AccDoo Logo
Simplify Tax & Compliance

Simplify Tax & Compliance

Automatically calculate VAT and taxes, generate downloadable PDF invoices and reports, and stay up to date with changing Sri Lankan tax requirements.

Explore Features
AccDoo Logo
👋

Welcome to Accdoo

Manage your accounting
from anywhere.

Language

Region

© accdoo.ai 2026

1. Purpose and Scope

This Security Policy outlines the technical, administrative, and physical controls established by Era Biz Solutions (Pvt) Ltd to protect Customer Data, Personnel Data, and system infrastructure within the AccDoo.ai multi-tenant cloud environment. This policy applies to all systems, employees, networks, and third-party sub-processors contributing to the delivery of AccDoo Services worldwide.

2. Multi-Regime Compliance Matrix

Our security infrastructure is architected to simultaneously satisfy global privacy frameworks:

  • Sri Lanka PDPA (No. 9 of 2022): Satisfies Section 23 obligations by protecting integrity and confidentiality against unauthorized processing, loss, or damage.
  • EU & UK GDPR (Article 32): Ensures the ongoing confidentiality, integrity, availability, and resilience of systems, utilizing automated data pseudonymization and localized access protocols.
  • US State Laws (CCPA/CPRA):Maintains “reasonable security procedures and practices” to prevent statutory private right-of-action triggers due to data breaches.

3. Cloud Infrastructure & Data Localization

  • Primary Hosting: All production data, core ledger microservices, and databases are hosted on Amazon Web Services (AWS) in the US East (Virginia, USA) region.
  • Physical Security: Data centers maintain 24/7/365 physical security, biometric access entry checkpoints, surveillance logs, and independent certifications (ISO 27001, SOC 2 Type II).
  • Network Isolation: Customer production environments are strictly separated from non-production development environments. Virtual Private Clouds (VPCs) and security groups isolate system tiers.

4. Cryptographic Standards (Data Protection)

  • Data in Transit: All connections to accdoo.ai and associated APIs are forced over HTTPS using Transport Layer Security (TLS 1.3) with robust cipher suites. Legacy, unencrypted protocols are entirely blocked.
  • Data at Rest: Customer business ledgers, hashed login credentials, and HRMS records are encrypted using AES-256 bit encryption at the storage volume layer.
  • Key Management: Encryption keys are managed securely via AWS Key Management Service (KMS) with automatic, scheduled cryptographic key rotation.

5. Logical Access Controls & Identity Management

  • Staff Access Restrictions: Era Biz Solutions personnel are granted infrastructure access strictly on the Principle of Least Privilegeand a “Need-to-Know” operational basis.
  • Authentication Requirements: All employee administrative connections require mandatory Multi-Factor Authentication (MFA), strict password complexity profiles, and hardware-bound tokens.
  • Audit Logging: Every single database query, administrative configuration change, and server access event is recorded in a centralized, read-only audit log monitored for structural anomalies.

6. Vulnerability and Threat Management

  • Continuous Monitoring: Automated network scanners inspect our software components continuously for known CVE dependencies and configuration flaws.
  • Penetration Testing: Independent, certified cybersecurity firms conduct deep web application penetration tests at least once every twelve (12) months.
  • AI Feature Guardrails: Data processed via our AI Feature integrations (API wrappers with OpenAI) uses strictly encrypted, non-caching data pipelines. Prompts are zero-retention and contractually barred from training general public models.

7. Availability, Backups, and Disaster Recovery

  • Data Redundancy: Database clusters utilize active real-time replication across isolated Availability Zones inside our primary AWS data center.
  • Backup Schedule: Automated incremental system backups are generated daily. Full snapshots are compiled weekly.
  • Backup Security & Lifecycle: All backup volumes are thoroughly encrypted, stored independently from live workspaces, and systematically overwritten on a strict 35-day rotation loop.

8. Incident Response and Breach Notification Lifecycle

In the event of a verified data compromise, AccDoo will execute its structured Incident Response Plan:

  • Containment & Forensics: Security operations will instantly isolate affected nodes, revoke active authentication tokens, and trace the breach vector.
  • Regulatory Alerts (GDPR / UK GDPR): Where a breach poses a risk to European or UK citizens, the designated supervisory authorities (e.g., the UK ICO) will be formally notified within 72 hours of discovery.
  • Regulatory Alerts (Sri Lanka PDPA): The Data Protection Authority of Sri Lanka will be systematically notified within the legally required timelines dictated by local statutory rules.
  • Customer/Processor Notice: For personal data handled as a Processor (e.g., employee payroll tables uploaded by our business clients), AccDoo will alert the affected business Customer (the Controller) without undue delay so they can take proper step measures.