GSTRecon360 is in public beta. This page distinguishes controls that are present from work still required before we describe the service as independently audited or enterprise-ready.
Current controls
- Supabase authentication and authenticated workspace routes.
- Organisation-scoped database access policies and private source-file storage.
- Server-side checks around billing, downloads and reconciliation access.
- No collection of GST portal passwords or OTPs in the upload-first workflow.
- Source-file hashes and authenticated download and deletion controls where shown in the product.
Public-beta limitations
- No independent penetration-test report or security certification has been published.
- No uptime SLA or independently monitored public status page is available yet.
- Automatic retention schedules, legal holds and full account self-erasure are still being completed.
- Direct GSTN/IMS connectivity is not available; users upload portal exports and verify all actions on the GST portal.
Data handling
Source files can contain GSTINs, invoice references and tax amounts. Give workspace access only to authorised staff, retain an independent copy of statutory records, and delete sources when they are no longer needed. See the Privacy Policy for the current beta position.
Report a security concern
Send a concise description, affected URL and reproduction steps to support@gstrecon360.com. Do not include live client invoice data in an initial report. Responsible reports will be investigated; no response-time bounty or SLA is promised in the beta.