Legal businessAster Retail Pvt LtdGSTIN29AABCU9603R1ZJBranch / locationIndiranagar · Retail floorWorkspace roleBusiness owner

Owner / Security admin · connected fictional workspace

Settings & access

Organisation, modules, users, roles, authentication, privacy, plans, and integrations.

Coverage environment · Settings & access is enabled by a server-shaped access snapshot (permission version 6, assurance AAL2). The production API independently rejects missing, cross-domain, and out-of-scope access; this fictional preview creates no credential.

Integration centre · fictional sandbox

Commit first. Call providers second. Reconcile before retry.

One adapter contract governs tax documents, messages, bank-file previews, public API clients, webhooks and future providers.

Certification ready
  1. 01Core stateINV-2026-001 committedLedger, audit and outbox remain intact
  2. 02Adapter handoffIRP contract v1Secret reference · no value exposed
  3. 03Provider resultTimeout · outcome unknownBlind resubmission blocked
  4. 04ReconcileStatus lookup requiredRequest/response hashes archived
  5. 05Final truthPendingNo duplicate official document
Deterministic local evidence only · no IRP, EWB, email, WhatsApp, bank or customer system contacted
IRP + E-Way Bill

Primary degraded · failover healthy

Sandbox
Email + WhatsApp

Retry and delivery states ready

Sandbox
Bank statement

CSV v1 preview · nothing posted

Sandbox
Public API + webhooks

v1 · scoped · signed · replay-safe

Sandbox

Credential boundary

References, never values

  • Vault/KMS/secret-manager URI only
  • Environment + tenant + provider scoped
  • Rotation and revocation remain auditable
  • Logs and archives redact credentials

Failure control

Committed means preserved

  • Provider call runs after the business commit
  • Bounded backoff; dead-letter/manual fallback
  • Unknown blocks the submission transition
  • Internal time separated from provider delay

Live activation

External inputs still required

  • Commercial provider and signed contract
  • Sandbox/live credentials in secret manager
  • GSTIN/IRP onboarding and API authority
  • Webhook URL, allowlist, consent and templates
Production connections not activated

Security & privacy command · Fictional tenant

Know what may be kept, shared, or erased—without breaking the books

Integrity baselineAll plan-independent controls active

ASVS 5.0.0 L2 baseline · selected L3 high-impact paths · source review 22 Aug 2026

94/ 100verified posture
Open alerts1 highrouted · within SLA
Privacy requests1 activeidentity verified
Legal holds1 activedisposal paused
Vulnerability SLA0 overduehigh ≤ 14 days
Security chain4,281 eventshash verified

Rights request · PRV-2026-0041

Erasure request from principal …0091

In reviewDue 15 Sep · Tenant fiduciary
01RequestReceivedAccess / correction / erasure
02IdentityVerifiedAuthority evidence …a72f
03RetentionHold checkedTax + accounting preserved
04OutcomeRestrict + maskOptional profile anonymised
May anonymiseBirthday · marketing profile · free-form notesPurpose ended · no active authority
Must retain, restrictTax invoice · journal · payment allocationLegal books intact · access narrowed
Legal holdDispute LH-0017 · activeNormal disposal suspended · reviewer A. Nair

The preview uses synthetic references. The implementation records every request, verification, hold check, decision and response as tenant-scoped evidence.

Security alert · ALT-0428

Repeated cross-tenant denials

High severity3 denials / 90 seconds · API identity svc-reports
  1. OpenRouted to security on-call
  2. AcknowledgedOwner and timer recorded
  3. ContainedCredential revoked · queue blocked
  4. ClosedReason + evidence hash retained
Security log proofprevious 7bd1…9a02 → event 04ec…773fSeparate from business audit · no token or PII payload

Purpose register

Four data classes

Public published catalogueInternal operating configurationConfidential customer + supplierHighly restricted salary + bank + credentials

12 active purposes · each binds basis, fiduciary role, class, recipients and retention policy.

Notice & processors

Versioned sharing truth

Notice
v2 · effective · SHA-256 …b19c
Consent
Promotional withdrawn · transactional retained
Processors
3 active · India storage region
Sharing
Last disclosure purpose-bound

Secure release

Gate evidence

  • SAST / SCA / secret scan
  • IaC / container / API scan
  • CycloneDX SBOM + signed provenance
  • Rollback + tenant isolation
  • Critical 7d · high 14d SLA
No live production provider or certification is claimed by this fictional preview.

Identity/access response

Privileged session: passkey ready

Passkey-preferred MFA, rotating server sessions, revocation, recent re-authentication, trusted devices and device-bound POS PINs.

Organisation context

Trusted server scope

Aster Commerce subscriberAster Retail Pvt Ltd · legal businessIndiranagar branch · Counter 04