QubitPilotBeta
ProductFor CAsFor advocatesPricingDocs
Home/Security
Security & trust

Your client data is protected

Built for advocates, chartered accountants and law firms who handle sensitive client matters every day. Here’s exactly how QubitPilot protects your data - explained without jargon.

Start your 15-day free trialTalk to us
On this page
  • Your account and passwords
  • Who can see what
  • How your data is protected
  • WhatsApp, payments and other connections
  • Infrastructure you can rely on
  • Where we're still honest about the gaps

Your account and passwords

Your password is never stored in a form anyone - including us - can read. It runs through a one-way process before it touches our database, so it can be checked at sign-in but never reversed back into the original password.

  • Sessions expire automatically after 7 days, so a forgotten sign-in on a shared or lost device does not stay open indefinitely
  • If you reset your password, every other active session is signed out immediately and you get an email telling you it happened - even if you weren't the one who asked for the reset
  • Sign-in attempts are rate-limited, so a script trying thousands of password guesses against your account gets blocked, not a fair shot
  • Team invite links expire on their own and can be revoked or reissued by the workspace owner at any time

Who can see what

Permissions are enforced on our servers, not just hidden in the screen you see - so a team member without access to a module cannot reach it by any route, not just the obvious one.

Your workspace is completely walled off from every other firm on QubitPilot. There is no shared view, no cross-firm search, no way for another practice to see your matters or clients, ever.

  • 8 role presets built specifically for how Indian legal and CA practices are actually staffed - Senior Lawyer, Associate Lawyer, CA Partner, CA Staff, Accountant, Manager, Intern and Viewer
  • Every role's access is scoped by module and by action, so "can view invoices" and "can send invoices" can be granted separately
  • A team member only ever sees the clients, matters and documents their role is allowed to see - not the whole firm by default

How your data is protected

Sensitive credentials your workspace stores - like a connected Google Calendar or a court-data provider connection - are encrypted at rest using AES-256, the same encryption standard used by banks. It is not readable as plain text anywhere in our systems.

Every action anyone takes inside your workspace - who changed what, when, and in which module - is written to a tamper-evident audit log you can review. Sensitive fields, like phone numbers, are masked in that trail so the record itself doesn't become a new place your data leaks from.

  • Access to QubitPilot's own admin systems requires two-factor authentication, on top of everything protecting your workspace
  • The audit log is workspace-wide, not per-module, so nothing falls in a gap between two features
  • Bring your own storage — connect Cloudflare R2, Amazon S3 or any S3-compatible bucket (Growth and above). Your files stay in your account, with no storage limit.

WhatsApp, payments and other connections

Every message QubitPilot receives from WhatsApp, and every payment event from Razorpay or Stripe, is cryptographically checked before we act on it. If a payload wasn't genuinely sent by that service, it is rejected outright - it never reaches your workspace as if it were real.

This is what stops someone from being able to fake a payment confirmation or a client message and have QubitPilot treat it as genuine.

Infrastructure you can rely on

Every update to QubitPilot goes through an automated deployment that checks the live application is actually healthy before the deployment is considered complete - a broken deploy doesn't get left live for customers to hit.

The entire platform runs over HTTPS, and every response includes security headers that tell your browser how to handle the page safely - this happens on every request, without you needing to do anything.

Where we're still honest about the gaps

We would rather tell you what isn't done yet than let a checkmark imply it. QubitPilot does not currently claim independent third-party security certifications, a dedicated file-scanning layer for uploads, or a formal bug-bounty programme - we are actively working through this list as the platform grows, and we'll update this page as each item is genuinely true rather than in advance of it.

If you have a specific security question - your own compliance checklist, a client asking for assurances, anything not answered above - write to us directly and we'll answer it plainly.

Have a security question?

Write to us and we’ll answer directly - your own compliance checklist, a client’s question, anything not covered above.

Contact usReady to get started?
QubitPilotBeta

Practice on autopilot - clients, matters, hearings, billing and an AI associate in one calm workspace, built for Indian advocates and CAs.

Start free trialTalk to us

5th Floor, Gordhan Sky Mall, Office 507, Khatipura Rd, Jhotwara, Jaipur, Rajasthan 302012 · +91 8000243808

GSTIN 08COWPC8765E1ZC

Find us on Google · LinkedIn

Product

  • Features
  • Pricing
  • Business plan
  • Integrations
  • Sign in
  • Get started

Resources

  • Docs
  • Help center
  • Blog
  • FAQ
  • Editorial Policy

Company

  • About
  • Team
  • Security
  • Book a demo
  • Contact

Legal

  • Privacy Policy
  • Terms & Conditions
  • Cancellation & Refunds

© 2026 Qubitron Labs · QubitPilot. All rights reserved.

QubitPilot