1.Security Principles
Our security program is based on three core principles:
| Confidentiality | Information should be accessible only to authorized users and systems. |
|---|---|
| Integrity | Information should be protected against unauthorized alteration or manipulation. |
| Availability | Authorized users should be able to access services when required, subject to maintenance and service availability. |
2.Access Control
Cashflow uses access-control measures designed to limit access to authorized users.
Controls may include:
- User authentication;
- Role-based access control;
- Least-privilege access;
- Organization-level access restrictions;
- Administrative access controls;
- Session management;
- User access reviews;
- Audit logs.
Employees and service personnel are granted access only where required for legitimate business purposes.
3.Authentication
We implement appropriate authentication controls for application and administrative access.
Users are expected to:
- Maintain secure credentials;
- Never share passwords;
- Use strong passwords;
- Report suspected account compromise;
- Follow additional authentication requirements where enabled.
4.Encryption
Where technically applicable, Cashflow uses encryption mechanisms to protect information during transmission.
Sensitive information should be protected using appropriate encryption and secure communication protocols.
Data-at-rest protection may also be applied depending on the infrastructure, database and service involved.
5.Financial Data Confidentiality
Cashflow treats accounting and financial records as confidential business information.
Examples include:
- Ledgers;
- Vouchers;
- Receipts;
- Payments;
- Invoices;
- Loan information;
- Debtor and creditor records;
- Financial statements;
- Customer information;
- Accounting reports.
Access to such information is restricted according to authorization and business need.
6.CA and Professional Confidentiality
Where Cashflow is used by Chartered Accountants, CA firms or professional organizations, customer information may include confidential client information.
Cashflow therefore supports confidentiality principles relevant to professional relationships.
Cashflow does not claim to replace the professional confidentiality obligations of a CA or CA firm. Customers remain responsible for complying with their professional obligations.
7.Infrastructure Security
Our infrastructure is designed to use appropriate controls such as:
- Network access restrictions;
- Secure hosting configurations;
- Firewall and perimeter controls;
- Database access controls;
- Monitoring;
- Logging;
- Backup procedures;
- Vulnerability management;
- Patch management.
The exact controls may vary according to the infrastructure and service architecture.
8.Application Security
Security considerations are incorporated into application development and maintenance.
Depending on the service, controls may include:
- Server-side authorization;
- Input validation;
- Secure API design;
- Authentication and session controls;
- Rate limiting;
- Protection against common web vulnerabilities;
- Dependency updates;
- Code review;
- Security testing.
9.Logging and Monitoring
Security and operational events may be logged and monitored to:
- Detect unauthorized activity;
- Investigate security events;
- Maintain service reliability;
- Troubleshoot failures;
- Support audit requirements.
Logs are protected against unauthorized access and retained according to applicable operational, legal and security requirements.
10.Backups and Recovery
Where applicable, Cashflow maintains backup and recovery mechanisms designed to reduce the risk of data loss.
Backup procedures may include:
- Regular backups;
- Access restrictions;
- Backup integrity checks;
- Recovery testing;
- Appropriate retention periods.
11.Vulnerability Management
We seek to identify and address security vulnerabilities through:
- Software updates;
- Dependency management;
- Security reviews;
- Vulnerability scanning;
- Security testing;
- Monitoring of relevant security advisories.
Critical vulnerabilities are prioritized according to risk.
12.Employee and Contractor Security
Personnel who may have access to confidential information are expected to follow confidentiality and security requirements.
Access is limited according to job responsibilities and business necessity.
Where appropriate, personnel may be subject to confidentiality obligations.
13.Data Protection
Cashflow maintains organizational and technical measures intended to protect personal data and confidential information.
Where applicable, our processing practices are designed to support compliance with India’s Digital Personal Data Protection framework.
14.Security Incident Response
Cashflow maintains procedures for identifying, assessing, containing, investigating and responding to security incidents.
Depending on the incident, response activities may include:
- Detection;
- Initial assessment;
- Containment;
- Investigation;
- Remediation;
- Recovery;
- Root-cause analysis;
- Customer or regulatory notification where required.
15.Responsible Disclosure
If you discover a potential security vulnerability in Cashflow, please report it responsibly rather than attempting to exploit it.
| Security Contact | whhoohh@gmail.com |
|---|
Please include:
- Description of the issue;
- Affected URL or feature;
- Steps required to reproduce the issue;
- Potential impact;
- Relevant screenshots or technical information where appropriate.
Do not include passwords, access tokens, financial records or other unnecessary confidential information in the initial report.
16.Third-Party Services
Cashflow may rely on third-party infrastructure, integrations and service providers.
Third-party access is limited according to the applicable service requirements and contractual arrangements.
Where third parties process customer information, appropriate contractual and security controls should be maintained.
17.Customer Security Responsibilities
Security is a shared responsibility.
Customers should:
- Use strong passwords;
- Restrict access to authorized personnel;
- Regularly review users and permissions;
- Secure their devices;
- Keep browsers and operating systems updated;
- Protect API credentials and integration credentials;
- Avoid sharing confidential reports through unsecured channels;
- Immediately report suspected unauthorized access.
18.Security Limitations
No internet-based system can guarantee absolute security.
Cashflow continuously works to reduce security risks, but cannot guarantee that unauthorized access, cyberattacks or security incidents will never occur.
19.Security Updates
This Security Policy may be updated as our infrastructure, security controls, legal requirements and security practices evolve.
The latest version will be published on this page.
20.Contact
| Security Contact | whhoohh@gmail.com |
|---|---|
| Privacy Contact | whhoohh@gmail.com |
| Organization | Cashflow |
| Address | Available on request |
For security incidents, please use the dedicated security contact rather than publicly posting vulnerability details.