← Home

Cyber-Attack & Data Safety Policy

Policy version 2026-07-14. Last updated: 13 August 2026

This page is maintained by Gstian Software Solutions Private Limited (the “tool owner”) to explain, in plain language, the safeguards used to protect data you enter into the GST Notice Reply Drafting Assistant (the “tool”), and the responsibilities that rest with you as an end user. It is not a certification, audit, or legal opinion.

1. What we do not collect

The tool is designed for GST notice and reply workflows. It does not ask you for, and you should not enter into it:

  • Aadhaar numbers, PAN photocopies of unrelated individuals, or other government-issued identity numbers not required for the notice.
  • Bank account numbers, debit or credit card numbers, CVV values, UPI PINs, or net-banking credentials.
  • OTPs, one-time passcodes, or passwords for any other service (including the GST portal).
  • Personal photos, videos, or health records.

Please do not paste such data into notice replies, brain entries, case-law notes, or uploaded files. Where a submitted field appears to contain a bank/card-style number, the tool blocks the save and asks you to remove it before continuing.

2. Reasonable technical and organisational measures

The tool owner uses reasonable technical and organisational measures to protect data on a best-efforts basis. Currently shipped safeguards include:

  • Encrypted transport (HTTPS) for all browser traffic and server-side calls.
  • Private, non-public object storage for uploaded notice PDFs, case-law PDFs, and other user files, with time-limited signed URLs for download.
  • Row-Level Security on the database so that each authenticated user can read and write only their own taxpayers, cases, notices, and replies.
  • Role-based access control separating end users, analysts, and administrators.
  • Server-side upload validation (file-type magic-byte checks and size limits) to reduce the risk of malicious uploads.
  • Server-side PII pattern checks that block obvious sensitive-financial input at save time.
  • Salted password hashing performed by the managed authentication provider; the tool owner never sees plaintext passwords.
  • Least-privilege service credentials, kept out of client code.

Additional controls — including expanded audit logging, adaptive login throttling, and administrator multi-factor authentication — are ongoing controls being progressively rolled out. This page will be updated as those controls ship. No representation is made that any specific control is enabled at any given moment beyond what is described here.

3. AI processing

Some features send the relevant text of your notices, orders, or case-law material to third-party large language model providers via a secure AI gateway, strictly to perform the task you initiated (extraction, drafting, summarisation). These providers process the text under their enterprise data terms and, per those terms, do not use it to train their models. Do not submit material to the tool that you are not authorised to share with such providers.

4. Limits of any online system

No online system can be guaranteed to be completely free from cyber-attacks, unauthorised access, or data loss. The tool owner does not warrant that the tool will be uninterrupted, error-free, or immune from every conceivable threat. The safeguards described above are provided on a best-efforts security basis.

5. Your responsibilities as an end user

  • Use a strong, unique password for your account and do not reuse it on other services.
  • Keep the device, browser, and operating system from which you access the tool up to date, and run reputable anti-malware software.
  • Do not share your login credentials, session, or download links with anyone else.
  • Sign out of shared or public devices after use.
  • Report a suspected compromise of your account to the contact address below without delay.
  • Do not attempt to probe, scan, or otherwise attack the tool’s security.

6. Risk allocation for user-side compromise

Where a security incident arises from a compromise of your own device, email account, browser, other applications on your device, or any third-party service used to access the tool, the resulting loss is not attributable to the tool owner. The Saving / Limitation of Liability terms at /liability apply.

7. Legal framework and updates

This policy is a plain-language description intended to complement the tool owner’s obligations under applicable Indian law, including the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023. Where specific statutory obligations apply, they prevail over the summaries above. The tool owner may update this policy from time to time; on a material change, users are asked to accept the new version before continuing to use the tool.

8. Contact

Security or privacy concerns: contact@gstian.in. Postal address: Gstian Software Solutions Private Limited, Plot No.542, Sri Vijaya Durga Nagar Colony, Bachupally, Hyderabad, Telangana-500090.

See also: Saving / Limitation of Liability · Privacy Policy · Terms of Use