Your clients trust you with their data. We take that seriously.
How FirmSaathi keeps a CA firm's client data private, separate and recoverable.
Hosted in India
The app and the database run on AWS in Mumbai. Uploaded documents and backups are kept in encrypted storage; the data processing agreement lists every provider and where it is.
Each firm walled off in the database
Every row carries its firm, and Postgres row-level security refuses to return another firm's data even if the app asked for it. Automated tests try to read across firms on every release.
Credentials encrypted field by field
Portal logins you keep for clients (income tax, GST, TRACES, MCA) are encrypted individually. Revealing one needs permission and is logged with who and when.
Two-factor sign-in and roles
Any user can turn on two-factor authentication, and an owner can require it. Roles decide who sees which clients and which modules, down to the client.
Backups we restore-test
The database is backed up continuously and restored on a schedule to prove the backups work. Firm owners can export all their data at any time.
Audit trail
Changes to clients, tasks, permissions and settings are recorded in an audit log that the app itself cannot edit.
The DPDP Act, in plain words
For your clients' data, your firm decides why and how it is used, so the firm is the data fiduciary under the Digital Personal Data Protection Act, 2023. FirmSaathi processes it only on your instructions, as your data processor, under a written data processing agreement.
If we ever detect a breach that affects your firm, we tell you without delay with what we know, so you can meet your own duties. Questions or a security report: security@firmsaathi.com.
Read the privacy policy and the data processing agreement.
See your firm on one screen
30-day free trial of the Firm plan. No card needed.