Security at Total
Local by default. Reviewable by design.
The core accounting path works without an account or cloud database. Network features are optional and visible.
Product safeguards
- One transactional SQLite database per company, with migrations, integrity checks, WAL recovery and verified backups.
- Integer paise and balanced voucher validation at the main-process boundary.
- Human-reviewed AI proposals; AI cannot directly post vouchers or change deterministic report calculations.
- Encrypted local secrets, role-based access, approval controls, a tamper-evident audit chain and scoped exports.
- Signed build requirements, dependency policy, install/upgrade tests, performance budgets and release evidence in CI.
Your security responsibilities
Keep your operating system updated, restrict device access, use strong local passwords, verify backup restores, review exports before sharing, and revoke provider keys you no longer use. Do not open the same live company database from multiple synced computers.
Report a vulnerability
Email total@irminflow.com with “security report” in the subject. Include affected version, reproduction steps and impact. Do not include real customer books or credentials. We will acknowledge a credible report and coordinate remediation before public disclosure.
Current boundary
NIC live filing and GST portal connectivity are experimental and are not included in the production-ready claim. Offline books, calculations and reviewed exports remain independent of those services.