What we actually comply with
Compliance pages are usually a wall of badges. This one is a list of things we can show you in the product — Indian GST statutory formats, privacy law alignment, and access controls enforced in the database. It also lists, plainly, the certifications we do not hold.
Indian statutory compliance
LekhaPro is built for Indian businesses, so the statutory formats are the product — not an add-on.
GST return formats
GSTR-1, GSTR-3B and GSTR-2B are prepared and reconciled in the statutory formats. Live, GSP-certified filing is on the roadmap and is not yet available — we do not claim it.
E-invoice & e-way bill
E-invoice (IRN) and e-way bill payloads are generated as JSON in the government schema, ready for upload.
Real double-entry books
A posted General Ledger with balanced double-entry underneath every screen — books a chartered accountant can audit, not a simplified imitation.
Record retention
Account, billing and licensing records are retained for as long as your account is active and as required by Indian tax and accounting law.
Security and access controls
Each of these is implemented in the product today. Read the fuller explanation on the Security page.
Tenant isolation in the database, not just the app
The Cloud edition enforces PostgreSQL Row-Level Security beneath the application’s own scoping. Policies are default-deny: a connection that fails to set its business context sees nothing at all, so a session scoped to one business cannot read another’s rows even if application code has a bug.
Role-based access control
Fine-grained roles and permissions decide who in your business can open, post or approve what, per module.
Audit trail
Sensitive actions are recorded with who did them, so you have a trail to reconstruct what happened.
Passwordless authentication
Sign-in is by one-time code to your email, with signed HTTP-only sessions. We never store passwords, so there are none to leak or reuse.
Encrypted local data (Desktop)
The Desktop edition keeps your books in a local database on your own machine, with AES-256 encrypted backups you can copy offsite to a drive you control.
Export and portability
Reports, ledgers and registers export to PDF and Excel at any time, and on Desktop you hold the database and the backups outright. There is no lock-in.
Data protection & privacy
DPDP Act 2023
Our Privacy Policy is written against India’s Digital Personal Data Protection Act, 2023 — what we collect, why, how long we keep it, and your rights to access, correct, erase and withdraw consent.
Consent-gated analytics
Only strictly-necessary cookies run by default. Analytics and marketing cookies load only after you accept them, and you can change your choice at any time.
Your data is not training data
Your business data is never used to train AI models for anyone. Deterministic insights compute on your own data; the optional AI copilot sends a compact snapshot only when you ask it a question.
Named sub-processors
The third parties that process data on our behalf — the payment gateway, transactional email, consent-gated analytics and the optional AI provider — are named in the Privacy Policy rather than hidden behind a generic clause.
Full detail: Privacy Policy · Cookie Policy
Payments
Subscriptions are billed through Razorpay, a PCI-DSS-compliant payment provider. Card and UPI details are captured and stored by the gateway — they never touch our systems, so we never see your full card number. That is Razorpay's certification, not ours: we do not hold, and do not claim, PCI-DSS certification of our own infrastructure.
What we do not claim
We would rather lose a deal than win one on a badge we do not hold. As of July 2026, LekhaPro does not hold and does not claim:
- ISO 27001 certification
- SOC 1 or SOC 2 attestation
- GDPR certification or an EU representative
- PCI-DSS certification of our own systems
- HIPAA compliance
- An independent third-party security audit or penetration test report
- A published uptime SLA
If your procurement process requires any of the above, tell us what you need and we will give you a straight answer about where we are — rather than a badge.
Doing a security or vendor review?
Send us your questionnaire. We will answer it honestly, including the questions where the answer is “not yet”.