Trust at IntelliBooks

How we protect your data

IntelliBooks stores the financial and tax records of accounting firms and businesses across India. We treat that responsibility seriously and design the platform from the ground up around defense in depth, least privilege, and transparency.

Last updated: May 23, 2026

At a glance

Encryption in transit

TLS 1.2+ everywhere

Encryption at rest

AES-256 (RDS + S3)

Hosting region

AWS ap-south-1 (Mumbai)

Multi-factor auth

Mandatory for Owner / Admin / Platform Admin

Audit logs

Append-only, 7-year retention

Backups

Daily RDS + S3 versioning

Certifications & frameworks

We follow recognized security frameworks and undergo external audits to provide independent assurance of our controls.

FrameworkStatusTarget
SOC 2 Type IIn progressQ4 2026
SOC 2 Type IIPlannedQ2 2027
ISO/IEC 27001:2022PlannedQ3 2027
Digital Personal Data Protection Act, 2023 (India)Compliant
GDPR (for EU customers)Compliant via DPA + SCCs where applicable

Current audit reports and certifications are available to enterprise customers under NDA. Contact security@intellibooks.in.

Security practices

Concrete controls that protect your data in production.

Tenant isolation

Every database query is scoped to a single tenant at the middleware layer; cross-tenant access is impossible from application code paths.

Strong authentication

Passwords hashed with bcrypt. New passwords checked against Have I Been Pwned breach corpus. Multi-factor authentication mandatory for high-privilege roles.

Tamper-evident audit logs

Application audit logs are append-only at the database and runtime layers. AWS API activity is shipped to S3 with Object Lock in Compliance mode (7-year retention).

PII redaction in logs

Passwords, MFA secrets, encryption material, full account numbers, salary amounts and similar sensitive fields are automatically redacted from internal audit logs.

Continuous monitoring

AWS Config enforces baseline rules (encryption, public access, root MFA, etc.). GuardDuty provides threat detection in production. Dependency vulnerabilities are scanned on every code change.

Documented incident response

Severity-classified runbooks with defined owners and notification SLAs. Confirmed breaches: notification to affected customers within 72 hours of confirmation.

Sub-processors

IntelliBooks uses the following third-party services to deliver our platform. Customers are notified at least 30 days in advance before a material new sub-processor is added.

VendorServiceRegionCertifications
Amazon Web ServicesCloud infrastructure (compute, storage, database, network)ap-south-1 (Mumbai)SOC 2 Type II, ISO 27001, ISO 27017, ISO 27018
RazorpaySubscription billing & paymentsIndiaSOC 2 Type II, PCI DSS Level 1, ISO 27001
OpenAIAI Assistant feature (opt-in usage)United StatesSOC 2 Type II
SetuAccount Aggregator bank-feed integration (customer-consented)IndiaISO 27001, RBI Account Aggregator licensee
Meta WhatsApp Business PlatformWhatsApp notifications (opt-in)United States / European UnionSOC 2 Type II, ISO 27001

Government gateways used for statutory filings (NIC e-invoice portal, GSTN, NSDL/TRACES) are not commercial sub-processors and operate under their respective statutes.

Your rights as a data subject

Under the Digital Personal Data Protection Act, 2023 (and GDPR for customers in the European Union), you have the following rights with respect to your personal data:

Full details are in our Privacy Policy.

Reporting a security issue

Found a vulnerability or suspect a security incident?

Please email security@intellibooks.in with as much detail as you can share. We acknowledge reports within 2 business days. We welcome and recognize coordinated disclosure by independent researchers.

For confirmed breaches involving customer data, we notify affected customers within 72 hours of confirmation as required by the Digital Personal Data Protection Act, 2023.

For real-time service status, see status.intellibooks.in — hosted independently of our production infrastructure so it remains available during incidents.