Skip to content
Security follows the reconciliation

Client data stays scoped. Month-close evidence stays defensible.

Security is built into who can see a workspace, how database transport is verified, what gets recorded, and what happens after the month is frozen.

No portal passwords Tenant-scoped access Audited freeze history
0GST portal passwords storedFiles are downloaded by you
100%sensitive actions attributableUser, time, and request context
1tenant boundary per workspaceApplied through service reads
CAverified database TLSRequired for production
Controls across the full data lifecycle

From sign-in to deletion, the control is explicit.

Each layer has a practical job: keep clients separated, reduce unauthorised access, preserve evidence, and make sensitive changes reviewable.

Control 01

Tenant and organisation scope

Application reads and writes are scoped to the signed-in tenant and organisation, with separate platform-admin and client-portal access paths.

Control 02

Guarded authentication

Production can use Google OAuth. Email passwords are hashed, sessions are signed, and suspended accounts are blocked during access checks.

Control 03

Verified transport configuration

Production database connections require an explicit CA certificate for hostname verification; insecure certificate fallback is not part of the launch configuration.

Control 04

Tamper-evident activity history

Sensitive uploads, freezes, administrative changes, and configuration updates are recorded with request metadata and chained hashes.

Control 05

Immutable freeze snapshots

A frozen period preserves the approved reconciliation state. A later change must become a visible, reasoned revision rather than a silent overwrite.

Control 06

Controlled file retention

Source uploads and generated evidence are designed for private object storage with tenant keys, download controls, and plan-aware retention limits.

Control 07

No GST portal credentials

Users download GSTR-2B themselves. GSTRecon360 never asks for, stores, or uses GST portal passwords and is independent of GSTN.

Control 08

Tracked deletion requests

A deletion request immediately suspends the account and is queued for manual data removal by our support team, completed within 30 days.

Evidence architecture

The locked month is more than a status badge.

A defensible close needs the source, the reconciliation result, the review decision, and the activity trail to remain linked.

IdentitySigned session and scoped roleEvidenceFiles, hashes, matches, and exportsHistoryAppend-only sensitive actionsFreezeApproved state preserved as a snapshot
Security questions are welcome

Review the control model before you upload client data.

Tell us about your team, deployment, retention, or access requirements and we will answer plainly — without certification theatre.