Munib ji

How we protect your data

Last updated: 29 August 2026

Encryption

All traffic between your devices and Munib ji is encrypted in transit (TLS). Sensitive data at rest — PAN numbers, bank account numbers, and similar fields — is encrypted with AES-256-GCM before it is stored. For the professional (CA/CS/CMA) portal, each firm's stored credentials use a key derived uniquely for that firm, so a key leaked from one firm can never unlock another firm's data. Files you upload are stored in Cloudflare R2 storage.

Tenant isolation

Every row of business data belongs to exactly one organization and is scoped by its organization ID. The application verifies your membership in that organization on every read and write. As a second, database-level line of defense, row-level security is enabled on every table — any request that does not go through the application's membership checks is denied by the database itself by default. Accountants can see a client organization's data only through an explicit, active client link that the business or the firm controls.

Backups

Your data lives in a managed Postgres database (Supabase) with automated daily backups. Because GST law requires businesses to keep records for eight years, we do not delete accounting and compliance records for active organizations.

Retention

Your data is retained for as long as your organization's account is active. If an account is closed, its owner may request deletion of non-statutory data; records that Indian tax law requires you to retain (GST returns, invoices, and the documents behind them) are kept for the statutory eight-year period. You can download everything at any time — see the export commitment below.

Sub-processors

We run on Vercel (hosting). We use Clerk for authentication, Supabase for the database, Cloudflare R2 for file storage, Inngest for background jobs, Upstash Redis for rate limiting, MSG91 for SMS, Wati for WhatsApp, Razorpay for payments, Resend for email, PostHog for product analytics, and Sentry/BetterStack for error monitoring. AI features use Anthropic (Claude) and Google (Gemini) models.

AI data handling

The AI advisors (Pragati, Sahyog, Saathi, Seva, Hisaab) answer questions using your organization's data — and only your organization's data. An advisor answering for one business cannot read another business's records; the same tenant checks as every other feature apply. Answers are generated by Anthropic and Google models; we do not use your data to train them, and data sent to a model is used to answer your request.

If something goes wrong

If we become aware of a personal-data breach that poses a risk to your rights, we will notify affected organizations and users without undue delay through the contact details on your account, and report to the Data Protection Board of India where the law requires it.

Our commitment: your data is yours

Whatever happens to us as a company, your records remain yours. On request, we will export your organization's complete data — accounts, customers, invoices, GST returns, documents, everything you put in — in machine-readable form (CSV/JSON plus your original files), at no charge, while your account is active and for a reasonable period after it ends. If we ever discontinue the service, we commit to giving every organization at least 90 days' notice and a full export before anything is shut down. This is a standing commitment, not a plan tied to any feature release.

To request an export, write to us at support@munibji.com with your organization name.