.

Limitations

What the score doesn't tell you

  • 01

    The score is a probabilistic indicator, not a financial audit or legal opinion. It measures structural consistency between connected sources — it cannot detect fraud that is coordinated across all connected systems simultaneously.

  • 02

    ProofCap does not independently verify individual customer identities, invoice correctness, or contract terms. It cross-references aggregate signals only.

  • 03

    CSV upload mode (UNVERIFIED_MANUAL_CSV) is inherently less reliable than live OAuth. Files can be edited before upload. Reports generated from CSVs are labelled accordingly throughout the UI.

  • 04

    Traffic data reflects what Google Analytics reports. If GA4 tracking is misconfigured, missing from parts of the site, or has been recently re-installed, the session figures may undercount or overcount real activity.

  • 05

    Backlink data is sourced from third-party databases and may lag real-time link changes by several weeks.

ProofCap is a probabilistic data-consistency indicator. It is not a financial statement, accounting opinion, or legal verdict, and does not constitute professional financial, legal, tax, or investment advice. Do not rely on a ProofCap report as the sole basis for any acquisition, investment, or financing decision. Consult qualified professional advisors before acting on this information.

See the methodology applied to a real audit

Connect Stripe and Google Analytics — a full forensic report takes minutes.