Security
How we protect your data
Plain statements about what is in place today, and what isn’t yet.
Each account is walled off in the database
- Every row belongs to one workspace, and the database itself refuses to show or change rows from another one. This is enforced by PostgreSQL row-level security on every table, not only by the screens.
- An automated test signs in as one business and tries to read, change and join another. It runs on every change to the code.
- A client in the portal can read only their own projects, the tasks you chose to share, and their issued invoices and payments. They cannot write to anything except their own messages, approvals and reviews.
- A team member sees only the projects you assign them. Invoices, payments, expenses, leads and client notes are for owners and admins.
Records you can rely on
- An invoice is locked when it’s issued. To correct one, you cancel it and issue another, so your books always match what the client received.
- Invoice numbers are consecutive within each financial year, even when several invoices are issued at the same moment.
- Money is stored as whole paise, never as decimals, so totals never drift by a paisa.
- Important changes are written to an audit log with who made them and when. The database refuses any edit or deletion of the log.
- Client reviews and approval answers can’t be edited after they’re given.
Logging in
- Passwords are handled by Supabase Auth and stored only as salted hashes. We never see or store your password. You can also sign in with Google.
- Repeated failed log-ins from the same email or address are slowed down and then blocked for a while.
- Changing your password signs out every device.
- Invite links for clients and teammates work once, expire after 7 days, and are stored only as a hash, so a copy of the database wouldn’t reveal a working link.
Where your data lives
- The database is hosted in Mumbai, India, on Supabase (PostgreSQL). The application runs on Vercel.
- All traffic is encrypted in transit with HTTPS, and the database is encrypted at rest by the hosting provider.
- An encrypted backup of the whole database is taken every night and stored separately from the database.
- The site sends a strict Content Security Policy and related browser protections, and can’t be embedded in another site’s frame.
What we don’t do
- We don’t sell your data or your clients’ data, and we don’t show ads.
- We don’t store card numbers or UPI PINs. A UPI payment happens in your client’s own UPI app.
- The free tools on this site run in your browser. What you type into them is never sent to us.
Not in place yet
These are planned before paid plans begin. We list them so you can decide with the full picture.
- Two-step login (authenticator app)
- Exporting and deleting all your data yourself from Settings
- A list of your active sessions
Found a problem?
If you believe you’ve found a security issue, please tell us before sharing it publicly through the contact page.We’ll reply, fix it, and credit you if you’d like.