Your compliance evidence, handled carefully.
ComplianceStack becomes your system of record for sensitive statutory documents — so investors and their lawyers will ask how the tool itself handles data. This page describes our current practices and what's on our roadmap. It reflects how the product is built today; it is not a contractual commitment.
Where your data lives
Your data is stored in a managed Postgres database and file store hosted in India (ap-south-1, Mumbai), with the application running on Vercel. Data residency in-region matters for Indian companies and their counsel.
Encryption
All traffic is encrypted in transit over HTTPS/TLS. Data and uploaded documents are encrypted at rest by our managed database and storage providers.
The evidence vault
Uploaded documents live in a private storage bucket with no public access. The app serves them only through short-lived signed URLs to authorised users — there are no public file links. Diligence-pack exports are generated on demand for an admin; the read-only investor link you can share shows status only, never the underlying files.
Access control & tenancy
Every company's data is isolated. Access is enforced by role-based permissions scoped per company — your CA, CS, lawyer or payroll vendor sees only their bucket. Database row-level security denies the public API key, so no browser key can read another company's data. Read-only diligence links are time-boxed and revocable.
Authentication
Sign-in is handled by a managed auth provider (Supabase). Sign-in, sign-up and password-reset forms are protected by Cloudflare Turnstile bot mitigation. Application secrets are stored encrypted and are never exposed to the browser.
How we use AI
AI never decides what compliance applies to you— that's a deterministic, versioned rules engine. The AI only classifies documents, extracts fields, summarises notices and drafts reports, and every interpretive answer carries a “confirm with your CA, CS, or lawyer” disclaimer. We do not use your data to train AI models.
Your control over your data
Export an organised diligence pack of your records at any time. Deleting a company removes its tasks, documents and evidence. You can revoke any read-only share link instantly.
Subprocessors
We rely on a small set of vetted providers to run the service:
- Supabase — Managed Postgres database, authentication, and the evidence file store (ap-south-1, Mumbai).
- Vercel — Application hosting and serverless compute.
- Cloudflare — DNS and bot protection (Turnstile) on sign-in / sign-up.
- Resend — Transactional email (sign-in, reminders, advisor invites).
- Razorpay — Subscription billing (used only if you subscribe).
- Anthropic & OpenAI — AI that classifies documents, extracts fields, summarises notices and drafts reports.
- Meta (WhatsApp) — Reminder messages — only if you opt in and add a number.
Compliance roadmap
We are building toward SOC 2 and ISO 27001, and aligning with India's Digital Personal Data Protection (DPDP) Act. To be clear: we are not yet certified— this is our direction, and we'll update this page as we reach each milestone.
Questions, or a security concern to report? Email security@compliancestack.in.