Enterprise Security & Data Sovereignty Standards

Fiduciary-Grade Data Protection Built for Chartered Accountants.

As a CA firm, client confidentiality is sacred. CAfirmOS is architected with bank-level encryption, Indian sovereign cloud infrastructure, and strict role-based isolation to ensure complete compliance with ICAI guidelines and statutory laws.

AWS Mumbai (ap-south-1)
256-Bit AES Encryption
99.99% Uptime Guarantee

Cryptographic Isolation

Indian Sovereign Cloud & Bank-Grade Encryption Architecture

Your clients' income tax returns, profit & loss accounts, and GST data are stored in segregated relational databases hosted within AWS Mumbai (ap-south-1). No data crosses Indian borders.

Hardware Security Modules (HSM) with AES-256 automated key rotation
Time-based OTP & biometric multi-factor authentication for partners
Full compliance with Section 128 of the Companies Act 2013
AES

AES-256 at Rest

Every tax computation, bank statement, and client ledger is encrypted using individual practice cryptographic keys.

TLS

TLS 1.3 in Transit

End-to-end forward secrecy encryption across all browser sessions, mobile portals, and portal sync APIs.

AWS

AWS Mumbai Data Residency

Strict sovereign hosting within Indian borders (ap-south-1) with dual-zone automated snapshots.

SQC

SQC-1 Audit Trails

Immutable change logging for peer-review readiness under ICAI Quality Control standards.

Technical Safeguards

Multi-Layered Security Architecture

How CAfirmOS protects your practice records, confidential tax filings, and portal credentials.

Indian Sovereign Hosting

All databases and document buckets reside exclusively in AWS Mumbai data centers (ap-south-1). Your client data never leaves Indian borders, fulfilling Section 128 of the Companies Act 2013 and ICAI recommendations.

Zero cross-border transfers

End-to-End Encryption

Data in transit is encrypted using modern TLS 1.3 with Perfect Forward Secrecy. Data at rest (stored documents, audit notes, database backups) is encrypted with AES-256 with KMS rotating keys.

Military-grade cryptographic ciphers

Granular Role Permissions

Four discrete authorization roles: Partner, Manager, Senior Associate, and Article Trainee. Restrict visibility into fee ledgers, partner notes, or government portal passwords based on staff level.

Customizable access matrices

Immutable Audit Logging

Every user action - document downloads, status updates, client edits, and login attempts - is permanently timestamped and logged. Essential for peer review defense and internal accountability.

Tamper-proof event logs

Automated Encrypted Backups

Continuous point-in-time recovery and automated daily multi-AZ snapshots safeguard against hardware failure or accidental deletions. You can export your full practice data vault in 1 click anytime.

Zero data lock-in

Zero AI Training on Client Data

Unlike consumer AI tools, CAfirmOS executes document OCR, bank analysis, and statutory queries within isolated ephemeral containers. Your clients' sensitive financial statements are never used to train public LLMs.

Private inference pipeline
Fiduciary Security Whitepaper

The Indian CA's Guide to Data Protection, Section 128 Compliance & Sovereign Hosting

A definitive guide for managing partners on safeguarding client confidentiality, complying with the Digital Personal Data Protection Act (DPDPA 2023), and defending against internal data exfiltration.

1Section 128 of the Companies Act 2013: Keeping Books in India

Rule 3 of the Companies (Accounts) Rules, 2014, amended under Section 128, mandates that electronic books of account and other relevant books and papers must remain accessible in India at all times. Crucially, the back-up of the books of account and other papers kept in electronic mode, even if maintained outside India, must be kept in servers physically located in India on a daily basis.

Foreign practice management tools hosted in US or European regions create substantial statutory compliance vulnerabilities for Indian audit clients. CAfirmOS eliminates this risk by maintaining all production and disaster recovery databases within AWS Mumbai (ap-south-1).

2Digital Personal Data Protection Act (DPDPA 2023) Safeguards

CA firms handle India's most sensitive personally identifiable and financial data: PAN numbers, Aadhaar OTPs, bank statements, director DINs, and net-worth certifications. Under the DPDPA 2023, data fiduciaries face fines up to ₹250 Crores for significant data breaches or failure to implement reasonable security safeguards.

CAfirmOS incorporates technical controls designed for fiduciary protection: automatic redaction of Aadhaar numbers in stored document previews, role-restricted PAN registries, ephemeral tokenization of government portal credentials, and automatic logging of all data export attempts.

3Preventing Article Clerk Data Exfiltration

The most common data security threat in an Indian CA firm is not an external hacker - it is departing staff or article trainees downloading the firm's complete client roster before launching an independent practice.

In CAfirmOS, bulk export capabilities are restricted exclusively to equity partners. Article assistants can view the specific tasks and documents assigned to their active jobs, but cannot export entire client databases, download bulk contact lists, or access fee recovery records.

Security & Compliance FAQs for CA Partners

Addressing the common concerns raised during firm partner meetings.

Does hosting client data on CAfirmOS violate ICAI confidentiality rules?

No. The Institute of Chartered Accountants of India (ICAI) permits cloud practice management tools provided confidentiality is preserved through contractual commitments and encryption. CAfirmOS acts solely as a data processor with strict non-disclosure obligations, and data is stored in AWS Mumbai under Indian law.

What happens if an article assistant leaves our firm abruptly?

You can deactivate any staff or article account in 1 click from the Partner Administration console. Deactivation immediately invalidates all active sessions, revokes document access, and reassigns all pending tasks and client files to another team member without data leakage.

Can we export our complete database if we decide to switch platforms?

Yes. We believe in absolute client ownership. Partners can request a complete data archive (CSV client records, organized document directories, and billing history) with one click from the firm settings panel.

Rated #1 CA Practice Management Software in India • 500+ Active Practices

Bank-Level Security For Your Practice. Zero Compromises.

See why over 500 top Indian CA firms trust CAfirmOS with their client compliance workflows and document archives.

14-Day Full Access Free Trial
No Credit Card Required
AWS Mumbai Data Sovereignty
ICAI Code of Ethics Adherent