Last updated: September 2026

Security & Data Governance Guarantee

Confidentiality Commitment to CA Firms

At ReconDesk, we recognize that Chartered Accountants, tax practitioners, and finance professionals entrust us with their clients' most sensitive business data: purchase registers, sales invoices, vendor transaction histories, and GST returns.

Our security architecture is designed from the ground up to ensure strict confidentiality, tenant isolation, and regulatory compliance with Indian data protection laws, including the Information Technology Act, 2000 and the Digital Personal Data Protection (DPDP) Act, 2023.

Data Encryption Standards

All data processed by ReconDesk is protected by state-of-the-art cryptographic standards:

  • Encryption in Transit: All traffic between your browser and our servers is enforced over TLS 1.3 with 256-bit encryption. Plain HTTP requests are automatically upgraded and redirected.
  • Encryption at Rest: All database storage, document storage, and backups are encrypted using industry-standard AES-256 encryption.
  • Sovereign Indian Data Residency: ReconDesk infrastructure is deployed exclusively in AWS Asia Pacific (Mumbai, ap-south-1) data centers, ensuring your clients' financial records never leave Indian territorial borders.

Tenant Isolation & Access Control

Every Chartered Accountancy practice or business account on ReconDesk operates within an isolated tenant environment. Cross-firm data leakage is prevented at both the application logic level and database schema level:

  • Row-Level & Schema Isolation: Every database query requires verified organization and client identification. No firm can ever access or query another firm's records.
  • Role-Based Access Control (RBAC): Firms can manage staff access with granular permissions (Admin, Associate, Reviewer), ensuring team members only access assigned clients.

GSTN Credentials & Session Security

When you connect to the GST Portal via GSP/GSTN APIs:

  • Zero Password Storage: ReconDesk never asks for or stores your GST portal login passwords.
  • Ephemeral OTP Tokens: Authentication is conducted via standard GSTN OTP. Session tokens expire automatically after the statutory 6-hour window and are never logged or exposed.

Data Ownership & 1-Click Purge

You retain 100% ownership of all uploaded files, registers, and generated workpapers. ReconDesk will never sell, monetize, or use your client data to train machine learning models.

Firms can permanently purge raw upload files or delete entire reconciliation runs at any time. When purged, data is deleted irreversibly across all active storage partitions.

Reporting Security Vulnerabilities

If you discover a potential security vulnerability or have questions regarding data privacy and protection, please reach out directly to our security team at support@recondesk.in.

← Back to home