Your compliance evidence, handled carefully.
ComplianceStack becomes your system of record for sensitive statutory documents — so investors and their lawyers will ask how the tool itself handles data. This page describes our current practices and what's on our roadmap. It reflects how the product is built today; it is not a contractual commitment.
Where your data lives
Your data is stored in a managed Postgres database and file store hosted in India (ap-south-1, Mumbai), with the application running on Vercel. Data residency in-region matters for Indian companies and their counsel.
Encryption
All traffic is encrypted in transit over HTTPS/TLS. Data and uploaded documents are encrypted at rest by our managed database and storage providers.
The evidence vault
Uploaded documents live in a private storage bucket with no public access. The app serves them only through short-lived signed URLs to authorised users — there are no public file links. Diligence-pack exports are generated on demand for an admin; the read-only investor link you can share shows status only, never the underlying files. Uploads are size-capped per file and bounded by a per-plan storage allowance (visible on your billing page); files sit on durable, replicated object storage, and your records are backed up daily by our managed database provider.
Access control & tenancy
Every company's data is isolated. Access is enforced by role-based permissions scoped per company — your CA, CS, lawyer or payroll vendor sees only their bucket. Database row-level security denies the public API key, so no browser key can read another company's data. Read-only diligence links are time-boxed and revocable.
Authentication
Sign-in is handled by a managed auth provider (Supabase). Sign-in, sign-up and password-reset forms are protected by Cloudflare Turnstile bot mitigation. Application secrets are stored encrypted and are never exposed to the browser.
How we use AI
AI never decides what compliance applies to you— that's a deterministic, versioned rules engine. The AI only classifies documents, extracts fields, summarises notices and drafts reports, and every interpretive answer carries a “confirm with your CA, CS, or lawyer” disclaimer. We do not use your data to train AI models, and our AI providers do not train on data sent through their APIs.
The compliance inbox (optional, rolling out)
We're rolling out an optional email-forwarding inbox — it's off until you turn it on. When enabled, each company gets an unguessable forwarding address; emails you forward there are classified and matched to the right task as evidence or turned into a notice. We verify the inbound webhook's signature, store the email under your company only, and never expose the address publicly.
Your control over your data
Export an organised diligence pack of your records at any time. Deleting a company removes its tasks, documents and evidence. You can revoke any read-only share link instantly.
Subprocessors
We rely on a small set of vetted providers to run the service:
- Supabase — Managed Postgres database, authentication, and the evidence file store (ap-south-1, Mumbai).
- Vercel — Application hosting and serverless compute.
- Cloudflare — DNS and bot protection (Turnstile) on sign-in / sign-up.
- Resend — Transactional email — sign-in, reminders, advisor invites (and inbound email if you turn on the optional compliance inbox).
- Sandbox (Quicko) — GST/MCA verification — we send a GSTIN or CIN and receive public registry data; your documents are never sent.
- Razorpay — Subscription billing (used only if you subscribe).
- OpenAI (and Anthropic where enabled) — AI that classifies documents, extracts fields, summarises notices and drafts reports — the providers do not train on it.
- Meta (WhatsApp) — Reminder messages — only if you opt in and add a number.
Compliance roadmap
We are building toward SOC 2 and ISO 27001, and aligning with India's Digital Personal Data Protection (DPDP) Act. To be clear: we are not yet certified— this is our direction, and we'll update this page as we reach each milestone.
Questions, or a security concern to report? Email security@compliancestack.in. We'll acknowledge responsible disclosures and work with you on a fix.
ComplianceStack is operated by Ventuno Technologies Private Limited, Chennai, Tamil Nadu, India.