The operating system for Indian accounting and CA firms
From source document to review-ready work.
Bodhi brings practice operations, cloud books, bank and document automation, tax work, audit evidence, client collaboration, and governed AI into one role-aware workspace.
Workspace invitation detectedSign in with the invited email to review and accept access.
ONE LOGINPracticeBooksCA OneSyncIntelligenceONE EVIDENCE GRAPH
THE BODHI PLATFORM
Five connected workspaces. One professional system of record.
Start with the firm, select the client and period once, then move from source evidence to books, compliance, review, and delivery without losing context.
Foundation available
Bodhi Practice
Firm command centre for clients, entities, teams, obligations, deadlines, maker-checker review, work queues, exceptions, billing, and profitability.
Client 360 and global switcher
Role and assignment scoped work
Compliance workflow state machine
Controlled core available
Bodhi Books
Cloud double-entry accounting designed for Indian businesses and the accountants who close their books.
28-group chart and atomic vouchers
Bill-wise, inventory, payroll drafts and assets
Reconciled reports that drill to evidence
Controlled modules in build
Bodhi CA One
Multi-client banking, OCR, GST, TDS, income tax, audit, notices, MCA, and workpapers under professional review.
Exception-first operations
Frozen period snapshots
Evidence-linked workpapers
Controlled exchange available
Bodhi Sync
Safe exchange with TallyPrime, Tally.ERP 9, Zoho Books, Vyapar, bank feeds, and structured ERP files.
Preview-first Tally XML round trips
Signed-request outbound agent runtime
Conflicts, checkpoints and reconciliation
Governed core available
Bodhi Intelligence
Provider-neutral AI for extraction, classification, explanation, and draft actions—never the owner of arithmetic or professional authority.
Rules and approved client memory first
Multilingual editable voice transcripts
Evaluation, citations, preview and undo
COMPLETE OPERATING LOOP
Designed around the work CAs and accountants repeat every day.
Every capability enters through the same controls: client context, source evidence, exact calculations, review authority, and an immutable result trail.
Bodhi automates the complete route, not just one AI response.
01
Collect
Portal, upload, email, official WhatsApp, API, or local connector.
02
Prove
Identity, source coverage, schema, exact paise math, and duplicates.
03
Prepare
Rules and memory propose mappings, vouchers, returns, and workpapers.
04
Review
Maker, reviewer, partner, and client consent gates remain explicit.
05
Deliver
Post, export, submit, communicate, and store the real receipt.
BODHI INTELLIGENCE
AI can do the work. Controls decide what becomes truth.
Numbers come from parsers and deterministic engines. AI extracts, classifies, explains, and prepares. Material actions still require evidence, policy, permission, and confirmation.
Parser owns the numberNo model arithmetic becomes a source value.
Math and policy own the gateFailed integrity never becomes a silent post.
AI owns the suggestionProvider agreement is not fake probability.
The professional owns authorityFiling, payment, and material posting remain controlled.
Bodhi CopilotEvidence mode
“Why does this client’s turnover differ?”
Books snapshot · GSTR period · reconciliation rows
Preview onlyNo mutation requested
INTEROPERABILITY, NOT LOCK-IN
Meet every client where their books already live.
Each connection is truthful about configuration, heartbeat, consent, checkpoints, conflicts, and reconciliation.
TallyXML and approved local bridge
Zoho BooksOAuth and organization scope
VyaparDocumented exchange profiles
GST / ERIAccredited provider boundaries
WhatsAppOfficial Cloud API channels
AAConsent-based bank feeds
Connection names describe supported architecture and roadmap. A provider is shown as connected inside Bodhi only after a real verified probe.
BUILT FOR FINANCIAL TRUST
Security is a workflow, not a badge.
Tenant isolation, least privilege, encrypted evidence, no secret-bearing logs, append-only history, provider receipts, and truthful failure states are part of the operating model.
Encrypted evidenceAES-256-GCM before object storage; authenticated decrypting access.
Verified identitySupabase sessions, workspace membership, role, assignment, and support scope.
Immutable accountabilityApprovals, posting, consent, exports, and provider events remain traceable.
No credential shortcutsNo bank password collection, personal WhatsApp scraping, or fake accreditation.
ONE FIRM. EVERY CLIENT. CONTROLLED AUTOMATION.
Make repetitive work disappear. Keep professional judgment visible.
