This page summarises how Bizalys protects customer and client data, where primary data is hosted, how access is controlled, how backups and recovery are handled, and which legal documents govern data processing.
All primary customer firm data, client records, compliance tasks, and uploaded documents are hosted in enterprise-grade Tier-4 data centers located in Mumbai, Maharashtra, India. Secondary encrypted disaster recovery backups are maintained in a secure Pune region to guarantee high availability and business continuity in regional catastrophes.
Secondary encrypted disaster recovery backups are maintained in a secure Pune region to guarantee high availability and business continuity in catastrophic.
Bizalys enforces fine-grained Role-Based Access Control (RBAC). CA practice admins can restrict access by role (Partner, Manager, Senior Staff, Articles, Clients). Built-in security features include Multi-Factor Authentication (2FA), mandatory session timeouts, password complexity rules.
Automated incremental backups are executed continuously, with full encrypted system snapshots generated daily. Backups are stored across geographically isolated facilities with a 90-day retention cycle. Recovery point objectives (RPO) and recovery time objectives (RTO) are tested regularly.
Bizalys undergoes periodic Vulnerability Assessment & Penetration Testing (VAPT) conducted by DISA-certified security auditors and independent cybersecurity specialists. Code releases undergo automated static and dynamic security scanning prior to production deployment.
Infrastructure and API endpoints are monitored 24/7 for security anomalies, unauthorized access attempts, and performance bottlenecks. In the event of a confirmed security incident affecting personal data, Bizalys will notify affected clients without undue delay in accordance with DPDP Act requirements.
Bizalys operates in full alignment with India’s Digital Personal Data Protection Act, 2023. The subscribing CA firm acts as the Data Fiduciary (determining processing purposes), while Bizalys acts strictly as the Data Processor processing data on documented instructions.
Clients retain 100% data ownership. You can export complete client lists, compliance logs, billing records, and documents in standard formats (Excel, CSV, PDF) at any time. Upon subscription termination, a 30-day grace period is provided for data retrieval, after which all customer data is permanently purged.
Bizalys maintains a public registry of all third-party subprocessors used for cloud hosting, messaging gateways, and payment processing. Customers are provided 30 days advance notice before any new subprocessor is onboarded.
Bizalys enforces a strict ZERO-TRAINING GUARANTEE. Private client data, firm financial records, timesheets, and uploaded documents are NEVER used to train public or proprietary machine-learning/AI models. AI capabilities operate strictly within isolated ephemeral processing boundaries.
We welcome security feedback from researchers and customers. For security inquiries, vulnerability disclosures, or Data Processing Addendum (DPA) requests, please contact our dedicated security team.
Security Email: support@bizalys.com (Subject: "Security Disclosure / Trust Inquiry")