Enterprise Trust & Data Governance

Security Built for Financial Data

Security is not an afterthought — it is foundational to how Complytics partitions multi-tenant CA firm workspaces, encrypts statutory registers, and logs compliance actions.

PostgreSQL RLS Active

Engine-Level Data Isolation Guarantee

When managing multiple client entities, CA firms cannot risk cross-client data visibility. Complytics enforces database-level RLS policies so every query is mathematically isolated to its parent organization.

Database Kernel Isolation

PostgreSQL Row-Level Security (RLS)

Unlike application-level filtering, every database query executed by Complytics is subject to PostgreSQL RLS policies at the engine level. SQL queries evaluate the active user's firm_id tenant key, making cross-tenant data leakage physically impossible even under API misconfiguration.

TLS 1.3 & AES-256

Bank-Grade Encryption Standards

All statutory GSTR-2B data, invoices, and accounting registers are encrypted in transit using TLS 1.3 with HSTS enabled. At rest, data is encrypted using AES-256 cryptographic keys with automated key rotation.

Clerk Enterprise Auth

Identity & Multi-Factor Auth (MFA)

User authentication is powered by Clerk Auth, featuring Multi-Factor Authentication (MFA), SAML SSO for enterprise CA firms, session token signing, and automated brute-force protection.

Audit Lineage & Governance

Immutable Audit Trails

Every document upload, GSTR-2B reconciliation run, manual mismatch override, staff invitation, and data export creates an immutable audit record containing precise timestamps, user identity, and IP address.

99.9% Uptime Target

High Availability & Regional Backup

Hosted on enterprise cloud infrastructure with regional failover, automated point-in-time database backups, and DDoS protection provided by Vercel and AWS infrastructure.

Security Bug Bounty

Responsible Vulnerability Disclosure

We encourage ethical security researchers and partners to report potential vulnerabilities. Our internal security response team acknowledges reports within 24 hours.

Security Incident & Vulnerability Reporting

If you believe you have discovered a security vulnerability or unauthorized access risk within the Complytics platform, please report it immediately to our security engineering team.

Report Security Concern PVP Key / PGP Encryption Available Upon Request