Active Client
Firm WorkspaceClient No client selectedPeriod FY not setNo data loaded
Offline shell Live financial data is unavailable. Unsaved non-sensitive form drafts remain on this device only.
Update ready Reload to use the latest controlled shell.
COMMAND CENTRE
Welcome back, Partner.
Firm-wide operational status across all clients, obligations, and exceptions.
Client Groups 0
0 Legal Entities
GST Registered 0
Active GSTINs
Active Books 0
Accounting Engagements
Statutory Audit 0
Form 3CD & Statutory
Open Exceptions 0
Requiring Action
COMPLIANCE RADAR
Statutory & SLA Deadlines
Live Calendar
0Overdue
0Due Today
0Within 3 Days
0Within 7 Days
0Within 15 Days
0Client Blocked
0Review Queue
0Awaiting Consent
DAILY WORK QUEUE
Active Obligations
Client / Entity
Obligation
Statutory Due
Stage
Assigned Staff
No obligations in this queue.
TEAM ALLOCATION
Staff Workload & Capacity
Team Member
Role
Assigned
Overdue
Review
PRACTICE PORTFOLIO
Client Master Hub
Scalable multi-entity client directory with server-side pagination and filters.
Client Group
Primary Legal Entity
Entity Type
PAN
Primary GSTIN
Partner / Manager
Deadlines
Next Due Date
Risk
Actions
No clients found matching the query.
CL
Client Name
CL-000000Status unavailable
Primary Entity: — · PAN: —
COMPLIANCE CALENDAR
Statutory Deadline Radar
Monitors GST, TDS, ITR, Advance Tax, and Audit obligations firm-wide.
Compliance Form
Client Entity
Period
Statutory Due Date
Internal SLA
Stage
Assigned Staff
CAPACITY & ALLOCATION
Staff Workload Matrix
Real-time review backlogs, overdue items, and task distributions.
Staff Name
Email
Firm Role
Active Work
Overdue
Review Backlog
Blocked
TEAM & ACCESS
Workspace Membership
Invite team members with a defined role. Access remains server-enforced and workspace scoped.
CURRENT MEMBERS
People with workspace access
Name
Email
Role
Joined
No workspace members are available.
ROLE-BOUND INVITATION
Invite a team member
The invitation is bound to the verified email address and expires automatically.
ACTION REQUIRED
Operational Exceptions Tracker
Bank math failures, unclassified transactions, and missing compliance proofs.
Dr = Cr enforced Atomic numbering Reversal, never erasure Integer paise
Trial balanceNot calculatedSelect a client with configured booksOpen receivables₹0.000 bill referencesStock value₹0.000 active itemsReview queue0Drafts awaiting controlled posting
Ctrl + A save
IMMUTABLE REGISTER
Voucher history
Posted, reversed and revised records remain visible.
0 records
Date
Number
Type
Narration
Debit
Credit
Control state
No vouchers posted. Bodhi never inserts fake transactions.
No ledgers created yet. Set up the chart, then create only real masters.
REFERENCE-LEVEL CONTROL
Receivable & payable ageing
New Ref, Agst Ref, Advance and On Account settlements with concurrent over-allocation protection.
₹0.00 open
Side
Party
Reference
Due date
Age bucket
Open amount
No open bill references.
GODOWN · BATCH · VALUATION
Stock control
FIFO, LIFO, weighted average, standard cost and last purchase are calculated from retained movements.
₹0.00
Item
Unit
Valuation
Quantity
Value
Control
No stock items. Inventory masters are created only from real company data.
LIVE, RECONCILED REPORTS
Financial statement control room
Every number drills back to a voucher and source evidence reference.
Net result₹0.00Trading + indirect resultTotal assets₹0.00As of report end dateLiabilities + equity₹0.00Including current earningsBalance sheet controlNot calculatedDifference not calculated
Link the statement identity to the exact books ledger before analysis.
STATEMENT ANALYSIS
Analyse verified source
Use the original bank-generated CSV, XLSX, or text PDF. Safety scanning must pass before parsing.
STATEMENT CONTROL
Statement
Pending
Safety—
Identity—
Coverage—
Math—
Books—
Continuity not evaluated
SOURCE-LINKED ROWS
Normalized transactions
0 rows
Date
Narration
Channel
Counterparty
Direction
Amount
Balance
Category
Match
Source
BANK RECONCILIATION
BRS matches
Bank Row
Voucher
Match
Date Gap
Status
CONTROLLED DRAFTS
Voucher proposals
Date
Type
Narration
Amount
Target Ledger
Status
BULK BANK INTELLIGENCE · EVIDENCE FIRST
Every account. One control story.
