Security & Compliance

Your clients' data is safe. We mean it.

Aalekh is built with security as a first principle — not an afterthought. Every feature that touches data is encrypted, logged, and access-controlled.

256-bit SSL EncryptionZero data breach incidents

Password Encryption Layer

All user passwords in Aalekh are encrypted using industry-standard bcrypt hashing with salting. Even Aalekh's own team cannot read stored passwords. Additionally, an extra application-layer encryption wraps all authentication tokens, ensuring that session compromise does not expose account data.

  • bcrypt + salt password hashing
  • Application-layer token encryption
  • Automatic session expiry
  • Failed login attempt detection and lockout
Password
Hash (bcrypt + salt)
Encrypted Token
Secure Access
Audit Trail

Complete Audit Logs — For Employees and Clients

Every action taken inside Aalekh — by your team members or your clients — is recorded in an immutable audit log. Know exactly who did what, when, and from which device. Perfect for compliance reviews, dispute resolution, and internal oversight.

  • Employee audit log: every login, entry, edit, and export tracked
  • Client audit log: document access, approvals, and signatures logged
  • Timestamped and IP-tagged entries — tamper-proof
  • Exportable audit reports for compliance or legal review
  • Role-based log visibility — managers see team logs, clients see their own
Recent activity
TimestampUserActionModuleIP Address
14 May, 10:32 AMRavi (Staff)Edited invoice #1042Invoicing103.x.x.x
14 May, 10:45 AMMehta TextilesDownloaded GSTR-3BGST Portal202.x.x.x
14 May, 11:02 AMPriya (Staff)Exported audit logSecurity103.x.x.x
Infrastructure

Data Security Built for Financial Firms

Aalekh's infrastructure is designed to meet the standards that CA firms and financial businesses require — not just standard SaaS security.

End-to-End Encryption

All data in transit and at rest is encrypted using TLS 1.3 and AES-256.

Secure Cloud Infrastructure

Hosted on AWS with multi-region redundancy, automated backups every 6 hours, and 99.9% uptime SLA.

Zero-Knowledge Architecture

Client financial data is isolated per tenant. No cross-client data access is possible - even internally.

DPDP Act Compliance

Designed to comply with India's Digital Personal Data Protection Act. Data residency in India. Right to erasure supported.

Role-Based Access Control

Define exactly what each team member and client can see, edit, or export. Granular permissions per module.

Online + Offline Security

Offline data is encrypted locally and only decrypts after authenticated sync - no raw data stored on device.

Works Everywhere — With or Without Internet

Aalekh is built as an offline-first application. Your team can continue entering data, creating invoices, and managing tasks without any internet connection. When connectivity is restored, all changes sync automatically and securely.

  • Offline mode for data entry, invoicing, and task management
  • Conflict resolution engine handles simultaneous edits
  • Offline data encrypted locally — not accessible without authentication
  • Auto-sync in background when internet is detected
  • No data loss — ever

Offline

Data stored locally, encrypted

Online

Auto-sync to secure cloud

Trusted by CA firms handling sensitive client data

“We reduced GST stress completely and now track everything as it happens.”

Vikram Mehta

Founder, Mehta Textiles

“Our reconciliation used to take 3 days. With Aalekh, it's done in under 10 minutes with complete accuracy.”

Sneha Kapoor

CFO, BrightPath Logistics

“As a CA firm managing 200+ clients, client data security is non-negotiable. Aalekh's audit logs give us full visibility.”

CA Rajesh Iyer

Iyer & Associates

Security Q&A

Have security questions before signing up?

Common questions about how Aalekh protects your firm and your clients' data.

All client financial data is hosted on AWS with data residency in India and multi-region redundancy. Backups run automatically every 6 hours, and our infrastructure is designed to comply with India's Digital Personal Data Protection (DPDP) Act, including support for the right to erasure.
No. Passwords are stored using bcrypt hashing with salting, so even our own team cannot read them. Client financial data is isolated per tenant under a zero-knowledge architecture, meaning no cross-client access is possible — even internally.
Every action — by your team members or your clients — is recorded in an immutable, timestamped, IP-tagged audit log. You can export audit reports for compliance or legal review, and visibility is role-based: managers see team logs while clients see their own.
Yes. Offline data is encrypted locally and only decrypts after authenticated sync — no raw data is stored on the device. When connectivity returns, changes sync automatically and securely, with a conflict resolution engine handling simultaneous edits so you never lose data.
Data in transit and at rest is encrypted using TLS 1.3 and AES-256. Authentication tokens are wrapped in an additional application-layer encryption, and sessions expire automatically with failed-login detection and lockout.

Talk to our security team

Our team will walk you through our security architecture in detail.