Skip to main content
Security & compliance

Your GST data, secured in India

Built for Indian compliance law from day one. Every rupee of financial data stored on Indian soil, every action logged and auditable.

DPDP Act 2023
Compliant
GST IT-01
Framework
TLS 1.3
In transit
AES-256
At rest
ap-south-1
India region
SOC 2 Type II
Supabase infra

How we protect your data

DPDP Act 2023 compliant

Full compliance with India's Digital Personal Data Protection Act. You own your data. We process it only for the purpose you consented to — GST filing and compliance.

GST IT-01 framework

Our GSP (GST Suvidha Provider) infrastructure meets the GSTN IT-01 security framework — the mandatory baseline for any system that accesses the GSTN portal.

Data never leaves India

All data stored in Supabase's ap-south-1 region (Mumbai, AWS). No cross-border replication. No CDN caching of financial data. Backups encrypted and also within India.

Encryption everywhere

TLS 1.3 in transit. AES-256 at rest. Sensitive fields — GSTIN, PAN, bank details — are additionally encrypted at the column level with separate key management.

Role-based access

Four roles: owner, CA, accountant, viewer. Each scoped to exactly the data they need. Your CA can't edit invoices; a viewer can't approve returns. Zero privilege escalation.

Tamper-proof audit log

Every login, data access, filing action, and export is logged with timestamp, user email, and GSTIN context. Immutable. Downloadable as CSV for statutory audits.

Data residency in India

Every byte of your GST data — invoices, GSTR drafts, ITC reports, company GSTIN records — is stored in Supabase's ap-south-1 (Mumbai) region. We do not use CDN edge caching for financial data. Backups are encrypted and also stored within India.

  • Primary: Supabase ap-south-1 (Mumbai, AWS)
  • Daily encrypted backups, retained 30 days
  • No cross-border data transfer — ever
  • Point-in-time recovery available on request
  • GSTN portal credentials never stored — session-only

Every action, logged

A tamper-proof audit trail records every login, data access, filing action, and export — with timestamp, user email, and GSTIN context. Immutable and downloadable as CSV for your CA or statutory audit.

  • Who accessed which GSTIN and when
  • Every GSTR submission and approval
  • All ITC reconciliation exports
  • System actions (GSTR-2B fetch, reminders)
  • Login events and session details

Your compliance data deserves this

Built for India. Stored in India. Designed for your CA's audit requirements.