Built to earn the trust of
institutional capital.
AIFLedger is the fund-administration platform used by Corpzo to service SEBI-registered Alternative Investment Funds in India. Every design choice here — from encryption to audit trails — starts from a single premise: institutional LPs never accept a "trust us."
Data protection
- ▸TLS 1.3 in transit; AES-256 at rest (MongoDB Atlas)
- ▸Field-level encryption for PAN, Aadhaar, bank details (roadmap Q3 2026)
- ▸Cookie consent + Google Consent Mode v2 (DPDP + GDPR)
- ▸Password hashing via bcrypt (cost 12)
Access control
- ▸Role-based access (13 roles, per-module CRUD grants)
- ▸TOTP-based 2FA available for every account
- ▸Session cookies HttpOnly + Secure + SameSite
- ▸Idle auto-logout after 30 minutes
- ▸Brute-force lockout after 5 failed attempts
Compliance
- ▸SEBI (AIF) Regulations 2012 — Category I / II / III aligned
- ▸DPDP Act 2023-ready (data minimisation, consent, purpose)
- ▸PMLA — investor screening and record-keeping (12+ years)
- ▸SOC 2 Type I — assessment in progress
- ▸Data residency: primary storage in India (Mumbai / Hyderabad)
Audit & immutability
- ▸Every mutation is audit-logged (user, IP, before/after)
- ▸Immutable audit stream (append-only, retained ≥ 7 years)
- ▸Maker-checker workflows on money movements
- ▸Full document vault with SHA-256 hashing
Availability
- ▸Target 99.9% uptime (measured monthly)
- ▸Nightly backups with 30-day retention
- ▸Point-in-time restore up to 24 hours
- ▸Disaster recovery: RPO ≤ 24h, RTO ≤ 4h
- ▸Status page: status.aifledger.com (launching soon)
Vendor management
- ▸MongoDB Atlas (data) · Emergent (hosting) · Resend (email)
- ▸Sandbox.co.in (PAN verification) · PostHog EU (analytics)
- ▸Every subprocessor covered by an executed DPA
- ▸Zero data shared with third parties for marketing
Responsible disclosure
If you believe you have discovered a vulnerability in AIFLedger, please report it privately. We commit to acknowledging within 48 hours, an initial triage within 5 business days, and a fix or accepted-risk statement within 30 days.
security@aifledger.comDPDP / GDPR requests
Data-subject requests — access, erasure, portability, correction — are honoured within 30 days as required by the DPDP Act 2023. Enterprise customers can request a signed Data Processing Agreement (DPA).
dpo@aifledger.com