Security

Your clients' books stay in India. Full stop.

Financial data belongs in India, on Indian servers, under Indian jurisdiction. Here's exactly how we protect it.

๐Ÿ‡ฎ๐Ÿ‡ณ

Data Residency โ€” India

All data is pinned to the ap-south-1 (Mumbai) AWS region. Your clients' financial documents never leave India.

๐Ÿ—๏ธ

Multi-Tenant Architecture

Every table carries a company_id. Supabase Row-Level Security (RLS) policies enforce that each user sees only their own company's data โ€” at the database level, not just the application layer.

๐Ÿ”

Encryption at Rest

All data stored on AWS is encrypted using AES-256. This is enforced at the infrastructure level by AWS, independent of our application code.

๐Ÿ”’

Encryption in Transit

All connections between your browser, our servers, and Supabase use TLS 1.3. HTTP connections are automatically redirected to HTTPS.

๐Ÿ‘ค

Authentication

Passwords are never stored by JadooBooks. Authentication is handled entirely by Supabase Auth, which uses bcrypt hashing and industry-standard session management.

๐Ÿ“‹

Audit Logging

Every significant action โ€” invoice posted, vendor updated, user login โ€” is logged with the actor identity, company context, and timestamp. Logs are immutable.

๐Ÿค–

AI & Your Data

We use Google Gemini API to process documents. We do not use your financial documents to train AI models. Document data is processed transiently and not stored by the AI provider.

๐Ÿข

Infrastructure

Built on Supabase (SOC 2 Type II certified) and Vercel. Both providers undergo independent security audits and maintain compliance certifications.

Have a security question?

We take security seriously and respond to all enquiries within 24 hours.

Contact security@jadoobooks.com