How we protect your data
IntelliBooks stores the financial and tax records of accounting firms and businesses across India. We treat that responsibility seriously and design the platform from the ground up around defense in depth, least privilege, and transparency.
Last updated: May 23, 2026
At a glance
Encryption in transit
TLS 1.2+ everywhere
Encryption at rest
AES-256 (RDS + S3)
Hosting region
AWS ap-south-1 (Mumbai)
Multi-factor auth
Mandatory for Owner / Admin / Platform Admin
Audit logs
Append-only, 7-year retention
Backups
Daily RDS + S3 versioning
Certifications & frameworks
We follow recognized security frameworks and undergo external audits to provide independent assurance of our controls.
| Framework | Status | Target |
|---|---|---|
| SOC 2 Type I | In progress | Q4 2026 |
| SOC 2 Type II | Planned | Q2 2027 |
| ISO/IEC 27001:2022 | Planned | Q3 2027 |
| Digital Personal Data Protection Act, 2023 (India) | Compliant | — |
| GDPR (for EU customers) | Compliant via DPA + SCCs where applicable | — |
Current audit reports and certifications are available to enterprise customers under NDA. Contact security@intellibooks.in.
Security practices
Concrete controls that protect your data in production.
Every database query is scoped to a single tenant at the middleware layer; cross-tenant access is impossible from application code paths.
Passwords hashed with bcrypt. New passwords checked against Have I Been Pwned breach corpus. Multi-factor authentication mandatory for high-privilege roles.
Application audit logs are append-only at the database and runtime layers. AWS API activity is shipped to S3 with Object Lock in Compliance mode (7-year retention).
Passwords, MFA secrets, encryption material, full account numbers, salary amounts and similar sensitive fields are automatically redacted from internal audit logs.
AWS Config enforces baseline rules (encryption, public access, root MFA, etc.). GuardDuty provides threat detection in production. Dependency vulnerabilities are scanned on every code change.
Severity-classified runbooks with defined owners and notification SLAs. Confirmed breaches: notification to affected customers within 72 hours of confirmation.
Sub-processors
IntelliBooks uses the following third-party services to deliver our platform. Customers are notified at least 30 days in advance before a material new sub-processor is added.
| Vendor | Service | Region | Certifications |
|---|---|---|---|
| Amazon Web Services | Cloud infrastructure (compute, storage, database, network) | ap-south-1 (Mumbai) | SOC 2 Type II, ISO 27001, ISO 27017, ISO 27018 |
| Razorpay | Subscription billing & payments | India | SOC 2 Type II, PCI DSS Level 1, ISO 27001 |
| OpenAI | AI Assistant feature (opt-in usage) | United States | SOC 2 Type II |
| Setu | Account Aggregator bank-feed integration (customer-consented) | India | ISO 27001, RBI Account Aggregator licensee |
| Meta WhatsApp Business Platform | WhatsApp notifications (opt-in) | United States / European Union | SOC 2 Type II, ISO 27001 |
Government gateways used for statutory filings (NIC e-invoice portal, GSTN, NSDL/TRACES) are not commercial sub-processors and operate under their respective statutes.
Your rights as a data subject
Under the Digital Personal Data Protection Act, 2023 (and GDPR for customers in the European Union), you have the following rights with respect to your personal data:
- Access: request a copy of your personal data — available in-app under Settings → Privacy → Export my data.
- Correction: update inaccurate or incomplete data via your profile or by contacting support.
- Deletion: request deletion of your account and personal data, subject to statutory retention requirements (e.g., 6-8 years for accounting records under Indian tax law).
- Grievance: contact our Data Protection Officer at security@intellibooks.in.
Full details are in our Privacy Policy.
Reporting a security issue
Found a vulnerability or suspect a security incident?
Please email security@intellibooks.in with as much detail as you can share. We acknowledge reports within 2 business days. We welcome and recognize coordinated disclosure by independent researchers.
For confirmed breaches involving customer data, we notify affected customers within 72 hours of confirmation as required by the Digital Personal Data Protection Act, 2023.
For real-time service status, see status.intellibooks.in — hosted independently of our production infrastructure so it remains available during incidents.