Skip to content
LekhaPro
Compliance

What we actually comply with

Compliance pages are usually a wall of badges. This one is a list of things we can show you in the product — Indian GST statutory formats, privacy law alignment, and access controls enforced in the database. It also lists, plainly, the certifications we do not hold.

Indian statutory compliance

LekhaPro is built for Indian businesses, so the statutory formats are the product — not an add-on.

GST return formats

GSTR-1, GSTR-3B and GSTR-2B are prepared and reconciled in the statutory formats. Live, GSP-certified filing is on the roadmap and is not yet available — we do not claim it.

E-invoice & e-way bill

E-invoice (IRN) and e-way bill payloads are generated as JSON in the government schema, ready for upload.

Real double-entry books

A posted General Ledger with balanced double-entry underneath every screen — books a chartered accountant can audit, not a simplified imitation.

Record retention

Account, billing and licensing records are retained for as long as your account is active and as required by Indian tax and accounting law.

Security and access controls

Each of these is implemented in the product today. Read the fuller explanation on the Security page.

Tenant isolation in the database, not just the app

The Cloud edition enforces PostgreSQL Row-Level Security beneath the application’s own scoping. Policies are default-deny: a connection that fails to set its business context sees nothing at all, so a session scoped to one business cannot read another’s rows even if application code has a bug.

Role-based access control

Fine-grained roles and permissions decide who in your business can open, post or approve what, per module.

Audit trail

Sensitive actions are recorded with who did them, so you have a trail to reconstruct what happened.

Passwordless authentication

Sign-in is by one-time code to your email, with signed HTTP-only sessions. We never store passwords, so there are none to leak or reuse.

Encrypted local data (Desktop)

The Desktop edition keeps your books in a local database on your own machine, with AES-256 encrypted backups you can copy offsite to a drive you control.

Export and portability

Reports, ledgers and registers export to PDF and Excel at any time, and on Desktop you hold the database and the backups outright. There is no lock-in.

Data protection & privacy

DPDP Act 2023

Our Privacy Policy is written against India’s Digital Personal Data Protection Act, 2023 — what we collect, why, how long we keep it, and your rights to access, correct, erase and withdraw consent.

Consent-gated analytics

Only strictly-necessary cookies run by default. Analytics and marketing cookies load only after you accept them, and you can change your choice at any time.

Your data is not training data

Your business data is never used to train AI models for anyone. Deterministic insights compute on your own data; the optional AI copilot sends a compact snapshot only when you ask it a question.

Named sub-processors

The third parties that process data on our behalf — the payment gateway, transactional email, consent-gated analytics and the optional AI provider — are named in the Privacy Policy rather than hidden behind a generic clause.

Full detail: Privacy Policy · Cookie Policy

Payments

Subscriptions are billed through Razorpay, a PCI-DSS-compliant payment provider. Card and UPI details are captured and stored by the gateway — they never touch our systems, so we never see your full card number. That is Razorpay's certification, not ours: we do not hold, and do not claim, PCI-DSS certification of our own infrastructure.

What we do not claim

We would rather lose a deal than win one on a badge we do not hold. As of July 2026, LekhaPro does not hold and does not claim:

  • ISO 27001 certification
  • SOC 1 or SOC 2 attestation
  • GDPR certification or an EU representative
  • PCI-DSS certification of our own systems
  • HIPAA compliance
  • An independent third-party security audit or penetration test report
  • A published uptime SLA

If your procurement process requires any of the above, tell us what you need and we will give you a straight answer about where we are — rather than a badge.

Doing a security or vendor review?

Send us your questionnaire. We will answer it honestly, including the questions where the answer is “not yet”.

Security → · Privacy Policy → · Terms →