Process up to 100 retained statements across clients and accounts with exact identity, period, continuity, duplicate, coverage and math gates—then inspect BRS, transfers, recurring payments, EMI candidates, anomalies and independently reviewed semantic exceptions.
Batch stateNO BATCHCreate a retained-source batchSources / rows0 / 0Encrypted evidence onlyExceptions0Material and gate failuresSemantic reviewNOT RUNAgreement is not probability
BATCH BUILDER
Add retained sources
Choose a registered account and Smart Inbox evidence. Passwords stay only in browser memory for the current run.
CONTROLLED ACTIONS
Run, review and freeze
Processing continues around a failed item. Nothing posts, files or exports tax JSON automatically.
No fake statutory export
GST/Income Tax output remains unavailable unless exact official schema and applicable facts are proven. Proprietary Tally backups are never reverse engineered.
INTER-ACCOUNT
Transfer candidates
No batch analysis.
BEHAVIOUR
Recurring and EMI candidates
No patterns calculated.
MATERIAL REVIEW
Exceptions and evidence
No exceptions loaded.
EVIDENCE INTAKE
Smart Inbox
Bulk files enter one safety, duplicate, password, classification, encryption, and review pipeline.
MULTI-FILE INTAKE
Drop client evidence
Up to 20 files per batch. Originals are encrypted before object storage. Files do not enter OCR or books until safety gates allow processing.
INTAKE CONTROLS
Before any extraction
Magic-byte identityExtension and MIME do not establish file truth.
Malware and archive safetyUnscanned or risky files remain quarantined.
Tenant content hashRenaming the same file does not create a duplicate.
Password stateProtected PDFs request the supplied password; no guessing.
Encrypted evidenceAES-256-GCM before R2; authenticated download only.
LATEST BATCH
Intake result
Pending
File
Class
Safety
Password
Processing
Evidence ID
CLIENT COLLECTION
Open document requests
Request
Type
Period
Due
Status
No document requests for the active client.
STRUCTURED REQUEST
Ask the client once
Specify exactly what is required, for which period, and when. A validated upload can complete the request automatically.
GST CONTROL PLANE · PREPARATION AVAILABLE
From books snapshot to consent gate.
Multi-GSTIN periods, evidence-locked 2B, explainable matching, October 2025 IMS and BoE rules, Table 4, return snapshots, IRN/EWB preflight and professional DRC workpapers—without pretending a provider filed anything.
Immutable period snapshot Invoice-level 2B matching Single-use taxpayer consent Production blocked by default
Active GSTINNot configuredFormat verification requiredReturn period—Open a controlled periodData readinessNOT READYBooks and 2B not frozenProvider truthNOT_CONFIGUREDConnection requires verified probe
One client can hold multiple registrations without losing state and period scope.
PERIOD ACTIONS
Prepare, never silently file
EVIDENCE-LOCKED GSTR-2B
Inward document source
Direct upload remains preview-only. IMS approval needs the matching encrypted Smart Inbox vault object.
NO SOURCE
2B / BOOKS EXCEPTIONS
Reconciliation
0 rows
Status
Match type
Taxable variance
Tax variance
Reason
Run invoice-level reconciliation.
IMS PROPOSALS
Action review
0 records
Action
Rule reason
ITC impact
Allowed
No IMS proposal prepared.
RETURN SNAPSHOTS
GSTR-1 and GSTR-3B preparation
Versioned internal normalized snapshots. They are not represented as official portal JSON or filed returns.
Provider submission blocked
Freeze books, then prepare returns.
No statutory action without all gates.
Maker-checker approval, single-use scoped taxpayer consent, accredited provider configuration and a real acknowledgement are separate requirements. OTP/DSC values are never retained.
TDS/TCS aggregation, challans and corrections; payroll proofs and effective rules; AIS/26AS/Form 16 evidence graph; explainable ITR-1 through ITR-7; official CBDT schema validation and a fail-closed ERI boundary.
