ITC sitting in Mismatch & No Match doesn't recover itself. Talk to us

Security

Built for enterprise security requirements.

GSTITC ingests Purchase Register and GSTR-2A data, financial data that belongs to your organisation. This page is for InfoSec and procurement. It states what is true today, not a roadmap dressed as a control.

1. Data handling

What leaves your systems, where it lives, and for how long.

Hosting. Client data is hosted in India on cloud infrastructure, DigitalOcean and AWS, depending on the engagement. Data does not leave India. If your policy requires it, you can bring your own database in your VPC; GSTITC then connects to you, and the books never sit on our tenancy.

What we collect. For a cycle we need the Purchase Register and GSTR-2A / ITC extracts at invoice-line grain: GSTIN, vendor GSTIN, invoice number, date, invoice type, taxable value, tax rate, and tax. That is what the matching engine runs on. We do not need your full ERP, payroll, or unrelated ledgers.

How it is transmitted. Intake is a structured file handoff with your GST cell, not a self-serve public upload. Formats and field mapping are covered on How it works: data intake.

Retention. How long books are kept, and when they are deleted, is set in the commercial agreement for that engagement. You can request deletion of your data at any time, including at the end of the engagement.

2. Encryption and infrastructure

Encrypted at rest and in transit. Backups included.

At rest. AES-256 on the database, on file storage used for intake extracts, and on backups of that data. No raw financial extract is left unencrypted on disk.

In transit. TLS 1.2 minimum on every connection into the application. No raw financial data is accessible outside the application layer.

Backups. Backups of hosted data are encrypted with the same at-rest standard and stored in India. If you bring your own database, backup schedule, location, and encryption stay under your existing policy, and we do not take a second copy out of your VPC.

3. Access control

Scoped to the engagement. Logged. Not standing admin.

Your users. Role-based access control is configured per GSTIN / entity during onboarding and reviewed with your IT or InfoSec team. A user in one state entity does not see another state's books, even inside the same group.

GSTITC personnel. Only people required to deliver that engagement can see that client's books. There are no shared credentials and no standing admin access from our side in production. Access is granted for the engagement, reviewed with you, and revoked when the person leaves the engagement or the company.

Audit log. Login, data upload, classification run, export, and vendor communication are logged with user identity, timestamp, and data scope. Logs are available to your administrators on request. Retention of logs is set with the rest of the engagement in the commercial agreement.

4. Subprocessors

Who can touch client reconciliation data.

Enterprise reviews ask for this list. Here it is. Analytics on this marketing site do not see your purchase register.

PartyPurposeClient data
DigitalOceanApplication hosting in IndiaApplication layer. Reconciliation data where the engagement is not on a client-owned database.
Amazon Web ServicesCloud infrastructure in India; optional client-owned RDS / AuroraSame as above, or data that remains in your VPC when you bring your own database.
Microsoft 365, Google Workspace, or your SMTPVendor outreach, when you connect your own mailboxException emails sent from your domain. Replies land in your inbox. We do not send vendor mail from a GSTITC address.

Deployment options

Your infrastructure. Your email.

For organisations where data must not leave their own infrastructure, or where vendor outreach must run from a corporate domain, GSTITC supports both.

Bring your own database

Connect your own cloud database, AWS RDS, Azure SQL, or GCP Cloud SQL. Your ITC reconciliation data never leaves your infrastructure. GSTITC connects to your DB; you retain full ownership, backups, and access controls.

  • AWS RDS / Aurora
  • Azure SQL Database
  • GCP Cloud SQL
  • Data stays in your VPC

Connect your email address

Vendor outreach runs from your organisation's domain, not ours. Connect your SMTP server, Microsoft 365, or Google Workspace. Replies land in your inbox; GSTITC tracks them back against the vendor and invoice.

  • Microsoft 365 / Exchange
  • Google Workspace
  • Custom SMTP
  • Replies tracked per invoice

InfoSec contact

Questions go to a mailbox, not a marketing form.

Architecture diagrams, a completed security questionnaire, and data flow documentation are available before you commit. Route follow-up to contact@gstitc.com, subject line “security review”. We work with your IT, InfoSec, and legal teams during scoping, and the review cycle is part of the engagement timeline, not an exception to it.

Security review before you commit?

We support it. Write to contact@gstitc.com or start a conversation with finance leadership, and InfoSec can join that thread.