Security
CA firms trust AutoFS with their most sensitive client financials. Every connection is read-only where it matters, every change is attributed, and your data always remains yours.
AutoFS is not SOC 2 or ISO 27001 certified — our controls stay aligned to their best practices across encryption, access control and logging, and every statutory judgment stays with your firm.
Connected where it helps, read-only where it matters.
The Chrome extension talks to TallyPrime on your own machine over localhost. The server never connects to Tally, stores no Tally credentials and installs no background service.
Snapshot hashed on receipt
Connect Drive and Sheets with least-privilege OAuth you can revoke anytime. Only the files you pick for the engagement are read — never the whole Drive.
Revocable, least-privilege access
Eight controls, on every engagement, on every plan.
TLS 1.3 in transit everywhere. Sensitive secrets (MFA seeds, webhook secrets) protected with AES-256-GCM; issued packs hashed with SHA-256.
Articled assistants, reviewers, senior managers and signing partners get only the engagement access their role needs — no shared logins.
Tamper-evident, attributed revision history records who grouped each ledger, who resolved each review point and when the year locked.
Strict multi-tenant isolation enforced at the database layer by fail-closed row-level security — firm data never co-mingles.
Versioned snapshots of sources, groupings and packs mean any engagement can be reproduced exactly as received and approved.
Your data stays yours. Firm workspaces are isolated, exports are explicit actions, and nothing is used to train shared models.
Strong authentication, scoped sessions and least-privilege service access — with sign-in activity you can review.
ICAI Guidance Note structure, GST invoicing discipline and documented controls your firm's own reviewers can inspect.
The documents your firm's reviewers actually ask for.
No. The Chrome extension only extracts the Trial Balance and ledger list when you explicitly start a sync in your browser session. The AutoFS server never connects to Tally, and no raw Tally database files are ever accessed or transferred.
Client data is hosted in the cloud and stays yours — isolated per firm at the database layer, under the handling terms of our Data Processing Agreement (/dpa). Traffic uses TLS 1.3, and every export is an explicit, logged action by your team.
Through scoped OAuth you grant and can revoke at any time. The connector reads only the files you choose for the engagement — it cannot browse your whole Drive — and tokens are stored as protected secrets.
When a year locks, AutoFS computes a SHA-256 digest of the dataset, grouping decisions and outputs, and binds it to the evidence and audit history. AutoFS records a user-obtained UDIN and does not generate or independently verify UDIN.
Yes. Team members with assigned engagement access can work on grouping, schedules and review points together, with every change attributed and timestamped.
Start your free evaluation today — isolated workspace, review-first controls and an audit trail from the very first sync.