Seven official schemas hashed Integer-paise computation Evidence reconciliation Accreditation required
Assessment year2026–27FY 2025–26 rulesOfficial schemasITR 1–7Local hash-verified CBDT copiesActive caseNot selectedCreate an evidence caseERI stateACCREDITATION_REQUIREDNo connection from credentials alone
TAXPAYER CASE
AY-specific evidence graph
COMPUTE & SELECT
Explainable form decision
SOURCE RECONCILIATION
AIS · 26AS · Form 16 · books
0 records
Status
Match
Variance
Evidence basis
Ingest at least two evidence sources.
FROZEN REVIEW SNAPSHOT
Official-schema gate
Internal workpaper export remains available. Official JSON is labelled valid only after the exact AY/form schema passes.
Compute a case first.
DEDUCTOR & DEDUCTEE
Master setup
THRESHOLD ENGINE
Compute TDS
EFFECTIVE STATUTORY PROFILE
PF · ESI · PT · LWF · gratuity
Declarations need proof
Employee regime, other-employer income, perquisites and deduction claims remain unverified until retained evidence is reviewed.
No timeless rates
Every payroll run retains state, effective version and exact statutory calculation inputs.
ERI TYPES 1 / 2 / 3
ACCREDITATION_REQUIRED
Preparation, computation and manual JSON/workpaper export continue without accreditation. Add-client, prefill, validate/submit, e-verify and acknowledgement remain provider- and consent-gated.
Short-lived encrypted sessions
Session tokens are AES-256-GCM encrypted. OTPs and DSC private keys are never accepted or retained.
Scoped consent
Each add-client, prefill, submit, e-verify or acknowledgement action uses a separate expiring single-use consent.
Official schema validation is exact, not implied.
Seven CBDT AY 2026-27 schema copies are retained with SHA-256. A Bodhi workpaper is not renamed as official ITR JSON unless the selected form schema validates it.
TAX EXCHANGE · CA/AUDITOR AGENTS · FILE FIRST
Bring official downloads in. Send reviewed work out.
Versioned AIS, TIS, 26AS, Form 16/16A, TDS, challan, acknowledgement and GST offline-file profiles with exact taxpayer/period identity, source hashes and integer-paise controls—plus evidence-linked agents that prepare drafts without filing, paying, signing or scraping portals.
JSON · CSV · XLSX PAN · GSTIN · TAN identity Cross-source reconciliation L1 draft-only agents
No authenticated portal login, CAPTCHA bypass, OTP or DSC.
RECONCILIATION AND EXPORT
Source-to-source review
Compare independent file sources; export workpapers, not fabricated portal files.
Import two independent sources to reconcile.
Official export is schema exact
ITR JSON requires the exact locally retained official schema. GST/TDS snapshots remain internal workpapers unless their own official/provider gate passes.
PROFESSIONAL AGENT
Prepare the work, preserve authority
Agents inspect only assigned tenant evidence and produce reviewable tasks.
DRAFT TASKS
Human review queue
Review changes task state only; it never executes the underlying action.
No agent run prepared.
Portal and authority boundaryNo authenticated government scraping, CAPTCHA bypass, OTP collection or DSC automation. Agents cannot file, pay, grant consent, sign opinions, issue UDIN/SRN/ARN, post vouchers, deploy or rotate secrets.
BODHI ASSURANCE · PROFESSIONAL JUDGMENT PRESERVED
Every conclusion has a trail.
Acceptance to archival, evidence-linked workpapers, reproducible sampling, JE risk indicators, 43B(h), notice mutation gates and MCA preparation—without automated opinions, fabricated UDINs or invented SRNs.
EngagementNot configuredCreate acceptance fileWorkpaper library64Professional conclusion templatesBooks snapshotNOT FROZENExport parity gateOpinion / UDINNOT GENERATEDPartner and external systems only
ENGAGEMENT ACCEPTANCE
Create controlled file
FILE CONTROL
Lifecycle actions
SA 230 WORKPAPER
Prepare evidence record
SA 530 SAMPLING
Freeze and select
SECTION 43B(h)
Evidence-first MSE master
YEAR-END CONTROL
15 / 45-day assessment
Partial payments, debit notes, non-trade balances, disputes, year-end outstanding and post-year payment remain separate facts.
NOTICE IDENTITY GATE
Ingest normalized evidence
Mutation protection
Changed PAN/GSTIN, AY/FY, date, amount or reference creates a different mutation hash and cannot replace accepted evidence.
Draft, not legal advice
Issue trees retain missing evidence and official-source research placeholders. Partner review and client authority remain mandatory.
