Security & Trust

Your clients trust you with their lives’ paperwork. We take that seriously.

Passports and visa files. Bank statements and salary slips. Company licences and shareholder documents. Legal matters and engagement letters. Loan applications and KYC. Insurance claims — and the immigration medicals and health reports clients submit to authorities. The files in your OS are the most sensitive things your clients own. Here is exactly how they’re protected.

Every person sees only what their role allows

Access is role-based across the whole OS — sales sees sales, accounts sees accounts, a case officer sees their cases. Managers scope by team and branch. Ask Euphoric answers only from data the asking person is allowed to see.

Every action is recorded

Views, edits, payments, deletions, logins — an activity log records who did what and when. It’s how you answer “who changed this?” in seconds, and how disputes end.

Your data is never used to train AI

AI features process your data under enterprise API terms. It is not used to train models, and it is not pooled with any other firm’s data.

Clients and partners are walled off

A client sees only their own case. A referral partner sees only the clients they referred. The separation is built into the system — not a policy someone has to remember.

Retention that respects your obligations

Documents are kept for the period your industry requires — configurable per firm — and nothing is deleted without review. Immigration regulators, legal bodies and financial rules each get the window they demand.

Everyday practices

  • Encryption in transit for every connection, and at rest for stored data
  • Password hashing and session controls; account lockout on repeated failures
  • Per-user rate limits on sensitive actions like uploads and logins
  • Payment gateways (Razorpay, Stripe) handle card data — we never store card numbers
  • Daily database backups with restore procedures
  • Least-privilege access for our own team, with logged access
  • Independent security review before major releases

We say only what is true today. Formal certifications are on the roadmap; if your firm needs a specific control or attestation, ask in the demo and we’ll answer plainly.

Questions firms ask about security

Where is our data stored?

In managed cloud infrastructure with encryption at rest and in transit. Firms with residency requirements should raise them in the demo — we discuss options case by case.

Can we export or delete our data?

Yes. Your data is yours: exports are available on request, and deletion follows your retention configuration — with review before anything is removed permanently.

Do you have SOC 2 or ISO 27001?

Not yet certified. We follow the practices those frameworks describe — role-based access, activity logging, encryption, backups, least-privilege — and formal certification is on the roadmap as we grow.

Is our data used to train AI models?

No. AI features process your data under enterprise API terms; it is never used for training and never pooled across firms.

Can we restrict access by branch or team?

Yes. Roles combine with team and branch scoping, so a manager sees their branch and a staff member sees their own work.

Have a specific requirement?

Bring it to the demo. We’ll tell you exactly what we do — and what we don’t yet.