shield
CA AssistStatutory Vault Architecture
verified_userDPDP Act 2023 · ISO 27001 Standard Architecture · ICAI Ethics Compliant

Security you can trust. Engineered for statutory compliance.

How CA Assist safeguards confidential client tax returns, GST computations, and partner audit trails from unauthorized access.

Data Residency
100% In-Country
AWS Mumbai & Hyderabad
Rest Encryption
AES-256 GCM
Hardware KMS Enclaves
Uptime SLA
99.95%
High-availability cluster
Portal Passwords
Zero Stored
Strict Zero-Knowledge Policy
Pillar Architecture

Institutional Trust & Cryptographic Rigor

Every layer of the platform is designed against statutory disclosure hazards and cyber liability under Section 43A of the IT Act.

location_on

Data hosted in India

100% data residency in AWS Mumbai (ap-south-1) with redundant disaster recovery in Hyderabad. No overseas routing. Complete alignment with RBI and DPDP localization mandates.

Sovereign Cloud Enclave
enhanced_encryption

Encrypted in transit and at rest

AES-256 GCM encryption at rest and TLS 1.3 in transit with automated key rotation via AWS KMS. Master signing keys never leave FIPS 140-2 Level 3 hardware security modules.

Continuous KMS Key Rotation
domain_verification

Tenant isolation

Strict database schema segregation ensuring firm and client records are completely isolated and cryptographically partitioned. Zero cross-tenant data leakage risk.

Row-Level Security (RLS)
history_edu

Immutable audit trail

Read-only tamper-evident logs for every document view, dispatch, fee payment, and partner approval. Cryptographic SHA-256 hash chains prevent retroactive alteration.

Append-Only Ledger Architecture
phonelink_lock

Two-factor sign-in

Mandatory OTP verification via WhatsApp or SMS for attesting partners and client download PIN protection. Biometric WebAuthn passkey support for enterprise practice desks.

WhatsApp Cloud API Auth
password

No portal passwords stored

Zero-knowledge architecture. We never request or store client Income Tax or GST portal passwords. All workflows operate via client-authorized document pushes and direct webhooks.

Zero Credential Exposure
water_dropDocument Anti-Leakage Tech

How your documents are protected

Statutory tax audits (Form 3CD), computation sheets, and monthly GSTR-3B filings carry severe fiduciary liability. Our dual-layer dynamic watermarking renders unauthorized external forwarding immediately traceable.

branding_watermark

Dynamic Statutory Stamping

Every downloaded page is dynamically stamped across the diagonal with the authorized recipient's PAN/GSTIN, mobile number, Indian Standard Time timestamp, and unique dispatch serial number.

timer

Revocable Expiring Links

Client WhatsApp download links expire automatically after 72 hours. Partners can revoke access with a single click from the Review Queue before or after file viewing.

lock_open

4-Digit PIN Security

PDF files remain encrypted until the authorized recipient inputs their secure 4-digit PIN delivered strictly to their verified WhatsApp business thread.

picture_as_pdf
FORM_3CD_FY2023-24_AUDIT.pdf
4.8 MB · 256-bit AES Encrypted
check_circleVerified Hash
CONFIDENTIAL · RECIPIENT: 27AABCT2432M1ZG · MOB: +91 98XXXXXX10 · 21 SEP 2026 14:32:08 IST · DISPATCH #TRV-8942
TRIVEDI & ASSOCIATES · STATUTORY AUDIT COPY · FOR CLIENT ASSESSMENT USE ONLY
CONFIDENTIAL · RECIPIENT: 27AABCT2432M1ZG · MOB: +91 98XXXXXX10 · 21 SEP 2026 14:32:08 IST · DISPATCH #TRV-8942
Tax Year
AY 2024-25
Tax Payable
₹12,40,500.00
Status
Reconciled
fingerprintSHA256: 7f83b1657ff1...b6a382e
Tamper Sealed
pinProtected by 4-digit recipient PINValid for: 71h 58m
Automated Verification Protocol

Right document, right client. Guaranteed.

Our six-step cryptographic handshake ensures no tax return or billing computation is dispatched to the wrong entity, even with identical client trade names.

01forum

Client Request

Client texts WhatsApp bot from their registered authorized mobile number.

Req: Form 3CB / 3CD
02mark_chat_read

WhatsApp Verification

Meta Cloud API checks verified phone badge and firm opt-in registry status.

E.164 +91 Matched
03policy

Document Match

System cross-matches client PAN/GSTIN with exact statutory filing tax period.

GSTIN Check: Exact
04password

Send Guard & PIN

Confidentiality check executed; 4-digit decrypt PIN dispatched securely.

4-Digit Challenge
05qr_code_2

UPI Settlement

Client settles outstanding invoice directly into CA bank account via UPI.

Direct CA Bank VPA
06task_alt

Watermarked Delivery

Masked PDF unlocks with watermarks and logs immutable partner audit receipt.

Tamper Log Recorded
lockZero manual file handling. All dispatches mediated by cryptographically signed worker processes.
Meta Cloud API 2024 Verified NPCI UPI Autopay Ready
Governance & Controls

Who can see what

Granular role-based access control (RBAC) engineered according to ICAI partner supervision rules. Prevent junior staff from dispatching unreviewed audits or altering professional fees.

Role TypeManage BillingApprove DispatchesWaive FeesView Audit LogsDownload Vault Files
Senior Partner
Firm owner & statutory attestation lead
check_circlecheck_circlecheck_circlecheck_circlecheck_circle
Qualified CA (Manager)
Audit team leader with review sign-off
check_circlecheck_circleremovecheck_circlecheck_circle
Article Assistant / Staff
Trainee & document prep clerk
removeremoveremoveremovelock Watermarked Only
Client Recipient
Authorized director or accounts manager
removeremoveremoveremovekey PIN Protected
* Role assignment requires dual Senior Partner sign-off under multi-signatory provisions.ICAI Supervised Model v2.4
Resilience & Compliance

Incident response & Business Continuity

Statutory deadlines (like September 30 Tax Audits or October 20 GSTR-3B) allow zero room for downtime. Our infrastructure is built for maximum disaster resilience.

speed
99.95%
Uptime Service Level

Multi-availability-zone load balancing backed by financially supported service credits during peak compliance quarters.

backup
24h RPO / 4h RTO
Disaster Recovery Targets

Continuous real-time block-level replication between AWS ap-south-1 (Mumbai) and secondary failover nodes in Hyderabad.

verified
SOC 2 Type II
Independent Alignment

Controls verified against Security, Availability, and Confidentiality trust principles with continuous automated evidence gathering.

security
CERT-In Audited
Annual Empanelled VAPT

Rigorous penetration testing conducted by CERT-In empanelled auditing agencies with full remediation validation reports.

All statutory dispatch pipelines & WhatsApp gateways operational
View Real-Time System Statusopen_in_new
gavelEnterprise Practice Assurance

Have custom security requirements or need a VAPT audit report?

We provide prospective partners and Tier-1 audit firms with signed VAPT summaries, ISO compliance certificates, data processing agreements (DPA), and DPDP questionnaire support.

shield_with_heartNDA-protected diligence vaultschedule24-hour SLA on statutory queriesverified_userSigned Data Processing Agreements (DPA)