Encryption
Secure HTTPS/TLS in transit, and protected storage on managed infrastructure.
We protect your business information with security and privacy built into the platform from the ground up. From GST and accounting records to invoices, customer information and payroll data, your information is protected through secure communication, controlled access, tenant isolation and auditability.
Your business data belongs to you.
We design our platform so that your financial, GST, accounting, payroll, invoice, customer and business information is protected using multiple layers of security. We do not treat your business data as a product. Your data is stored securely, access is controlled, and your company's data is isolated from other customers.
Security and privacy are built into the platform from the foundation — not added as an afterthought. Your data is protected through multiple layers, not one security feature.
Each of these is a control that is actually part of the product today.
Secure HTTPS/TLS in transit, and protected storage on managed infrastructure.
Your company's data is logically separated from every other business.
Only authenticated, authorized users reach the information they're permitted to.
An authenticator-app second step adds protection beyond the password.
Important actions are recorded — who, what and when — for accountability.
Managed backup and recovery procedures help reduce the risk of accidental loss.
The platform handles the information a business most needs to keep safe. Because of that, security and privacy are treated as a core product requirement — not a setting.
Yes — data protection is implemented across the application and infrastructure using encryption and secure communication. It helps to distinguish two things:
Information transferred between your browser or app and our servers is protected using secure HTTPS/TLS communication, with HSTS enforced in production so connections stay encrypted.
Stored business information is protected using the encryption and security capabilities of the underlying managed database and cloud infrastructure it runs on.
We deliberately don't claim a specific encryption algorithm we can't verify end to end. The wording reflects what is actually implemented.
No. Each business operates within its own isolated data environment.
Getting into an account is protected by several mechanisms working together:
Access is controlled through authentication, role-based permissions, company- and location-level controls, MFA, session security and audit logging. Within your own organisation, each employee only receives the permissions you assign them.
| Role | What they can reach |
|---|---|
| Owner | Full access — including confidential fees and business settings |
| Manager | Management access across the company's operations |
| Accountant | Accounting, GST and reporting access |
| Store keeper | Inventory and location-scoped access only |
| Read-only | View-only access, no changes |
These are examples — the product ships 8 roles across granular permissions, checked in the service layer, so the line sits exactly where your business needs it.
The platform runs on managed cloud infrastructure with your data kept in India.
Business data is backed up according to our backup and recovery procedures to help protect against accidental loss and infrastructure failures.
We describe this as a procedure rather than a promise of zero data loss, instant recovery or unlimited, permanent backups — because honest security means saying what the infrastructure actually does.
The platform maintains an immutable audit trail for important system changes, giving your business greater visibility and accountability over its financial records.
Posted entries have no edit or delete path — corrections are new, linked postings, so the record can be trusted, not just believed.
When a subscription or trial period ends, the account moves to read-only — you are not locked out, and it can be extended or converted to a paid plan. Your data stays available to view and export during that period.
The exact data retention and deletion timeline is defined in our Privacy Policy and applicable service terms.
The platform is built to help you manage your own business information — access it, export it, manage users and permissions, and handle deletion and retention according to policy.
Every return, register, ledger and report exports to Excel and PDF — GSTR-1, 3B and 9, sales, purchase and expense registers, debtors and creditors ledgers, Trial Balance, P&L and Balance Sheet — so your data stays portable, not locked in. Access to customer information is controlled and limited according to our security, operational and support policies.
You can request deletion of your business data through our security contact. When data is permanently deleted is governed by our retention and deletion policy.
Our data retention and deletion policy is set out in our Privacy Policy and applicable service terms.
Our Privacy Policy sets out how business information is collected, used, retained and deleted, and the rights that apply to it.
Read the full Privacy Policy — written in plain business language and aligned with India's DPDP Act, 2023.
For security questions, data-export or deletion requests, or to report a concern:
Your business trusts us with information that matters. That's why security is built into the architecture — from authentication and access control to tenant isolation, auditability and infrastructure protection. We continuously work to keep your business information protected.
Plain answers, in business language. Finkitaabh sells software, not your data.
We protect your business information with multiple layers of security — encrypted connections, authenticated logins, role-based permissions, per-company data isolation and an immutable audit trail. Your financial records are guarded at several steps, not by a single feature.
Yes. Information moving between your browser and our servers travels over secure HTTPS/TLS connections, with HSTS enforced in production. Stored business data is protected using the encryption and security capabilities of the managed database and cloud infrastructure it runs on. We describe this the way it is actually implemented rather than claiming a specific algorithm we can't verify end to end.
No. Each business operates within its own isolated data environment. The platform enforces tenant-level access controls, and PostgreSQL row-level security is enabled at the database on every company-scoped table — an additional layer of isolation beyond application checks. Users can access only the company data they are authorized for.
Access to customer information is controlled and limited according to our security, operational and support policies. Where support access is needed to help resolve an issue, it is explicit and recorded in the audit log rather than being an invisible capability. We don't claim that no employee can ever access data — honest security means describing the controls, not making absolute promises.
Yes. GST returns, invoices, accounting records and related business information are handled within the same protected application environment and access-control framework as the rest of your data — the same encryption in transit, tenant isolation, permissions and audit trail apply to all of it.
Yes. Payroll and employee-related information is protected through authentication, role-based authorization and access controls. Sensitive items such as confidential fee contracts are restricted to owner and manager roles, enforced by permission rather than convention.
Yes. Every return, register, ledger and report exports to Excel and PDF — GSTR-1, 3B and 9, sales, purchase and expense registers, debtors and creditors ledgers, Trial Balance, P&L and Balance Sheet — so your data stays portable, not locked in.
When a subscription or trial period ends, the account moves to read-only — you are not locked out, and it can be extended or converted to a paid plan. Your data stays available to view and export during that period. The exact data retention and deletion timeline is defined in our Privacy Policy and applicable service terms, and you can request deletion through our security contact.
Your data is hosted on managed cloud infrastructure, with data kept in India, in a managed PostgreSQL database that has row-level isolation per company and managed backup and recovery procedures.
Business data is held in a managed database with backup and recovery procedures intended to help protect against accidental loss and infrastructure failures. We describe this as a procedure, not a guarantee of zero data loss or instant recovery.
A 30-minute personalised walkthrough with our product specialist — in Hindi or English, whatever you're comfortable with. We'll set up a sample company that looks like your business.