Questions consultants ask first

You are being asked to connect a client's GST portal account. These are the answers you need before you do.

Which GSP do you use, and whose licence is it?

Alankit. GST return data is retrieved through Alankit, a GST Suvidha Provider licensed by GSTN, under Alankit's licence — not ours. There is no other route into the portal, and nothing is scraped from the portal website.

Do you store the client's GST portal password?

No. Connecting a GSTIN uses the portal username and a one-time password. We store the encrypted API session the portal issues, for the life of that session only. When it expires, a fresh OTP is required. Details are in the Privacy Policy.

Where is client data held, and who can see it?

In a managed database in an India region, encrypted at rest and reached only over TLS. Access is scoped to your organisation, so your practice sees only your clients. Inside Pinnacle, production access is limited to the named administrators who run the service and is used only to investigate a fault you have reported.

How does OTP re-authentication work across 30 GSTINs?

Each GSTIN carries its own portal session, and the portal requires the OTP per GSTIN — that is a GSTN rule, not our choice, so it cannot be bulk-automated. In practice a session lasts for the working window, so a monthly cycle needs one OTP per client per connection. The Clients page shows a checklist of which GSTINs are connected and which are pending, so you can work through them, and reports for a disconnected client say so plainly instead of showing zero.

What happens when the GST portal or an operation is unavailable?

The report still renders and names the exact period and operation that did not return data, as a note. We never substitute a zero for missing data. Some operations are simply not part of the portal's API catalogue — notices and orders is one — so those are tracked manually in the Notices section, with deadlines and law references working the same way.

What exactly does the AI do?

The engine that finds anomalies and attaches the section, rule or notification is deterministic. Citations are never generated by a language model. AI is used only to draft the client-facing wording of an advisory and to summarise a period for you — you edit and approve it before it goes anywhere.

Does it file returns or generate e-invoices?

Yes. Firm owners and admins can prepare and file GSTR-1 and GSTR-3B, including nil returns, through Alankit after recording the client's authorisation. The return is reconciled against books and portal-validated first, and it can be run in dry-run mode before anything is submitted. Filing uses EVC: your firm enters the OTP on the client's instruction, and the OTP is never stored. The ARN, filed figures and the people who prepared, approved and filed the return are retained as evidence, ready for your firm to confirm with the client.

The invoicing tool produces GST-compliant documents but does not generate e-invoice IRNs or QR codes, create e-way bills, or support DSC filing. Return filing is EVC-only.

What are the trial terms?

30 days, no credit card, up to 3 GSTINs, every Professional feature. Your 30 days start when you connect your first GSTIN, not when you sign up. Nothing is charged automatically. When the trial ends, portal connections are disconnected and your data stays read-only for 30 days so you can export your reports and choose a plan. Want it deleted sooner? Email us.

A tip for getting started quickly: connect your own firm's GSTIN first — it needs no client OTP.

Is the statutory content kept current?

Yes, and it is dated. Every finding and every export carries a “law current as of” date, and rate checks are tested against the slabs in force on the date of supply — which matters in a year that spans a rate change.