How CA Assist safeguards confidential client tax returns, GST computations, and partner audit trails from unauthorized access.
Every layer of the platform is designed against statutory disclosure hazards and cyber liability under Section 43A of the IT Act.
100% data residency in AWS Mumbai (ap-south-1) with redundant disaster recovery in Hyderabad. No overseas routing. Complete alignment with RBI and DPDP localization mandates.
AES-256 GCM encryption at rest and TLS 1.3 in transit with automated key rotation via AWS KMS. Master signing keys never leave FIPS 140-2 Level 3 hardware security modules.
Strict database schema segregation ensuring firm and client records are completely isolated and cryptographically partitioned. Zero cross-tenant data leakage risk.
Read-only tamper-evident logs for every document view, dispatch, fee payment, and partner approval. Cryptographic SHA-256 hash chains prevent retroactive alteration.
Mandatory OTP verification via WhatsApp or SMS for attesting partners and client download PIN protection. Biometric WebAuthn passkey support for enterprise practice desks.
Zero-knowledge architecture. We never request or store client Income Tax or GST portal passwords. All workflows operate via client-authorized document pushes and direct webhooks.
Statutory tax audits (Form 3CD), computation sheets, and monthly GSTR-3B filings carry severe fiduciary liability. Our dual-layer dynamic watermarking renders unauthorized external forwarding immediately traceable.
Every downloaded page is dynamically stamped across the diagonal with the authorized recipient's PAN/GSTIN, mobile number, Indian Standard Time timestamp, and unique dispatch serial number.
Client WhatsApp download links expire automatically after 72 hours. Partners can revoke access with a single click from the Review Queue before or after file viewing.
PDF files remain encrypted until the authorized recipient inputs their secure 4-digit PIN delivered strictly to their verified WhatsApp business thread.
Our six-step cryptographic handshake ensures no tax return or billing computation is dispatched to the wrong entity, even with identical client trade names.
Client texts WhatsApp bot from their registered authorized mobile number.
Meta Cloud API checks verified phone badge and firm opt-in registry status.
System cross-matches client PAN/GSTIN with exact statutory filing tax period.
Confidentiality check executed; 4-digit decrypt PIN dispatched securely.
Client settles outstanding invoice directly into CA bank account via UPI.
Masked PDF unlocks with watermarks and logs immutable partner audit receipt.
Granular role-based access control (RBAC) engineered according to ICAI partner supervision rules. Prevent junior staff from dispatching unreviewed audits or altering professional fees.
| Role Type | Manage Billing | Approve Dispatches | Waive Fees | View Audit Logs | Download Vault Files |
|---|---|---|---|---|---|
Senior Partner Firm owner & statutory attestation lead | check_circle | check_circle | check_circle | check_circle | check_circle |
Qualified CA (Manager) Audit team leader with review sign-off | check_circle | check_circle | remove | check_circle | check_circle |
Article Assistant / Staff Trainee & document prep clerk | remove | remove | remove | remove | lock Watermarked Only |
Client Recipient Authorized director or accounts manager | remove | remove | remove | remove | key PIN Protected |
Statutory deadlines (like September 30 Tax Audits or October 20 GSTR-3B) allow zero room for downtime. Our infrastructure is built for maximum disaster resilience.
Multi-availability-zone load balancing backed by financially supported service credits during peak compliance quarters.
Continuous real-time block-level replication between AWS ap-south-1 (Mumbai) and secondary failover nodes in Hyderabad.
Controls verified against Security, Availability, and Confidentiality trust principles with continuous automated evidence gathering.
Rigorous penetration testing conducted by CERT-In empanelled auditing agencies with full remediation validation reports.
We provide prospective partners and Tier-1 audit firms with signed VAPT summaries, ISO compliance certificates, data processing agreements (DPA), and DPDP questionnaire support.