Security & Compliance

Your clients trust you.
You can trust Caledger.

As a CA, you hold your clients' most sensitive financial data. We hold it with the same seriousness - using the same encryption standards as Indian banks, with your client data stored on servers in India. (Some operational sub-processors - for example captcha-solving, transactional email and web-push delivery - may process limited data.)

AES-256 Encrypted
Data stored in India
DPDP Act 2023 Compliant
ICAI-aligned workflows

Bank-Grade Encryption

All data travels over TLS-encrypted connections (HTTPS everywhere). Login passwords are stored only as one-way salted hashes (bcrypt) - never in readable form. Deleted client records are protected with AES-256-GCM, the same encryption standard used by RBI-regulated Indian banks, and every firm's data is strictly isolated behind server-verified sessions.

Your password is never stored in readable form - not even our own engineers can see it.

🇮🇳

Data Stored in India

Your firm's core data is hosted on Indian cloud infrastructure and stored in India. A few operational sub-processors (captcha-solving, transactional email and web-push delivery) may process limited data outside India. This supports compliance with the Digital Personal Data Protection (DPDP) Act 2023 and RBI's data localisation requirements.

Infrastructure: Mumbai, India - client data stored in India.

Firm-Level Data Isolation

Every CA firm on Caledger is a completely isolated tenant at the database level. Your clients, filings, notes, and credentials are separated by firm ID across every table, query, and API call - making cross-firm data access technically impossible.

No other CA firm can ever see your data - not even by accident.

Role-Based Access Control

Three-tier access model: Admin (firm owner - full access), CA (senior staff - can approve filings), Staff (juniors - see only assigned clients). Every action requires the appropriate role. Status updates by staff require admin approval.

Aligns with ICAI's professional hierarchy and supervision requirements.

Full Audit Trail

Every action in Caledger - filing status change, client note, staff login, approval or rejection - is logged with user ID, timestamp, and IP address. This immutable audit trail meets ICAI's professional record-keeping standards and supports peer review.

Who did what, when - always available and tamper-proof.

🚫

Zero Data Selling - Ever

We do not sell, share, licence, or analyse your client data for any external purpose - not for advertising, not for third-party analytics, not for machine learning. Your firm's data exists solely to run your Caledger account.

You own your data. Export everything. Cancel anytime.

Compliance & Roadmap

Current and roadmap certifications for CA firms and ICAI

✅ Active
DPDP Act 2023
Digital Personal Data Protection Act - India's primary data privacy law
✅ Active
HTTPS / TLS
Encrypted in transit over HTTPS/TLS
🔜 In Progress
ISO 27001
Information Security Management certification - In Progress
🔜 Planned
SOC 2 Type I
Security, availability and confidentiality audit by independent auditor

Verified Indian Business

Entity Name
Caledger
GSTIN
Under Registration
Registered Office
Bengaluru, Karnataka

Questions about how we protect your data? We answer every security question personally.

Ask a Security Question Read Privacy Policy