Skip to main content

Security and trust

Security and trust by design

The privacy, access, evidence, audit, and professional-boundary principles guiding a safer financial certification platform.

Public pages
No financial-document collection
Protected access
Role plus relationship
Authority
Independent CA decision
S / 10Evidence over claims
Shielded customer session with identity and access checkpoints
Identity · Purpose · Relationship · Audit

Claim boundary

Security claims stop where evidence stops.

This page describes implementation principles and production targets—not an external security certification, completed audit, regulatory approval, or guarantee. A control is represented as live only after it is implemented and tested.

Trust architecture

Access depends on role, purpose, and relationship

Identity alone does not grant access to every resource or action.
01

Relationship-aware access

Customers see their own resources; panel CAs see eligible assigned work; operational access stays explicitly scoped.

02

Protected evidence handling

Uploads are intended to pass through private quarantine, content checks, malware scanning, protected versions, and authorized downloads.

Future document workflow
03

Append-only accountability

Facts, revisions, status changes, professional decisions, and final artifacts are designed to remain attributable.

04

Regional data posture

Production sensitive-data services target an India region, subject to provider, legal, and deployment validation.

Production target

Authorization path

Every protected action needs context

  1. 01

    Identity

    Who is making the request?

  2. 02

    Role

    What category of action is eligible?

  3. 03

    Relationship

    Which exact resource is in scope?

  4. 04

    Purpose

    Why is the data needed now?

  5. 05

    Audit

    What durable record is created?

Data behavior

Private by default is system behavior

A lock icon is not a privacy model. Collection, logs, assistance, and failures each need explicit limits.
01

Collect less

Public pages request no financial, identity, or document data. Private collection begins only with a stated purpose.

02

Log safely

Secrets, OTPs, tokens, raw documents, PAN, payment secrets, and signed URLs must not enter application logs.

03

Constrain assistance

OCR or AI output remains an untrusted, attributable suggestion and cannot approve a financial or professional outcome.

04

Fail without leaking

Errors expose a recovery path without disclosing diagnostics, resource existence, or another person’s data.

Professional boundary

Technology does not inherit professional authority

CA

CA authority

Only a verified, eligible practising CA assigned to the request may make the intended certification decision.

U

UDIN integrity

The UDIN is CA-controlled. The platform records and links it under approved rules; it does not pre-generate it.

V

Truthful verification language

A platform record must never be presented as automatic ICAI verification or ICAI endorsement.

Safe next step

Understand the product boundary before sharing data.

See the product model