Skip to content
Security

A product whose whole claim is provable records has to be provable about itself.

If we ask you to trust a compliance position, the least we owe you is a plain statement of how the data is held, who can reach it, what is already in place and what is not yet. The last part is the one most security pages leave out.

Data residency
India, for financial and legal records
Audit log
Append-only, no disable path
Certifications
None claimed today; status stated below
Four commitments

How the record is protected.

Isolation between entities and clients

Each client's data is logically separated, and within a client each entity is a boundary of its own. A user granted access to one subsidiary cannot read another, and consolidated views are assembled only for roles explicitly given group scope.

  • Entity-level segregation enforced at the data layer, not in the interface
  • Group-scope access granted deliberately and recorded when granted
  • Backups carry the same separation as live data

Encryption in transit and at rest

Traffic is TLS-encrypted end to end. Stored data and backups are encrypted at rest, and documents attached as evidence are held in encrypted object storage with access mediated by the application rather than by direct links.

  • TLS for all client and integration traffic
  • Encryption at rest for databases, backups and document storage
  • No publicly addressable document URLs; access is checked per request

Role-based access across every module

Permissions are defined by role, entity and period. Maker and checker are distinct, authority limits are versioned, and a period that is locked is read-only for everyone including administrators until a reopening is approved and logged.

  • Separation of duties between preparer, approver and filer
  • Time-bound, scoped access for auditors and consultants
  • Privileged actions require a reason that is written to the log

An audit trail that cannot be edited

The edit log is append-only. There is no administrative interface to modify or purge it, no bulk-edit path and no configuration switch to disable it - which is what the audit-trail requirement under the Companies (Accounts) Rules actually asks for.

  • Append-only log with user, timestamp and before and after values
  • Log retained for the statutory retention period with legal hold support
  • Export of the log available to your auditor in a readable form
Compliance posture

Stated as three lists, because that is the only honest way to state it.

Security pages tend to blur what exists with what is planned. These are separated deliberately, and the third list is not an omission.

In place today
  • TLS in transit and encryption at rest for data, backups and documents
  • Logical isolation per client and per entity, including in backups
  • Role-based access control with maker-checker separation and versioned authority limits
  • Append-only audit log with no disable or purge path
  • Daily encrypted backups with restore testing on a defined cycle
  • Least-privilege internal access, with production access requiring a recorded reason
  • Data residency in India for client financial and legal records
  • Documented incident response with defined notification paths to affected clients
In progress
  • Independent third-party penetration testing on a scheduled cadence
  • Formal ISMS documentation ahead of an external certification assessment
  • Customer-managed encryption keys for Enterprise deployments
Not claimed
  • We hold no completed ISO 27001 or SOC 2 report today, and we will not imply one
  • No on-premise deployment option at present
  • No claim that the product prevents fraud; it makes fraud harder to conceal and easier to trace
Data handling

What we hold, for how long, and how it leaves.

Your books are your statutory obligation. Our job is to hold them in a way that never gets in the way of you meeting it.

What we hold

Accounting records, tax and filing data, contract documents, statutory registers and the evidence attached to entries. Payroll data includes personal information about your employees, held under your instruction as the controller of that data.

How long it is kept

For the statutory retention period applicable to books of account, with legal hold where an assessment, appeal or litigation is open. Deletion requests are honoured for anything outside a retention obligation, and the record of deletion is itself retained.

How it leaves

On request or on exit, as a complete export: masters, transactions, the edit log, and documents in original formats with an index linking each to its entry - structured to stay usable after the subscription ends.

Who can see it

Your users, by role. Our engineers only where support requires it, with a recorded reason and time-bound access. Sub-processors are limited to infrastructure and are listed on request before onboarding.

Security review

Send your security questionnaire before you send your data.

We would rather answer a diligence questionnaire early and tell you where the answer is no. If a control your policy requires is not in place yet, you will hear that in the first conversation rather than during onboarding.

  • Sub-processor list shared before onboarding
  • Access model walked through with your IT or risk owner
  • Audit log export demonstrated to your auditor on request