DribbleAudit
Security & privacy

Client confidentiality, by design.

Your clients' GST notices, books, and identity belong to you and them — not to us. Here's exactly how we protect it, and what you should know about AI processing.

Managed cloud infrastructure
Data stored on managed cloud infrastructure with encryption at rest and in transit. AI inference uses Anthropic (USA) transiently — no training on your data.
Encrypted everywhere
AES-256 at rest, TLS 1.3 in transit. Encryption keys managed via the cloud provider's KMS.
No AI training on your data
Anthropic's commercial API terms prohibit training on customer inputs. We don't use your data for training either.
Export + delete
Data export within 7 days of request. Workspace deletion wipes all data within 30 days (backups within 90 days), except logs required by law.
AI privacy

What the AI sees, what it remembers, what it forgets.

What we send to Anthropic
  • The notice PDF / position text / query you submit
  • Relevant corpus excerpts (Act sections, circulars, cases) fetched via tool-use
  • Your prompt — never your full client list or unrelated workspace data
What gets remembered
  • By Anthropic: inputs and outputs are retained for a limited operational period per their standard API policy (currently up to ~30 days; longer only for flagged content). No model training occurs on your data.
  • By us: the structured output (draft, Position Card, classification) stored in your workspace
  • By the AI in subsequent calls: nothing — every request is stateless
What gets deleted
  • Workspace deleted → all data + backups within 30 days (90 days for backups)
  • On request: targeted data export + deletion within 7 days
  • Logs retained 180 days per CERT-In Directions 2022; billing records per GST / Companies Act
Citation-verified by design

The corpus + tool-use loop means the AI can only cite sources we've verified. Every citation in every draft is checked post-generation; unverified cites are flagged with an amber chip and block exports by default. This is a process commitment — not a guarantee that every citation is applied correctly; you must review before filing.

Infrastructure

Where your data lives.

Application + database
Region
Asia-Pacific managed cloud
Database
Managed Postgres (encrypted at rest)
Backup
Daily automated, 30-day retention
High availability
Provider-managed availability SLA
File storage
Region
Asia-Pacific managed cloud
Provider
S3-compatible object storage
Encryption
AES-256 server-side
Pre-signed URLs
Short-lived, scoped to file
Authentication
Method
Email OTP (no passwords stored)
Tokens
Short-lived signed session tokens
Brute-force
Rate-limited at the API edge
Session
Per-device, revokable
Audit + observability
Audit log
Every notice action recorded
Admin actions
Workspace impersonation logged + visible
Webhook integrity
HMAC-SHA256 verified on inbound payloads
Error reporting
Structured logs, no PII in production
Compliance

What we comply with, what's your responsibility.

Aligned with the DPDP Act 2023, IT Act / SPDI Rules 2011, and CERT-In Directions 2022. SOC 2 / ISO 27001 certification is on our roadmap — we are not yet certified.
Our responsibility
  • Encrypt your data at rest and in transit
  • Store data on managed cloud infrastructure (Asia-Pacific region)
  • Never use your data to train AI models
  • Maintain backups and disaster-recovery procedures
  • Notify affected workspaces without undue delay on a confirmed breach; report to CERT-In (6 hours for covered incidents) and the Data Protection Board (72 hours) as required
  • Honor export + deletion requests within stated SLAs
  • Patch infrastructure dependencies regularly
  • Restrict employee access on a need-to-know basis
Your responsibility
  • Review every AI output before filing — we draft, you sign
  • Obtain your clients' consent before processing their confidential information through DribbleAudit, per ICAI's Code of Ethics
  • Keep your sign-in email + OTP code secure
  • Add team members thoughtfully — they get full workspace access
  • Cancel access for staff who leave your firm
  • Comply with ICAI's professional ethics + confidentiality standards
  • Maintain your own off-site backups for irreplaceable client docs
  • Report security issues to security@dribbleaudit.com

Report a security issue

Please don't post security issues publicly. Email us directly — we acknowledge within 2 business days (Mon–Sat) and aim to triage within 7 days. Good-faith research within scope will not result in legal action.

security@dribbleaudit.com
For general support or grievances, visit our Contact page.

Get a free trial. Cancel anytime.

14 days of full access to every product. No credit card required. See if DribbleAudit saves you a week — then decide.

Built in India · Every citation verified against official sources · No AI training on your data