Security & compliance

The Answers Your Security Team Will Want

Where your data sits, who can reach it, how it is encrypted, and which Indian regulations we build to. If your IT or audit team has a questionnaire, most of what they need is on this page.

What We Comply With

The Indian frameworks that govern how public assets and personal data are handled.

Comptroller and Auditor General

CAG Audit

Records can be added but never quietly changed. Every requisition, transfer, depreciation entry and write-off certificate stays exactly as it was logged.

General Financial Rules

GFR 2017

Produces Form GFR 18 for fixed assets and GFR 22 for consumables, and runs the annual verification round that the rules require.

Govt Accounting Standards Board

GASAB Standards

Straight-line and written-down value depreciation calculated the way central and state reporting requires.

Government Cloud Community

GCC GI Cloud

Runs on government cloud, on a state data centre, or on your own hardware. Each customer's data is kept separate and encrypted.

Digital Personal Data Protection

DPDP Act 2023

Staff names and phone numbers are hidden in reports that leave the organisation, and consent is recorded where the law requires it.

Security Testing

VAPT & CERT-In

Tested every year by CERT-In empanelled auditors who actively try to break in, and we fix what they find.

How it is secured

Four Layers, Explained Plainly

The same controls whether you are a factory, a hospital or a defence installation.

Encrypted Both Ways

Data is encrypted while stored and while moving, using AES-256 and TLS 1.3 to FIPS 140-2 standards.

People See Only Their Own

Permissions can limit a user to their site, department or asset category, and nothing beyond it.

Your Existing Logins

Azure AD, Okta or SAML for companies, Parichay for government, with two-factor on top.

Runs Disconnected

For classified sites, the whole system installs on your own hardware with no route to the internet.