मुख्य सामग्री पर जाएँ
Pathak Associates

How we protect your documents

We ask for PAN cards, bank statements and Form 16s. This is what happens to them — encrypted private storage, download links that expire in minutes, no password to steal, and access limited to the person doing your work.

अंतिम अद्यतन 1 August 2026

Why this page exists

To do your filing we need documents that would do real damage in the wrong hands — PAN, Aadhaar, bank statements, Form 16, sometimes a full picture of your finances. Asking for those without explaining how they are handled is not reasonable.

This page describes what we actually do, in enough detail to be checkable.

Documents

Uploaded documents go straight from your browser to encrypted private storage. They do not pass through our application servers, and the storage bucket is not publicly readable — there is no URL that serves a document to an anonymous visitor.

Every download is a signed link that expires within five minutes. A link that is forwarded, logged or screenshotted stops working almost immediately.

Files are stored under opaque identifiers rather than names, so the storage key reveals nothing about whose document it is or what it contains. That key never leaves our servers and never appears in an API response.

Access is limited to you and the member of staff assigned to your order. Every access is recorded.

Signing in

There is no password. Signing in sends a six-digit code to your email, valid for ten minutes and usable once.

That is a deliberate choice: most account compromises start with a password reused from somewhere that was breached. A code that does not exist until you ask for it, and stops working ten minutes later, cannot be reused.

Session tokens live in cookies that JavaScript cannot read. A malicious script on the page — from a bad dependency, say — cannot take your session, which a token in browser storage could not prevent.

We will never ask you for that code by phone, email or WhatsApp. Anyone who does is not us.

Payments

We do not hold card details. Bank transfers happen inside your own banking app and we see only the reference number you tell us. Where online payment is enabled it runs through the payment gateway, and card numbers never reach our servers.

Payment confirmation is done by a person matching the reference against our bank statement, not automatically from what a browser reports.

Our own credentials

Gateway keys, bot tokens and similar secrets are encrypted at rest with AES-256-GCM rather than stored as readable text, and they are never returned to a browser — the admin console shows a mask, not the value.

Staff accounts carry only the permissions their role needs. Being able to see an order does not mean being able to change a payment or a setting.

Retention

Tax records are kept for eight years from the end of the relevant assessment year, because assessments can be reopened within that window and a destroyed record is one that cannot defend your position.

After that they are deleted rather than archived indefinitely. You can ask for a copy of anything we hold, at any time.

Reporting a problem

If you have found a security problem with this site or the portal, please tell us at pathakassociates.ranchi@gmail.com rather than posting it publicly, and give us a reasonable chance to fix it.

We will acknowledge within two working days, tell you what we have found, and credit you if you would like to be credited. We will not pursue anyone who reports a genuine issue in good faith.

संपर्क

Pathak Associates
302, Modi Heights, Ratu Road
Ranchi, Jharkhand 834005

pathakassociates.ranchi@gmail.com · +91 79034 45348

कॉलबैक चाहिए