MCA PREPARATION
Entity and filing calendar
No unsupported portal automation
Forms, calendars, registers, checklists and manual/provider exports are prepared without scraping MCA or fabricating SRNs.
Rule 11(g) analytics
Edit-log analytics provide exceptions only. The auditor’s reporting conclusion remains explicit professional judgment.
Automation prepares evidence; the auditor owns the opinion.
CARO, 3CD, Schedule III, going concern, fraud, notices, UDIN and filing outcomes are never inferred from a green checklist.
F2 EXPRESS POS · CONTROLLED CORE
Sell fast. Settle truthfully.
Inventory-aware counter billing, exact GST/discount/rounding, split tender, offline idempotency, returns, 58/80mm print and payment evidence—where a QR is never proof of payment.
SKU and stock Split tender 58 / 80mm Settlement evidence
ShiftCLOSEDCashier/location controlLast sale—No completed salePaymentNO EVIDENCELink/initiated ≠ paidStock—Godown movement enforced
CASHIER SHIFT
Open counter
THERMAL PREVIEW
Payment truth on receipt
Complete a controlled sale to generate the receipt.
Payment has a lifecycle.
LINK_CREATED → INITIATED → PAID_EVIDENCE / FAILED / REFUNDED_EVIDENCE → SETTLEMENT_RECONCILED. Only verified webhooks and settlement evidence move financial state.
CLIENT EXPERIENCE · ENTITY SCOPED
One place for every “please send”.
Mobile tasks, structured requests, secure uploads, query threads, approvals, consent, acknowledgements, invoices and payment truth—with official WhatsApp/email delivery states and quiet-hour automation.
Mobile first Entity isolated Quiet hours Webhook delivery truth
Client PortalSelect client
Secure workspace
Open requests0Deadlines0Invoices0Payment events0
No portal requests.
STRUCTURED INFORMATION REQUEST
Ask once, clearly
CHASE PREFERENCES
Respect time and consent
OFFICIAL BUSINESS COMMUNICATIONS
Embedded Signup v4 boundary · Provider evidence only
NOT_CONFIGURED
Official Meta Cloud API and signed webhooks only. Personal WhatsApp Web QR sessions and fake “delivered” states remain prohibited.
No verified channels.
BODHI ANALYTICS · FROZEN SOURCE REPORTING
Every number can answer “why?”
Partner, manager, staff, client/CFO and auditor dashboards share exact KPI contracts, evidence drill-through and one frozen source across PDF, XLSX and CSV. Empty data stays empty; a forecast is always a range with assumptions.
Source-query hashes Frozen snapshot parity Indian formats Accessible charts
ROLE VIEWSelect a client to open decision support. Asia/Kolkata · explicit period Compensation always restricted
No source data in this scope
Bodhi will not fill an empty tenant with sample revenue, automation percentages or forecasts. Post or import reviewed source records, then recompute.
Unbilled WIP—Waiting for sourceReceivables—Waiting for sourceRealisation—Collections / issued billingUtilisation—Approved billable / available
ACCESSIBLE FINANCIAL SIGNAL
Cash, working capital and exposure
Not a prediction
CLIENT / CFO LENS
Decision support with boundaries
No client insight loaded.
KPI CONTRACTS & EVIDENCE
Definition before decoration
Numerator, denominator, exclusions, timezone, query hash and evidence remain inspectable.
Metric
State
Numerator
Denominator
Value
Source / exclusions
Recompute to inspect KPI contracts.
FROZEN REPORT STUDIO
One snapshot. Three exact views.
20-sheet workbook, Indian-formatted PDF and control-total CSV use the same immutable snapshot ID.
ASSUMPTION-BOUND FORECAST
Range, never certainty.
Actual book history stays visually separate from scenario bounds. Basis points are explicit.
PRACTICE COMMERCIAL LOOP
Know the work. Bill it. Collect it.
Integer-minute time, recurring idempotency and evidence-defined collections feed the analytics above.
SERVICE & TIME
Capture commercial work
INVOICE & COLLECTION
Idempotent billing
Restricted profitability
Staff/client roles never receive compensation or staff-cost metrics. Recommendations require assignment authorization.
Never paste a key here. Use OS keychain or encrypted local vault.
Local does not mean trusted.Local AI must pass licence, checksum, loopback/no-public-port, signed-update, encrypted-cache and evaluation controls. It remains L1 draft-only and cannot file, pay, sign, consent, post material entries, deploy or rotate secrets.
