# Security and data protection

IndustryMax is a multi-customer cloud application with an on-premises connector for TallyPrime. Access is by role, with 153 distinct permissions and an unknown permission always refused. Every query is scoped to the signed-in customer from the session rather than from anything the caller supplies, and to the legal entities that user is allowed to see. Outside credentials are encrypted before they are stored. The Tally connector makes only outbound connections, so nothing has to be opened in a customer's firewall.

*Last reviewed 2026-09-12. Canonical HTML: https://industrymax.co.in/security*

## Signing in

- One field takes either a mobile number or an email address. A mobile number is verified with a one-time code; an email address is verified with a password. There is no path that needs both.
- Passwords must be at least 12 characters across three character classes, and are refused against a list of what people actually type when told to make one 12 characters long.
- A session is a short-lived token held in memory plus a refresh cookie the browser cannot read from JavaScript. Refresh sessions are recorded, so a session can be seen and ended.
- Administrators can see active sessions and login history.
- Suppliers sign in to their own portal with a mobile number or email and a one-time code — no password, and no access to anything but their own documents.


## Who can do what

- 153 distinct permissions, granted per role. A permission the system does not recognise is denied rather than allowed — on the web client and the mobile client alike.
- Separately, 27 document types can be set to require approval, and on the purchase chain those approvals can require different people at different rupee amounts.
- Some reads are deliberately their own permission because they are their own risk — the margin on a sale, for instance, is separate from the sales register it sits on.
- Modules are licensed per customer, so a module nobody bought is refused at the API rather than merely hidden in the menu.


## Separation between customers, and between legal entities

- Every query carries the customer account taken from the signed-in session. It is never read from a parameter, a header or a request body, so it cannot be substituted by a caller.
- Inside a customer, a user sees only the legal companies they have been granted, and the application is inside exactly one of them at a time.
- The AI assistant is held to both rules. Its lookups are read-only, its customer account comes from the session and never from the model, and each lookup requires the same permission as the screen that shows the same data.
- Restoring a customer's data is a super-administrator action, and the guard on it is restated on every single route rather than applied once, because that is the one place where a refactor dropping a shared guard would be silent.


## Credentials and secrets

- Outside credentials — GST portal and GSP logins — are encrypted with AES-256 and a per-value random initialisation vector before they are stored, and are never written to a log. Call logs keep response codes and timings, not credentials.
- A Tally connector's token is shown once when it is issued and stored only as a hash. The screen shows a short prefix so two connectors can be told apart without revealing either.
- A connector is a device. It can be revoked on its own, instantly, without deleting its history — because "that PC was replaced" and "this company has stopped using Tally" are different events.
- Tally XML payloads are kept only on failure, and only when the customer has explicitly switched retention on, because that XML carries party names, addresses, GSTINs and amounts.


## The Tally connector's network posture

This is the question a customer's IT department asks first, so it is answered first: nothing has to be opened.


- The connector runs on the machine that already runs Tally, makes outbound HTTPS calls to IndustryMax, and talks to Tally over localhost.
- No inbound port, no port forward, no fixed IP, no VPN. Where the network uses a proxy, the connector goes through it.
- This is the reason for the design, not a reassurance added afterwards: Tally's XML gateway has no authentication of any kind, so anything that can reach that port can read and write the books. An integration that asks you to forward a port to Tally is asking you to publish your accounts.
- The XML is built on our server rather than by the connector, so a format fix reaches every customer on the next poll instead of needing a new program installed on a shop-floor PC.


## Audit trail

- An activity log across the product and an audit log for administrators.
- Approvals record who signed, when, and on which version — a signature expires if the document is edited under it.
- Posted accounting entries are never editable. A correction is a reversing entry that stays visible permanently, which is what an unalterable trail means in practice.
- An edit log over the books, with a verification check.
- Email and WhatsApp sending logs, so a message that did not arrive can be distinguished from one that was never sent.


## What we do not claim

A trust page is worth more for what it refuses to say than for what it says.


- No SOC 2, no ISO 27001, no PCI-DSS, no CERT-In empanelment. None is held, so none is claimed.
- No "bank-grade" or "military-grade" encryption. AES-256 is AES-256.
- No uptime figure, because no measured one is published.
- Rate limiting is a per-process speed bump against brute force, not a global guarantee across every server.


> **Note:** If your procurement process needs a security questionnaire answered, ask us and you will get a straight answer about each item, including the ones where the answer is no.


## Questions

### Is IndustryMax data separated between customers?

Yes. Every query is scoped to the customer account taken from the signed-in session, never from anything the caller can supply. Inside a customer, a user sees only the legal companies they have been granted.

### Does the Tally integration require opening a port in our firewall?

No. The connector runs on the machine that already runs Tally, calls out to IndustryMax over HTTPS, and reaches Tally over localhost. There is no inbound port, no port forward, no fixed IP and no VPN.

### Is IndustryMax ISO 27001 or SOC 2 certified?

No. Neither certification is held, and neither is claimed. The security page describes the mechanisms that exist rather than certificates that do not.

### How are portal credentials stored?

GST portal and GSP credentials are encrypted with AES-256 and a random initialisation vector per value before storage, and are never written to a log. A Tally connector token is stored only as a hash and shown once when issued.

### Can an approved document be quietly altered afterwards?

An approval is recorded against the version it was given on and expires if the document is edited underneath it. Posted accounting entries cannot be edited at all — a correction is a reversing entry that stays in the book.

## Related

- https://industrymax.co.in/tally-integration
- https://industrymax.co.in/modules/approvals
- https://industrymax.co.in/modules/ai-assistant
- https://industrymax.co.in/modules/multi-company
