Security

We hold books of account. What follows is what the product does today, not what it aims to do.

Credentials are sealed, not stored

The keys that reach a customer accounting system or payment gateway are encrypted with AES-256-GCM before they are written down, under a key the application holds and the database never sees. Nothing that opens a third party account is readable in a database row.

A password for a locked bank statement is treated the same way, with ten minutes of life sealed inside it. It is taken off the record before the file is opened, and it never reaches the job history or the message log.

Who can see what

A person holds a role in one company, and a role is a set of named permissions that the company itself writes. Reaching a customer, paying a bill, posting a journal and handing a third party access to the books are separate permissions, because somebody trusted to draft an invoice is not automatically trusted to send it or to refund it.

The address bar is a request, never a permission: membership is checked on the server for every call. A company somebody is not a member of answers as not found rather than as not allowed, because saying it exists is itself something a stranger should not learn.

When somebody on our side has to act inside an account to help, a reason is typed first, the session lasts thirty minutes, a banner is visible the whole time, it is read only unless writing is separately permitted, and every action records both the staff member and the person they acted for.

Every change is recorded, and the record cannot be edited

Each change writes an audit row in the same database transaction as the change itself, so the two cannot come apart: if the record fails, the change fails with it. The rows are add only, each one carries a hash of the row before it, and a job recomputes the whole chain every night and names the first row that does not verify. They are kept for eight years, which is how long books of account must be kept in India.

Where a model did the work, the row names the model, the prompt it was given, and the person who confirmed it. A bill read from a photograph is a draft until somebody checks what was read, and the trail says who that was. For a product that takes instructions in a chat, a record saying only that the user did it is not good enough.

What never reaches a log

Tokens, passwords, whole bank account numbers and whole GSTINs are never written to a log. When somebody sends a statement password over WhatsApp, the message is recorded without its words, so the password is not in the message history either.

Links we send to people outside the business

A data room link carries its token after the hash, which a browser never sends to a server, and the page posts it in the body of a request instead. The token therefore stays out of our access logs, out of anything sitting in between, and out of the address of the next page the viewer opens. A link can be limited to certain items, set to work once, given an expiry, and withdrawn. Every time one is opened, and everything read through it, is recorded for the company that sent it.

A link that was withdrawn and a link that never existed answer with exactly the same sentence, because telling them apart would turn a guessed link into a way of finding out that a real one exists. A link that has run out of time says so instead, since its holder was given it by the company in the first place.

A link sent over WhatsApp opens a page and asks the person to sign in as they do everywhere else. It never carries a session: a message is forwarded, screenshotted and backed up, and a link that signed in whoever held it would be a key handed to everybody who saw it.

Connected accounting systems and gateways

Zoho Books, QuickBooks Online and Razorpay are connected by the customer authorising it at the provider, and what comes back is sealed before it is stored. The customer can disconnect, and can revoke our access at the provider, without asking us.

For a company whose accounts we keep ourselves, the ledger runs on a private network and is not reachable from the internet at all. Nothing in the product talks to it except through one interface, which is what makes a change to it a single, reviewable thing.

Where the product is run

Copy owed. Nothing here is written yet.

  • Who hosts it, in which region, and whether the database and backups stay in India.
  • Who on our side can reach production, and what they have to do first.
  • Whether the database is encrypted at rest by the platform, which is a hosting fact rather than a code one.
  • Backups: how often, kept how long, and the date a restore was last tested.

When something goes wrong

Copy owed. Nothing here is written yet.

  • What we commit to: who is told, how soon, and what the notice contains.
  • Whether that commitment is repeated in the data processing agreement, and in the same words.

Reporting a hole

If you have found something, we want to hear about it before anybody else does.

Copy owed. Nothing here is written yet.

  • The address to report to, and whether it accepts encrypted mail.
  • How quickly we answer, and how quickly we fix.
  • Whether we promise not to pursue somebody who reports in good faith, and what is out of bounds.

What we do not claim

We hold no security certification, and this page claims none. Everything above is a description of how the product is built, which you are welcome to test.