Review build Not the live site — unlaunched products, unfinished copy, no prices. comsky.ai →
Enterprise

Buying a suite is a risk decision before it is a software decision.

Multiple products, one control plane, one vendor, one invoice. This page is written for the three reviews that stand between a demo and a signature — security, legal and finance — and it tries to answer them in claims you can check rather than adjectives you cannot.

Isolation is enforced in PostgreSQL, not in application code

Tenant scope is injected on every query and row-level security is forced in the database. The default is fail-closed: a query that arrives without a tenant scope returns nothing rather than everything. Isolation does not depend on separate applications each remembering to add a filter, because that is the one thing applications reliably forget.

Credentials sit behind an authority no product can query

Passwords and second factors are held by a dedicated credential authority. No application database holds a password hash, and no product — not even ours — can read from that service. Signing in is a request to it and nothing more, so compromising any one product does not put credentials at risk across the rest.

The audit trail is append-only and hash-chained

Sign-ins, factor changes and administrative actions are written to a chained log. Removing an entry breaks the chain, and a broken chain is visible to you rather than only to us. Support access to your account requires an explicit, time-boxed grant, and that impersonation appears in your own log with a start, an end and a name against it.

Indian residency is a statement about disks

Instances, volumes, snapshots, backup copies and databases are created in Indian data centres and do not leave them. That is a claim about physical location, which is usually the question actually being asked when a policy says the data must stay in India.

Each of these is described in more detail, product by product, on the security page.

What we have not done

We are not certified yet, and we are not going to imply that we are.

Comsky does not hold ISO 27001 or SOC 2. There is no report to send you, and there is no letter from an auditor that says the controls above were tested by someone other than us. An external audit is planned, and when there is a report we will publish the report rather than the intention.

We say this here, near the top, because the alternative is that you find out in week six of a procurement cycle. If a certificate is a hard requirement in your policy, tell us now and we will tell you honestly whether the timeline works for you — a vendor who cannot meet a mandatory control is better identified early than argued with later.

What does exist is the list on this page, in writing, in the contract: the isolation model, the credential authority, the audit trail, residency, export and deletion. Those are the things an audit would test. They were built first because they are painful to retrofit; the certificate is the paperwork that follows them, not the other way round.

Procurement

The questionnaire, answered line by line.

These are the rows that appear on almost every security questionnaire we are sent. The middle column is the answer this kind of question usually gets.

The answer you usually get How Comsky answers it
Where is our data physically stored? “In the region you select.” Indian data centres, for every product in the suite. Named in the agreement.
How is tenant isolation enforced? Filtering in the application layer. Row-level security forced in PostgreSQL. Missing scope returns nothing, not everything.
Where are passwords stored? Hashed, in the product database. In a separate credential authority. No product can query it and no product database holds a hash.
Can your staff read our records? Only authorised personnel. Only under a time-boxed grant, which is written to your own audit log while it is active.
Is the audit log tamper-evident? Logs are retained. Append-only and hash-chained. A deleted entry breaks the chain and the break is visible to you.
Are you ISO 27001 or SOC 2 certified? Certification in progress. No. The audit is planned and we will publish the report when it exists.
How do we restrict what each role sees? Admin and non-admin. Per-role visibility inside each product. Payroll is not visible to sales; deals are not visible to accounts.
How do we offboard someone in a hurry? Remove them from each product. One identity across multiple products. Revoking it removes access to all of them at once.
Can we get our data out? Export is available on request. Export in an open format, initiated by you, without asking us or opening a ticket.
Can we have it deleted, and proven? Data is deleted per policy. Deletion on request, on a published schedule, confirmed back to you in writing.
How are API credentials scoped? An API key per account. Tokens scoped to one product and one permission set, listed with last use, revocable one at a time.
Who is accountable when it breaks? A support portal and a queue. A named escalation path, in IST, written into the agreement rather than a help page.
Control

The controls an administrator actually operates.

Security that only exists in the architecture diagram is not much use to the person who has to run it on a Tuesday.

Per-role visibility, not all-or-nothing

Roles are defined inside each product, so a salesperson does not see payroll and an accountant does not see every deal. The role a person holds in one product does not grant them anything in another.

