Security & Trust Center

Enterprise Architecture for Data Fiduciaries.

We provide a hardened, DPDP-aligned infrastructure designed specifically for Indian Chartered Accountants handling sensitive financial PII.

Cryptographic & Compliance Architecture

Our platform relies on verifiable, industry-standard mechanisms to protect data at rest and in transit.

Server-Side Envelope Encryption

Client documents are never stored in plaintext. We implement Application-Layer Encryption using AES-256-GCM before writing to storage.

  • Files stored as encrypted binary blobs
  • Strict in-memory decryption
  • No-store cache controls prevent browser caching

Immutable Access Logging

To fulfill DPDP auditing requirements, decryption events generate strict access logs enforced by Postgres Row Level Security (RLS).

  • Append-only SQL tables
  • Logs timestamp, user ID, and document ID
  • Fail-safe aborts decryption if logging fails

AI Sandboxing

Document extraction relies on Google Cloud Vertex AI infrastructure. We mathematically sandbox models to prevent prompt-injection attacks.

  • Explicitly disabled tool-calling
  • Strict JSON schema enforcement
  • Adheres to GCP Enterprise processing terms
// India DPDP Act Ready

You are the Data Fiduciary.
We are the Data Processor.

Our architecture ensures you comply with the 7-year statutory retention laws via Soft Deletes, while strictly controlling access via our Zero-Knowledge storage.

Review our Data Processing Agreement →

Ready to secure your firm's follow-ups?

Join the forward-thinking Indian CA firms using ClockingPulse to eliminate manual WhatsApp chasing and guarantee DPDP-compliant workflows.