Client confidentiality, by design.
Your clients' GST notices, books, and identity belong to you and them — not to us. Here's exactly how we protect it, and what you should know about AI processing.
What the AI sees, what it remembers, what it forgets.
- •The notice PDF / position text / query you submit
- •Relevant corpus excerpts (Act sections, circulars, cases) fetched via tool-use
- •Your prompt — never your full client list or unrelated workspace data
- •By Anthropic: inputs and outputs are retained for a limited operational period per their standard API policy (currently up to ~30 days; longer only for flagged content). No model training occurs on your data.
- •By us: the structured output (draft, Position Card, classification) stored in your workspace
- •By the AI in subsequent calls: nothing — every request is stateless
- •Workspace deleted → all data + backups within 30 days (90 days for backups)
- •On request: targeted data export + deletion within 7 days
- •Logs retained 180 days per CERT-In Directions 2022; billing records per GST / Companies Act
The corpus + tool-use loop means the AI can only cite sources we've verified. Every citation in every draft is checked post-generation; unverified cites are flagged with an amber chip and block exports by default. This is a process commitment — not a guarantee that every citation is applied correctly; you must review before filing.
Where your data lives.
- Region
- Asia-Pacific managed cloud
- Database
- Managed Postgres (encrypted at rest)
- Backup
- Daily automated, 30-day retention
- High availability
- Provider-managed availability SLA
- Region
- Asia-Pacific managed cloud
- Provider
- S3-compatible object storage
- Encryption
- AES-256 server-side
- Pre-signed URLs
- Short-lived, scoped to file
- Method
- Email OTP (no passwords stored)
- Tokens
- Short-lived signed session tokens
- Brute-force
- Rate-limited at the API edge
- Session
- Per-device, revokable
- Audit log
- Every notice action recorded
- Admin actions
- Workspace impersonation logged + visible
- Webhook integrity
- HMAC-SHA256 verified on inbound payloads
- Error reporting
- Structured logs, no PII in production
What we comply with, what's your responsibility.
- Encrypt your data at rest and in transit
- Store data on managed cloud infrastructure (Asia-Pacific region)
- Never use your data to train AI models
- Maintain backups and disaster-recovery procedures
- Notify affected workspaces without undue delay on a confirmed breach; report to CERT-In (6 hours for covered incidents) and the Data Protection Board (72 hours) as required
- Honor export + deletion requests within stated SLAs
- Patch infrastructure dependencies regularly
- Restrict employee access on a need-to-know basis
- Review every AI output before filing — we draft, you sign
- Obtain your clients' consent before processing their confidential information through DribbleAudit, per ICAI's Code of Ethics
- Keep your sign-in email + OTP code secure
- Add team members thoughtfully — they get full workspace access
- Cancel access for staff who leave your firm
- Comply with ICAI's professional ethics + confidentiality standards
- Maintain your own off-site backups for irreplaceable client docs
- Report security issues to security@dribbleaudit.com
Report a security issue
Please don't post security issues publicly. Email us directly — we acknowledge within 2 business days (Mon–Sat) and aim to triage within 7 days. Good-faith research within scope will not result in legal action.
security@dribbleaudit.comGet a free trial. Cancel anytime.
14 days of full access to every product. No credit card required. See if DribbleAudit saves you a week — then decide.