A straightforward account of the actual security measures in place — without unverifiable claims.
User accounts and sign-in are handled entirely by Clerk, a specialist authentication provider. Parakh does not store passwords. Clerk applies industry-standard practices including secure session management and email verification.
Payments are processed directly by Cashfree (INR) and Dodo Payments (international). Parakh never receives, stores, or touches your card number, CVV, UPI PIN, or bank credentials. These never pass through Parakh's servers.
All traffic between your browser and Parakh is encrypted using HTTPS/TLS. This covers your GSTIN input, your reports, and your account data. Parakh does not serve any content over plain HTTP.
Reports are private to the account that generated them. No other user can access your reports. Admin access to user data is limited to the minimum required for support and maintenance. Database access is not exposed publicly.
Parakh collects only what is needed to provide the service: your account details (via Clerk), the GSTINs you search, and the reports generated. No advertising data, no behavioural tracking, no third-party marketing cookies.
Parakh is hosted on Vercel, which provides DDoS protection, automatic HTTPS, and infrastructure security at the hosting layer. Vercel's security practices apply to the underlying servers and network.
The party you are checking is not notified when you run a GSTIN check. No enquiry is filed, no alert is sent, and no record is created against their name in any system.
Parakh searches public registers — information that is openly available to any member of the public who chooses to look. Searching public records is not a privacy violation.
Your own search history is visible only to you in your dashboard. It is not shared with other users or with the entities you searched.
Parakh is a small, focused product. We do not make claims that cannot be substantiated:
Questions about security or data handling?