Caledger is desktop software. It runs on your firm's own PCs and LAN - there is no Caledger cloud holding your clients' portal logins or financial data. That is the whole design.
The server, the database and every client's data live on the firm's own machines. We can't see it, and neither can anyone else.
Portal logins and sensitive fields are encrypted at rest with AES-256, keyed to the machine - not stored in plain text.
Sign-in is your activation code + firm email, bound to your machine's fingerprint. No shared passwords to leak.
Every action is timestamped and attributed to a user, so you always know who did what, for which client, when.
The only thing that talks to us is a short activation exchange over HTTPS - no client data, ever.
Because personal and financial data stays with the firm, Caledger keeps you on the right side of the DPDP Act by design.
A browser SaaS asks you to trust a third party with every client's GST login and books. Caledger doesn't ask - it runs on your hardware, so there's nothing to trust us with.
Ask a security question