Security

Your company's data, handled with care.

corpdesk holds the things that define your company — CIN, PAN, GST, bank and director details. Protecting them isn't a feature bolted on the side. It's how the product is built.

Encrypted at rest & in transit Append-only audit trail Least-privilege access
YOUR COMPANY DATACINPANGSTencryptedOFFICIAL REGISTRIES · TLSMCAGSTITROCTRACES
How we protect it

Six things we do, on every request.

Encryption

Encrypted at rest & in transit

Your company data is encrypted on disk in managed storage and moves over TLS on every request. Nothing sensitive travels or sits in the clear.

Access control

Least-privilege access

Every request is authorised before anything is read or written. Members and your accountant get distinct, verified access — nobody sees more than their role allows.

Audit logging

An append-only trail

Every create, update and delete on sensitive data is recorded — who, what, when, where, and the before/after. Audit logs are immutable and only added to.

Data minimisation

Only what's needed

We fetch and return the narrowest set of fields an operation requires. We don't compile profiles across sources or hold data a task doesn't call for.

Infrastructure

Managed, hardened hosting

corpdesk runs on managed cloud infrastructure (Supabase / Postgres) with encryption at rest, network isolation and routine patching handled by the platform.

Session security

Secure sessions & CSRF

Authentication uses secure, httpOnly session cookies with CSRF protection and rate-limited auth endpoints — so a session can't be lifted or replayed.

Our posture

Enterprise discipline, founder simplicity.

We don't ask you to trust a badge. We ask you to look at how the system is built and how your data is handled.

Framework

Built to ISO 27001 / SOC 2 principles

We design and operate to the controls behind ISO 27001 and SOC 2 — access control, audit trails, encryption and data-handling discipline — as our working baseline, not an afterthought.

India data handling

For Indian companies

corpdesk is built around Indian regulatory data — CIN, PAN, GST, ROC, TDS. We handle it with the care the Indian company records deserve and keep processing to what the service needs.

PII care

Sensitive data, treated as sensitive

Company identifiers, bank details and director information are treated as PII throughout — minimised, access-controlled, encrypted, and never placed in URLs or logs in the clear.

A note on certifications: corpdesk is built to ISO 27001 and SOC 2 principles. We describe our posture, not certificates we can't yet show — and we'll say so plainly the day that changes.

What we read

Official registries, over secure channels.

corpdesk watches your company across India's statutory registries. Every lookup goes over an encrypted connection, and results are cached only as long as they stay useful.

MCAGSTIncome TaxROCTRACES
TLS on every registry call · cached only while current
Responsible disclosure

Found something? Tell us.

If you believe you've found a security vulnerability, we want to hear from you before anyone else does. Email security@corpdesk.in with the details and we'll acknowledge and investigate. Please give us reasonable time to fix before disclosing publicly.

Report a vulnerability
Questions

What founders ask about security

Who can see my company's data?

Only you, the members you invite, and the accountant assigned to your organisation — each through verified, least-privilege access. Every request is authorised first, and every action on sensitive data is logged.

Is my data encrypted?

Yes. Data is encrypted at rest in managed storage and in transit over TLS. Sensitive identifiers are never placed in URLs, query strings or logs in the clear.

Do you sell or share my data?

No. We don't sell your data or share it for advertising. We access official registries on your behalf to run the service, and we minimise what we fetch and keep to what the task needs.

Where is it hosted?

On managed cloud infrastructure (Supabase / Postgres) with encryption at rest, network isolation and platform-managed patching. We build to ISO 27001 and SOC 2 principles as our baseline.

Data you can trust us with. Decisions only you make.

Onboard your company free in two minutes. See your compliance state — held with the care it deserves.