Compliance posture

Every certification, integration, and audit — exactly where we are.

Enterprise procurement reviewers can stop chasing us for status. The vendor questionnaire is on this page. Updated whenever status changes (last update: 2026-06-03).

Status legendLIVEcertified / contracted / shippedIN PROGRESSengaged, dated milestoneSCOPINGdecided, vendor selection underwayPLANNEDon roadmap, not startedNOT PLANNEDexplicit "we will not do this"
LIVE
11
IN PROGRESS
8
SCOPING
5
PLANNED
3
NOT PLANNED
4

Audit & assurance certifications

The big-three procurement asks. Honest progress beats silence.

SOC 2 Type 1

IN PROGRESS

Engaged with auditor selection underway; observation period scoped. Type 1 first to get the controls letter on file faster.

Target Q4 2026

SOC 2 Type 2

PLANNED

Follows immediately after Type 1 closes — six-month observation window.

Target Q2 2027

ISO 27001

IN PROGRESS

Running parallel with SOC 2 to share the ISMS work — single control set, two reports.

Stage 1 audit Q4 2026

ISO 27701 (privacy)

PLANNED

Privacy extension on top of 27001. Sequenced after the base ISMS is certified.

Target H2 2027

VAPT certificate

LIVE

Annual third-party vulnerability assessment + penetration test. Current certificate dated within the last 12 months; share under NDA.

Reference: security@ongravy.com for a copy

Indian statutory compliance

What Indian law actually requires of an accounting platform — not aspirational, in production.

DPDP Act 2023 readiness

LIVE

Privacy notice, lawful-basis register, subject access endpoint, and right-to-erasure endpoint all shipped and exercisable from /dashboard/settings/privacy.

Reference: app/(dashboard)/dashboard/settings/privacy

Companies Act §128 retention

LIVE

Seven-year retention guaranteed for books of account via immutable audit trail. Periods sealed with Merkle roots cannot be retroactively altered.

Reference: lib/audit/period-merkle.ts

Rule 11(g) audit trail mandate

LIVE

Every edit captured via SHA-256 hash-chain plus activity_events log — actor, before/after, IP, timestamp.

Reference: lib/audit/writer.ts

SQC-1 firm-quality records

LIVE

ICAI SQC-1 compliance for CA firms: two-person sign-off on engagement decisions plus immutable engagement log.

Reference: lib/approvals/chain-engine.ts

GST infrastructure

Live submission paths to GSTN. The GSP licence is the gating dependency.

GSP licence

SCOPING

Cygnet, IRIS, and Vayana under evaluation. Decision criteria: uptime SLA, IRP latency, EWB throughput cap.

IRP (e-invoice IRN) live submission

IN PROGRESS

Adapter implemented and tested against sandbox; flips to live the day the GSP contract is signed.

Reference: Waiting on GSP

E-way bill live submission

IN PROGRESS

Same posture as IRP — sandbox-validated, GSP-gated. EWB cancellation + extension flows already coded.

Reference: Waiting on GSP

NIC TRACES portal automation

LIVE

Computer-use beta automates TRACES filings without a GSP — agent navigates the portal directly using vision + DOM tools.

Reference: app/(dashboard)/dashboard/tds (computer-use beta)

Banking integrations

Bank data acquisition strategy: consumer-consent AA route, not direct bank deals.

Setu AA (account aggregator)

SCOPING

Primary AA candidate — broadest FIP coverage among Indian banks.

Perfios

SCOPING

Secondary AA + statement-parsing fallback evaluated alongside Setu.

Finbox

SCOPING

AA aggregator with strong NBFC connectivity — under evaluation for lender-side flows.

HDFC / ICICI direct bank API

NOT PLANNED

Direct corporate bank APIs are deliberately out of scope. Consumer + AA route preferred — better coverage, faster onboarding, no per-bank legal.

Identity + signing

Aadhaar e-sign + PAdES PDF signing flow needed for filings and engagement letters.

Aadhaar e-sign (NSDL / eMudhra)

IN PROGRESS

Application Service Provider (ASP) certificate application filed with CDAC; integration code complete, blocked on cert issuance.

Awaiting CDAC ASP cert

DigiLocker

SCOPING

For pulling client KYC docs (PAN, GST cert, incorporation cert) directly with consumer consent.

PAdES PDF signing (HSM-backed)

PLANNED

Hardware Security Module-backed PAdES Level B-T signatures for archive-grade signed PDFs (audit reports, engagement letters).

Target Q1 2027

Cross-border

GCC + APAC e-invoice mandates — where we are in each country track.

UAE FTA Phase 2 e-invoice

IN PROGRESS

Peppol-based Phase 2 mandate. Waiting on FTA spec freeze and X.509 certificate enrolment.

Tracking FTA timeline

SA ZATCA Phase 2

IN PROGRESS

Clearance + reporting model. Same posture as UAE — adapter built, awaiting cert + spec freeze.

SG Peppol AP (Access Point)

IN PROGRESS

Singapore Peppol access point onboarding underway with a certified provider.

Data residency + sub-processors

Where your data lives, end to end. All India-resident by default.

Database (Supabase ap-south-1 Mumbai)

LIVE

Postgres primary in Mumbai. No client data leaves India for normal request handling.

Reference: Supabase region: ap-south-1

File storage (Supabase ap-south-1)

LIVE

Attachments and generated PDFs pinned to the same Mumbai region as the database.

Email transit (Resend)

LIVE

Transactional email via Resend. Only the minimum payload (OTP, invoice PDF link) leaves our infra.

AI inference (Anthropic, zero retention)

LIVE

Claude API with zero-retention contract. Inference traffic is not retained for training.

Reference: Anthropic zero-retention by default

Analytics (Vercel)

LIVE

First-party Vercel Analytics only — no Google Analytics, no third-party trackers.

What we will NOT do

Explicit anti-commitments. These are guardrails our customers can hold us to.

Sell your data, ever

NOT PLANNED

No data brokering, no aggregated-data resale, no anonymous-cohort sale. Period.

Train AI on your data without opt-in

NOT PLANNED

No customer data flows into model training without an explicit, per-business opt-in. Default is opt-out.

Use your books as training data for our agent-kit

NOT PLANNED

@ongravy/agent-kit is trained on synthetic + public data only. Your ledger never leaves your tenant for our model work.

Need our DPA, SIG questionnaire, or a procurement walkthrough?

Email security@ongravy.com and we'll fill out your vendor questionnaire line-by-line. Procurement calls happen with a founder, not a chatbot.

View DPA →Book a procurement call →security@ongravy.com