Compliance & Security
Working with the DGFT
The ebrc.in platform, an Eximfiles product, works directly with the Directorate General of Foreign Trade (DGFT) portal. You connect your DGFT account once; your inward remittance records then appear in the app, and every eBRC application you submit goes to the DGFT. Certificates (eBRCs) are issued by the DGFT itself. The platform helps you prepare, submit, and keep track of them. Eximfiles is an independent technology provider: it is not affiliated with, endorsed by, or acting for the DGFT or any government body.
Acting on your instructions
When you sign up you accept our Terms of Service, and when you connect your DGFT account you give express, recorded consent appointing Eximfiles as your authorised agent: we access the DGFT portal on your behalf, retrieve your remittance records, and submit the filings you initiate or approve. Every filing made this way is your own self-certified submission, exactly as if you had made it on the portal yourself. The mandate is revocable at any time by disconnecting your DGFT account, and we keep an audit trail of consents, instructions, and submissions.
Nothing is binding until you say so
Every workspace has a Test mode and a Live mode. Test submissions go to the DGFT's sandbox, so you can check your format and mapping without creating a real certificate. Switching to Live is an explicit step, and every certificate records the environment it was created in. Every row of a bulk upload is checked before anything reaches the DGFT, and resubmitting never creates a duplicate filing.
Protecting your information
- Your DGFT password: encrypted at rest and never shown back to you. When you update it, we replace the stored password immediately.
- Your data: we handle personal data in line with the Digital Personal Data Protection Act, 2023 and other applicable Indian law. See our Privacy Policy for details.
- Safeguards: we apply administrative, technical, and physical safeguards to protect your information.
- What we never do: we do not sell your data, and we do not use your filing data for advertising.
For platform partners
Access to the platform's API is contract-gated: production access follows a signed NDA and production agreement, completed electronically. API keys are shown once at creation and are never stored in a readable form, and every certificate created through the API records whether it was made in the sandbox or in Live. Programmatic use is governed by our API Terms, which bind platforms to the same end-customer mandate and data obligations described above.
Responsible disclosure
If you believe you have found a security vulnerability in the platform, write to amin@eximfiles.io with enough detail for us to reproduce it, and give us a reasonable opportunity to remediate before any public disclosure. Do not access data that is not yours, do not degrade the service for others, and do not test against Live accounts or real filings. We acknowledge reports and act on verified issues promptly.
Questions and grievances
If you have questions about compliance or how we handle your information, reach us through the contact form on this site. Our Grievance Officer under Indian law is Amin Naik (amin@eximfiles.io); see the Terms of Service and Privacy Policy for the full grievance process and your rights under the Digital Personal Data Protection Act, 2023.