Skip to content
Security

What we do to protect your data

Security pages usually list certifications. We hold none, so this page lists controls instead: what is actually implemented in Unnati today, and how to report a problem to us.

Controls

The controls we operate

Seven of them, each one a thing we can point at in the product rather than a policy in a document.

Data in transit is encryptedThe web application, the desktop application, the mobile application and the API all talk over encrypted HTTPS connections. Nothing your team submits travels in the clear between their device and our servers.
Backups are taken on a scheduleWe take regular backups of tenant data and test that they restore. We do not publish a frequency or a retention window on this page until the infrastructure team has confirmed the figure we can commit to, and we would rather say nothing than say something we cannot hold to.
Access is role and permission basedEvery user belongs to a role, and roles carry permissions per branch and per action. The permission to raise an e-invoice IRN is separate from the permission to raise the invoice, so compliance actions stay with the person accountable for them.
The audit trail is hash-chainedChanges are written to an audit log in which each entry is linked to the one before it. That makes a change made outside the application detectable rather than invisible, which matters when a rate or a quantity is disputed months later.
Two-factor authentication on our control panelThe internal control panel our own team uses to administer tenants requires two-factor authentication. It is the account with the most reach, so it carries the strongest control we operate.
Tenants are separatedThe backend is multi-tenant: your organisation identifier travels in the signed token on every request, and queries are scoped to it. One customer cannot read another customer’s records through the application.
Import and export stay in your handsYou can export your own data through the Import and Export Data screen at any time during your subscription. It is your data, and we do not treat an export request as a retention conversation.
Hosting

Where your data is kept

Unnati is a cloud application, and where it runs is a deployment choice rather than a fixed property of the product. For Indian customers we deploy into an Indian region, because that is what most of our customers ask for and because it keeps latency low for teams working across India.

If your contract or your own compliance obligation requires a specific region, or requires a written statement about where data is stored and processed, ask us before you sign. We will put the answer in writing rather than leave you to infer it from a marketing page.

We are not offering a data-residency guarantee here and we hold no residency certification. What we are describing is how we deploy today and what we are willing to commit to in a contract.

Vulnerability disclosure

Found a problem? Tell us

If you believe you have found a security vulnerability in Unnati, write to security@aavishkruti.com. Please include what you found, the steps to reproduce it, the environment you saw it on and the date and time, so we can trace it in our own logs.

We acknowledge every report within two working days and we tell you what we intend to do about it. We do not run a bug bounty and we pay no rewards, so please do not expect one. We will not pursue legal action against anybody who investigates in good faith, tells us privately first, gives us a reasonable period to fix the issue, and does not access, modify or destroy another customer’s data while doing so.

Please do not test on a live customer tenant, run denial-of-service tests, or use social engineering against our staff or our customers. Ask us and we will set up an environment.

Send it here

security@aavishkruti.com

For anything that is not a security issue, use the support page or the contact page instead, so a genuine vulnerability report is not queued behind a general question.

Aavishkruti
Ahmedabad
Gujarat 382470
India
Your side of it

Four things only you can do

Most incidents in small businesses are old access rather than clever attacks, and these four are where that gets decided.

Give each person their own login.

Shared logins destroy the value of the audit trail and make an investigation impossible.

Review roles when someone changes job and remove access on the day someone leaves.

Most incidents in small businesses are old access, not clever attacks.

Keep the e-invoice and payment permissions with the people who are accountable for them, rather than granting them to everybody to avoid a bottleneck.

Keep the e-invoice and payment permissions with the people who are accountable for them, rather than granting them to everybody to avoid a bottleneck.

Tell us immediately if you believe an account has been compromised, so we can help you close it rather than finding out later.

Tell us immediately if you believe an account has been compromised, so we can help you close it rather than finding out later.

Start where you are

Have a security question before you buy?

Send it to us in writing and we will answer it in writing, including where the answer is no.

Prefer to read first? The comparisons with Tally, Odoo, ERPNext and Zoho are written to be checked, not believed — each one names what the other product does better.