BODHI SECURITY · DEFENCE IN DEPTH
Assume attack. Expose nothing.
Layered request limits, bot challenge boundaries, tenant isolation, encrypted diagnostics, owner alerts, secret posture and model-route confidentiality—with no claim that any system is unhackable.
Layered quotas Bot challenge Secret values never returned Confidential intelligence routes
Model and prompt identity is confidential. Reverse prompting, hidden-prompt extraction, provider/model self-identification and fallback-route disclosure are blocked. Public answers identify only as Bodhi Intelligence. Legally required active-subprocessor disclosure remains separate from model identity.
Overall postureNOT MEASUREDNo fake secure badgeRuntime limitsNOT MEASUREDIP · user · tenant · routeBot challengeNOT_CONFIGUREDServer verification onlyDiagnosticsNOT MEASUREDEncrypted or metadata-onlyCanonical dataNOT MEASUREDPostgreSQL required in production
NOT ASSESSED
Run operational readiness to see exact deployment blockers.
OWNER ALERTS
Security and reliability queue
High-severity records are pending owner review until acknowledged. Delivery is never claimed without provider evidence.
Measure posture to load alerts.
SANITIZED ERRORS
Encrypted diagnostic envelopes
No secrets, prompts, document contents, PAN/GSTIN or raw financial rows.
No sanitized errors loaded.
SECRET LIFECYCLE
Aliases and configuration only
Values, fingerprints and model routes are never returned to the browser.
Secret posture not loaded.
CLIENT SUPPORT
Report a problem safely
Descriptions are redacted and encrypted when the observability key is configured.
AUDIT LEDGER PROOF
Cryptographic Integrity Check
Reports whether a persisted tamper-evident hash chain is configured. Stored events alone are never presented as cryptographically verified.
ENVELOPE ENCRYPTION
AES-256-GCM Status
Checks whether the server-side master key is configured. A named algorithm without a key is not reported as active encryption.
BODHI INTELLIGENCE · GOVERNED FOUNDATION
Useful when grounded. Silent when uncertain.
Rules and approved client memory first; one capability-routed provider when needed; evidence citations, multidimensional gates, shadow evaluation, editable voice transcripts and draft-only actions with confirmation and undo.
Prompt-injection isolation Provider-neutral routing Shadow evaluation Preview and undo
PolicyENABLEDTenant-scoped autonomyCapability meshNOT_CONFIGUREDPrivate identities concealedModeSHADOWEvaluation before autonomyKill switchCLEARTenant/task control
Filing, payments, e-verification, OTP/DSC use and client consent cannot be completed from voice. Transcript preview does not weaken RBAC or maker-checker gates.
No provider, no invented answer.
Circuit breakers, budgets and kill switches fail closed. Provider/model identities and secrets stay server-side.
BODHI SYNC · CONTROLLED CONNECTOR PROGRAM
Move books without losing identity.
Preview-first Tally XML, a signed-request outbound local agent, stable checkpoints, explicit conflicts and post-sync count/hash/Trial Balance controls—never a green badge from configuration alone.
Tally agentNOT PAIREDNo signed heartbeatActive company—Reported by a fresh device heartbeatExchange batches0Preview, applied and reconciledLast controlNOT RUNNo count/hash/TB evidence
MANUAL TALLY EXCHANGE
Upload → map → approve → apply
Documented XML only. Unknown groups, ledgers, voucher types and godowns stop for explicit mapping.
File exchange available
MAPPING PREVIEW
Batch
PREVIEW
Object
External identity
Action
State
Exception
OUTBOUND LOCAL AGENT
Pair one trusted machine
The cloud never calls localhost. The agent opens no inbound port and signs every outbound request.
No agent is paired. Static XML export is not live sync.
Zoho Books
NOT_CONFIGURED
OAuth v3 organization scope, incremental checkpoints and signed webhook boundary. No credentials in the browser.
Vyapar
FILE_EXCHANGE_ONLY
Versioned CSV/XLSX profiles, exact decimal controls and dry-run quarantine. No undocumented direct API claim.
Account Aggregator
NOT_CONFIGURED
Consented provider boundary with purpose, scope, duration, revocation and fetch audit. Banking passwords and PINs are prohibited.
Real Tally acceptance is an external gate.
Fixture and local mock contracts are verified. A release is marked live only after a licensed Tally machine produces a timestamped heartbeat, company identity, acknowledgement, count/hash and Trial Balance reconciliation.