Security

Bank-Level Security. Your Data, Your Control.

  • We never ask for your net-banking username or password — ever.
  • Bank account numbers are never stored in plain text — one-way cryptographic hashing.
  • Secure OTP-based login — no passwords to remember or leak.
  • Every billing and access event is permanently logged in an audit trail.
  • Built in line with India's Digital Personal Data Protection (DPDP) Act, 2023.

How It Works

Your account number is never stored — only a fingerprint of it

When you upload a statement, we need a reliable way to tell your accounts apart and to spot duplicate uploads — but we don't need, and never keep, your actual bank account number. Instead, we compute a one-way fingerprint of it.

Each account number is run through SHA-256, a standard cryptographic hash, together with a secret server-side pepper — an extra secret value held only on our servers, never stored alongside your data. The result is a fixed, irreversible string. The same account always produces the same fingerprint, so we can match and de-duplicate it, but the fingerprint cannot be reversed back into your account number. Even if someone obtained the stored fingerprints, they could not work out the original numbers, and without the pepper they cannot even test guesses against them.

In plain terms: we can recognise your account the way you'd recognise a signature — without ever writing down the number itself.


Audit Trail

An append-only ledger — nothing is silently altered or erased

Every billing event and sensitive access action is written to an append-only audit ledger. "Append-only" means entries can only ever be added — never edited or deleted after the fact. Each action leaves a permanent, timestamped record.

This gives you a trustworthy history you can rely on: who did what, and when. If a payment was made, an account was accessed, or a permission changed, there is a durable record of it that cannot be quietly rewritten. It's the same principle a paper ledger relies on — you add new lines, you never scrub out old ones.


Data Durability

Soft-delete architecture — your financial history is never accidentally lost

When something is deleted in Cashflow Evaluator, it isn't immediately wiped from existence. We use a soft-delete approach: the record is marked as removed and hidden from your everyday views, but it is preserved behind the scenes rather than destroyed on the spot.

This protects you from the most common cause of lost financial data — an accidental click. A mistaken deletion doesn't vanish your history; it can be recovered. Your books stay intact, and removals are deliberate and reversible rather than instant and permanent.


Compliance

Built in line with India's DPDP Act, 2023

Cashflow Evaluator is built in alignment with India's Digital Personal Data Protection (DPDP) Act, 2023. We practise data minimisation — collecting only what's needed to give you cashflow clarity — and the protections described on this page (hashing, audit logging, and reversible deletion) are part of how we honour that.

The full, authoritative detail lives in our policy documents:


Get Started

Your numbers, kept safe. Ready when you are.

Join Indian MSMEs who've stopped guessing and started seeing.

No credit card required