Scoped API tokens

Every token is bound to one product and one permission set, is listed in the console with its last use, and is revoked individually. There is no shared secret whose rotation breaks six integrations at once.

Export in an open format

Your records, ledgers and files come out in formats that open somewhere other than Comsky. Export is a button you press, not a retention lever we hold — we would rather you stayed because leaving was easy and you chose not to.

Deletion that is confirmed

A deletion request is honoured on a published schedule and confirmed back to you when it completes, including the copies inside backups and snapshots.

Alerts on the administrative events

Failed sign-ins, new second factors, permission changes and unusual provisioning raise an alert to the account owner rather than resting in a log that nobody opens until an incident.

Encryption in transit and at rest

TLS between you and us and between our own services, encryption at rest on the platform, and in Comsky Backup an additional per-device key so the vault is encrypted before it leaves the machine.

Group structure

One account tree, several legal entities.

The hierarchy runs admin → distributor → reseller → customer. It was built for the partner channel, and a group of companies uses the same shape: a holding entity above, subsidiaries beneath it, each one a tenant in its own right.

01

Each entity is a real tenant

A subsidiary is not a folder inside the parent. It is a separate tenant, isolated in the database from its siblings by the same rule that isolates unrelated customers.

  • ·No cross-entity reads by default
  • ·Separate user lists and roles per entity
02

Central provisioning, local operation

Group IT can create entities, set policy and issue products from the top of the tree. The people inside each entity operate their own workspace without seeing the rest of the group.

  • ·Products enabled per entity
  • ·Central view of what each entity is running
03

Billing that matches the legal reality

Spend can roll up to one wallet and one GST invoice, or each entity can hold its own wallet and receive its own invoice under its own GSTIN. Finance decides, not the architecture.

  • ·Per-entity cost lines either way
  • ·One vendor and one agreement above it all
04

One offboarding, group-wide

A person who leaves the group loses one identity, and that removes their access across every product in every entity they were attached to.

  • ·Access reviewed from a single list
  • ·Admin actions land in the hash-chained trail
Support

An SLA, in IST, with a name on it.

The same timezone as your incident

We are in Noida and we work in IST. The person who can actually fix a problem is awake during your working day, which is the part that decides how long an outage feels rather than what the status page eventually says.

The SLA is a contract term, not a web page

Response and resolution targets, escalation contacts and the credits that apply when we miss them are negotiated into the agreement. We are not going to put numbers on a marketing page that a signed document would then contradict.

A named escalation path

You get people to escalate to, in order, rather than a queue. Vulnerability reports go to security@comsky.ai and are acknowledged within one working day, and we do not threaten anyone who reports something in good faith.

Adopt it one product at a time

Four of the multiple products are running today; the rest are being built and this site says so on each of their pages. The control plane, the isolation model and the agreement cover every product from the start, so adding a product later is a switch rather than a second procurement cycle.

Running today: Cloud, CRM, TallyBridge and Backup. In build: Books, HRMS, Telephony, Chat and Monitor.

Questions

What the review board asks next.

Will you complete our security questionnaire?

Yes, in your format, filled in by someone who understands the system rather than copy-pasted from a template. Where the honest answer is no, it will say no.

Do you have a DPA and a sub-processor list?

Both, on request. The sub-processor list names every third party that could receive customer data — a payment gateway, an SMS or WhatsApp carrier — and states exactly what each one receives.

Can we run a penetration test against our tenant?

Yes, with notice and a written scope, so we can tell the difference between your test and an actual attack. Send us the report either way.

What happens to our data if Comsky stops trading?

The export path is the answer, and it is the same one you already have: your data comes out in an open format whenever you want it, with no dependency on us processing a request. A supplier continuity clause can be written into the agreement.

Can we sign one agreement for the whole group?

Yes. One master agreement above the account tree, with each entity a tenant beneath it, billed together or separately as finance prefers.

Is any of our data used to train models?

No. Customer data is not used to train models, and the AI features inside the products work on your records to answer your questions rather than to improve anything we sell to somebody else.

Send us the questionnaire.

We would rather answer forty specific questions now than be a surprise in month three. Bring your security, legal and finance reviewers to the same call.