Security & Data Privacy
Client Data Privacy Comes First
CA firms handle credentials, client records, tax documents, hard-copy locations, and communication history. CA DigiBox keeps privacy and controlled access at the center of the product.
Data privacy
Designed so firms decide what leaves the office.
Internal data stays internal by default. Client-facing access is controlled through visibility settings, permissions, temporary share links, and tenant-aware routes.
Privacy controls
Important controls for sensitive CA firm data.
These controls are built for real client portal usage where sensitive data must not become casually public.
Tenant data separation
Every firm works inside a tenant context. Login, settings, feature flags, usage, and records are resolved for the selected tenant.
Client visibility control
Credentials, document fields, documents, and services can be kept internal or exposed to clients only when the firm marks them visible.
Private document storage
Document storage is designed for private server or S3 storage. Public bucket access is not required for normal document handling.
Temporary secure links
Documents can be shared through controlled secure links with expiry and download limits instead of permanent public URLs.
Authentication
- Tenant login links
- Email OTP flow
- Authenticator support
- Platform admin login
Authorization
- Admin, employee, client roles
- Staff permission controls
- Feature flag enforcement
- Package level limits
Documents
- Private storage driver
- Attachment access routes
- Movement logs
- Share link expiry
Auditability
- Activity logs
- QR scan history
- Storage audit review
- Document verification trail
Operational security
Privacy also depends on daily workflow discipline.
That is why document movement, QR scans, storage audits, staff permissions, and activity logs are treated as core product features, not side notes.
Privacy-ready workspace
Launch a controlled client portal without opening everything.
Start the trial, configure visibility, and keep sensitive records within firm-controlled access.