Security · what's actually in place
What stands between your data and trouble.
Most security pages describe an ambition. This one describes what is running today — no more, and in plain words.
One shop can never see another
Every shop's data is held separately from every other shop's. That separation is structural, not a setting someone can get wrong — there is no shared table where a stray query could reach across shops, and nothing in the product can look from one shop into another.
We keep the specifics of how that is built to ourselves. What matters to you is the effect: your shop's records are reachable only by the people you have given access to.
Getting in
- Sign in with a one-time code sent to your email, or with your Google or Apple account. A password is optional, not required.
- A sign-in lasts 24 hours. After that, you sign in again.
- A new phone has to be approved by the owner before it can open shop data — useful when the phone belongs to the person rather than the shop.
- The owner can sign a user out of every device at once, immediately. A lost or handed-over phone stops being a problem the moment you say so, not at the end of the day.
- Optional biometric lock on the app itself.
Who can reach what
- Roles. Owner, admin, manager, staff and worker each reach only what that job needs. You set this per shop.
- Pia works inside the same limits. The assistant can never do something the person asking it isn't allowed to do. That boundary is enforced by the system, not by asking Pia nicely.
- Nothing consequential happens without approval. Pia drafts; a person approves. There is no path where your books change on their own.
A record of what was done
Consequential actions — a bill made, a draft approved, a user added, a role changed — are recorded with who did it and when. You can see that record, and it is kept for as long as the law requires the underlying documents to be kept.
Your data is not our training data
We don't train models on your shop's data without a written, separately-given yes, and that opt-in is never bundled with getting a feature. See privacy and our DPDPA 2023 statement.
Found a problem? Tell us
Email [email protected] with the subject “Security disclosure.” We reply to everything within a working day, we won't come after good-faith research that follows reasonable disclosure norms, and we'll credit you publicly once a fix is out if you'd like us to.
We don't run a paid bug bounty. We do take every responsibly-disclosed finding seriously and acknowledge it properly.
What you can do today
- Review your team's roles in Settings — remove access for anyone who no longer needs it.
- Check the approved-devices list, and remove any phone that has left the shop.
- Export your GST returns and registers every quarter. Even if you trust us, an offline copy is a good thing for any careful CA to have.