Security Built for Financial Data
Security is not an afterthought — it is foundational to how Complytics partitions multi-tenant CA firm workspaces, encrypts statutory registers, and logs compliance actions.
Engine-Level Data Isolation Guarantee
When managing multiple client entities, CA firms cannot risk cross-client data visibility. Complytics enforces database-level RLS policies so every query is mathematically isolated to its parent organization.
PostgreSQL Row-Level Security (RLS)
Unlike application-level filtering, every database query executed by Complytics is subject to PostgreSQL RLS policies at the engine level. SQL queries evaluate the active user's firm_id tenant key, making cross-tenant data leakage physically impossible even under API misconfiguration.
Bank-Grade Encryption Standards
All statutory GSTR-2B data, invoices, and accounting registers are encrypted in transit using TLS 1.3 with HSTS enabled. At rest, data is encrypted using AES-256 cryptographic keys with automated key rotation.
Identity & Multi-Factor Auth (MFA)
User authentication is powered by Clerk Auth, featuring Multi-Factor Authentication (MFA), SAML SSO for enterprise CA firms, session token signing, and automated brute-force protection.
Immutable Audit Trails
Every document upload, GSTR-2B reconciliation run, manual mismatch override, staff invitation, and data export creates an immutable audit record containing precise timestamps, user identity, and IP address.
High Availability & Regional Backup
Hosted on enterprise cloud infrastructure with regional failover, automated point-in-time database backups, and DDoS protection provided by Vercel and AWS infrastructure.
Responsible Vulnerability Disclosure
We encourage ethical security researchers and partners to report potential vulnerabilities. Our internal security response team acknowledges reports within 24 hours.
Security Incident & Vulnerability Reporting
If you believe you have discovered a security vulnerability or unauthorized access risk within the Complytics platform, please report it immediately to our security engineering team.