Data Security

Last updated: July 2026

This document is being finalised with our legal counsel. The summary below explains our intent; the binding version will be published here before launch. Questions? Contact us.

Encryption everywhere

All traffic is encrypted in transit with TLS 1.2+. Data at rest is encrypted with AES-256, and sensitive identifiers such as PAN and Aadhaar are additionally encrypted at the field level — so even a database dump reveals nothing readable.

Isolation & access

Every firm's data is fully isolated through row-level security, and access inside a firm is controlled by role (admin, staff, client). Clients only ever see their own documents.

Documents

Files are stored in private buckets and served only through short-lived, signed links — never public URLs.

Backups & residency

Data is backed up daily with 30-day retention and stored in Indian data centres.

Report an issue

Found a security concern? Please let us know — we take every report seriously.