Trust

Security at Lekhita

Your bills, khata and customer list are your business. Here is exactly how we store and protect them — in plain words, with no claims we cannot back.

Your data stays in India

Lekhita's application servers run on Google Cloud in the asia-south1 (Mumbai) region, and our primary database is MongoDB Atlas hosted in Mumbai. Your business records are stored and processed in India.

Encrypted in transit

Every connection between the app and our servers uses TLS — the same transport encryption your bank uses. We never send your data over plain connections.

Personal data encrypted at rest

Personal-data fields — the details that identify a person — are encrypted with AES-256-GCM before they are written to the database. Someone with raw database access would still not read them.

Sign-in has no password to steal

Sign-in is a one-time code sent to your email, rate limited, with no password anywhere to guess or reuse. Sessions use short-lived tokens with protected refresh. On the device itself, a PIN lock (and a fingerprint where supported) keeps a shared counter phone from being an open door.

Backups

The primary database is backed up automatically through MongoDB Atlas, so a hardware failure does not become your data loss. Restore procedures are part of our launch checklist, and a public status page will follow early access.

A real deletion path

You can request deletion of your account and personal data at any time. We acknowledge within 3 business days and complete deletion within 30 days; invoices and GST records are retained for 7 years as tax law requires, in encrypted form.

What we do not claim

We do not hold ISO 27001 or SOC 2 attestations, and we do not publish an uptime SLA — availability is best-effort while we are in early access, and it will be backed by a public status page as we exit. Two more, because they are the ones people assume: the app has no activity log, so it cannot show you who did what inside your business; and staff cannot yet sign in with their own accounts, which is why the answer to “how do I stop my cashier seeing my numbers” is currently a PIN-locked shop device rather than a separate login. Security pages that promise everything are usually hiding something; ours will grow only as fast as the facts do.

Data protection & grievances

Tanvrit Pvt. Ltd. is the data fiduciary under India's DPDP Act. For any privacy concern, data request, or grievance, write to our data protection officer:

dpo@tanvrit.com

168 Plot No 945, Gayatri Mandir se Purab, New Ariya, Sasaram, Bihar 821115, India. The full policy is at /privacy/; deletion is documented at /account/delete/.

Found a vulnerability?

If you have found a security issue in Lekhita — the app, this site, or our APIs — please tell us before telling anyone else. Email dpo@tanvrit.com with steps to reproduce. We read every report, we will respond, and we will never take legal action against good-faith research.