Built for Indian compliance law from day one. Every rupee of financial data stored on Indian soil, every action logged and auditable.
Full compliance with India's Digital Personal Data Protection Act. You own your data. We process it only for the purpose you consented to — GST filing and compliance.
Our GSP (GST Suvidha Provider) infrastructure meets the GSTN IT-01 security framework — the mandatory baseline for any system that accesses the GSTN portal.
All data stored in Supabase's ap-south-1 region (Mumbai, AWS). No cross-border replication. No CDN caching of financial data. Backups encrypted and also within India.
TLS 1.3 in transit. AES-256 at rest. Sensitive fields — GSTIN, PAN, bank details — are additionally encrypted at the column level with separate key management.
Four roles: owner, CA, accountant, viewer. Each scoped to exactly the data they need. Your CA can't edit invoices; a viewer can't approve returns. Zero privilege escalation.
Every login, data access, filing action, and export is logged with timestamp, user email, and GSTIN context. Immutable. Downloadable as CSV for statutory audits.
Every byte of your GST data — invoices, GSTR drafts, ITC reports, company GSTIN records — is stored in Supabase's ap-south-1 (Mumbai) region. We do not use CDN edge caching for financial data. Backups are encrypted and also stored within India.
A tamper-proof audit trail records every login, data access, filing action, and export — with timestamp, user email, and GSTIN context. Immutable and downloadable as CSV for your CA or statutory audit.
Built for India. Stored in India. Designed for your CA's audit requirements.