Security
Security at Distiqo
Last updated: 30 September 2026
1. Your business is kept apart
Every business's data is separated from every other's. The system checks who you are on every request and only ever returns your own business's records, and the database enforces the same separation with row-level security as a second line of defence.
2. Between businesses on the network
A shop and a distributor on Distiqo can link their accounts, and only once both agree. Even then, each business's data stays in its own separated space; the few places where one business reads another's records are written narrowly and reviewed on every change:
- A shop sees only the bills its distributor issued to it, and the distributor's catalogue and prices for that shop — never the distributor's stock, costs or other customers.
- A distributor sees only orders, payments and messages addressed to it, and sell-through of its own products in shops that share it. Never a shop's customers, other suppliers, prices or margins.
- Area demand for shops is combined across many shops and shown only when at least five shops sell a product.
3. Encryption and passwords
- Data is encrypted in transit.
- Sensitive details — such as bank and ID-proof information and PAN — are encrypted at rest with AES-256-GCM.
- Passwords are never stored; only a salted one-way hash is.
4. Who can do what
- Every user has a role, and each role sees and does only what it needs to — a cashier who can bill can't open profit, ledgers or GST unless the owner allows it.
- In a shop with several branches, the branch a person works in is checked against the business's own branches on every request.
- Password sign-in, sign-up and team invitations are protected by a one-time code emailed to the account's address. Codes are six digits, expire after 10 minutes, work once, allow a limited number of attempts, and can be re-requested only after a short wait and a capped number of times per hour. They are stored only as a one-way hash.
- Signing in with Google relies on Google's own verification of your email and doesn't ask for a code.
- You can choose to skip the code on a browser you trust. That trust lasts 30 days, can be reviewed and revoked in Settings, and is cleared automatically when the password is changed or reset.
- Repeated wrong passwords temporarily lock the account, and sign-in errors don't reveal whether an email is registered.
- Sign-in tokens are short-lived (30 minutes) and can be revoked. Idle sessions time out.
- Which pages a person can open is enforced on our servers, not just hidden in the app: a role without access to a page can't read or change its data by other means.
- Staff access to our own systems is limited to named administrators, with two-step sign-in.
5. Records that can't be quietly changed
- Every action is written to an append-only audit log. Each entry is sealed to the one before it, so any later change to history is detectable.
- Invoices and ledger entries can't be edited or deleted after posting. Corrections are made by reversal or credit note, so there's always a trail.
6. AI with a person in the loop
AI suggestions are assistive. Anything that changes money or stock — an order, an invoice, a reminder — waits for a person to approve it. There are guardrails on AI output, and AI usage is logged and capped. If an AI or messaging provider is down, those features say so plainly and the core billing, stock and ledger features carry on.
7. Where data lives
The main database is in Mumbai (AWS ap-south-1). Our language and speech features use an India-based provider, and the embeddings that power search are computed on our own servers. See the Privacy Policy for the full list of providers.
8. Backups and recovery
The database is backed up continuously with point-in-time recovery, plus periodic snapshots. These are our recovery targets:
| Target | Goal |
|---|---|
| Most data we could lose | 15 minutes |
| Longest time to be back up | 4 hours |
| Point-in-time recovery window | 30 days, plus monthly snapshots for 12 months |
After any recovery we check that the audit log and the ledgers still add up.
9. If something goes wrong
We have a written incident-response plan. If a breach affects your data we tell you and the authorities, as the law requires, and our target is to do so within 72 hours of confirming it. We review every incident afterwards and fix the cause.
10. What we have not done yet
We would rather tell you than let you assume:
- No certification yet. We are not yet SOC 2 or ISO 27001 certified. We have built to those standards and documented our policies, but an independent audit has not happened.
- No independent penetration test yet. We have tested our own controls; a test by an outside firm is still to come.
- Provider agreements are still being finalised. Formal data-processing agreements with our providers are in progress.
- Recovery drill. The recovery targets above are targets; a full timed restore drill is still to be run and recorded.
Distiqo is in private beta. If your business or your accountant needs something specific before you start — a questionnaire, a call about how we handle data — write to us and we'll answer directly.
11. Reporting a security problem
If you think you've found a vulnerability, please email info@distiqoai.com with the subject “Security report”. Tell us what you found, how to reproduce it, and what it affects.
- We acknowledge your report within 2 business days.
- We give you a plan and timeline within 5 business days.
- We keep you updated until it is fixed, and credit you if you like.
- Please don't open a public issue, and give us a reasonable time to fix it before you share details.
Questions? Write to info@distiqoai.com or message us on WhatsApp. See also our Privacy Policy, Terms and Security pages.