Security and certification.
Your clients' books are confidential. Here is how FinCom protects them, and where our certifications stand today.
Certifications
ISO/IEC 27001:2022
In progressInformation security management system documented against all 93 Annex A controls, with a risk register and a Statement of Applicability. The certification audit by an accredited body follows.
VAPT
ScheduledVulnerability assessment and penetration test by a CERT-In empanelled auditor, covering the web app, the cloud interfaces and the Tally Bridge.
DPDP Act 2023
In progressPrivacy notice, purpose limitation, deletion on request, processor terms for firms, and breach notice without delay.
CERT-In Directions 2022
In placeIncident process with reporting to CERT-In within 6 hours, a point of contact, and an audit trail kept for at least 180 days.
FinCom is not yet ISO 27001 certified. The certificate and the VAPT summary will be published here when they are issued, and shared with customers on request under a non-disclosure agreement.
How your data is protected
Each firm walled off
Every table in the database is locked to the firm that owns it. The database itself refuses any request for another firm's rows, whatever the screen asks for.
Stored in India
Accounts and firm data are held in the Mumbai region, encrypted at rest (AES-256) and in transit (TLS 1.2 or higher). Nightly backups are kept for 14 days.
Sign-in
Passwords of at least 10 characters, checked against known leaks. Automatic sign-out after 30 minutes without use. Optional two-step sign-in with an authenticator app, required for our own administrators.
A trail that cannot be changed
Sign-ins, every post to or deletion from Tally, and changes to people and credit are recorded in an audit trail that cannot be edited or deleted, even by us.
Nothing secret in your browser
AI and OCR keys stay on our servers. The site loads scripts only from its own address and blocks everything else, which shuts out most web attacks.
Tally stays on your computer
The Tally Bridge listens only on the computer where it runs, answers only FinCom with a paired key, and never opens Tally to the internet.
Who processes data for us
We use a small number of service providers. Each sees only what its service needs, under contract.
| Provider | What for | Where |
|---|---|---|
| Supabase Inc. | Database, sign-in, file storage | India (AWS Mumbai region) |
| GitHub (Microsoft) | Hosting of the website and app files; no customer data | Global |
| Anthropic PBC | AI reading of bills, only when chosen by the firm | United States |
| Google Cloud | Vision OCR of pages, only when chosen by the firm | Global |
| GST Suvidha Provider | Connection to the GST portal, when used | India |
Bill images sent for AI reading are used only to read them. Anthropic and Google do not train their models on this data under their commercial terms.
Found a security problem?
Please tell us privately. We acknowledge within 3 working days, fix critical issues within 7 days, and will not take action against good-faith research that stays within our test site and your own account.