O
Oris Work
Pricing
About
Sign inStart free trial
O
Oris Work

CRM, projects, communication, and client portal - unified in one workspace by Oris Work.

India

Product

  • Features
  • Pricing
  • CRM & Pipeline
  • Project Management
  • Team Chat
  • Client Portal
  • Integrations
  • Custom Objects

Industries

  • Professional Services
  • Restaurants & F&B
  • Healthcare & Clinics
  • Real Estate
  • Universal

Compare

  • vs Zoho One
  • vs Perfex CRM
  • vs Bigin by Zoho
  • Tally Integration

Resources

  • Documentation
  • API Reference
  • Blog
  • Resources
  • Help Center

Company

  • About
  • Careers
  • Contact
  • Privacy Policy
  • Terms of Service
  • Cookie Policy

© 2026 Oris Intelligence Private Limited. All rights reserved.

All systems operational
PrivacyTermsCookiesSecurity
← All docs

Getting Started

  • Quick Start Guide
  • Inviting & Managing Team Members
  • Your First-Day Checklist
  • Roles and Permissions
  • Custom Roles
  • Switching Between Organisations
  • Sessions and Staying Signed In

Clients & Contacts

  • Adding a Client
  • Importing Clients from a CSV
  • Merging Duplicate Records
  • Client Groups
  • Client Services Card and Turning a Service On
  • Do Not Chase: Pausing Automated Reminders

CRM

  • Contacts & Companies
  • Deals & Sales Pipeline
  • Lead Management

Invoicing & Money

  • Invoicing
  • Payments & Receipts
  • Setting Invoice Due Dates
  • Estimates and Proposals
  • Payment Links
  • Overdue Reminders and Dunning
  • Recurring Invoices and Retainers
  • Vendor Bills
  • E-way Bills
  • GST Basics in Oris Work

Practice Management

  • Client Engagements
  • Client Portal
  • Tasks: Create, Assign and Track Work
  • Timesheets: Submit, Approve and Lock
  • Time Budgets Report
  • Notices and the Notice Reply Service
  • Compliance Calendar
  • Document Requests
  • Sign-off Pipeline: Partner, Client, Filed

Communication

  • WhatsApp inbox setup
  • Linking a WhatsApp line by QR code
  • WhatsApp logged out or disconnected
  • Auto-link WhatsApp numbers to clients
  • Email setup
  • Team chat basics
  • Threads, mentions and reactions in chat
  • Files, search, pins and saved messages in chat
  • Messaging AI bots in chat
  • Client chat

Reputation

  • Requesting reviews
  • How review ratings are routed

Growth

  • Lead routing and the first-response SLA
  • Segments
  • Campaigns basics

AI

  • Oris AI assistant
  • AI bots and their approval gate

Projects

  • Project Management

Modules

  • Payroll with PeopleOS
  • Books Module (ThynkBooks)
  • Tax Module (ThynkTax)
  • Audit Module (ThynkAudit)
  • Filings Module (ThynkFile)

Integrations & API

  • Accounting Connectors
  • REST API Overview

Security & Privacy

  • Data Encryption and PAN Handling
  • DPDP Consent and the PII Access Log
  • How Workspaces Are Kept Separate
  • Exporting Your Data

Troubleshooting & FAQ

  • "Too many requests" or "Rate limit exceeded"
  • "Reset token is invalid or expired"
  • "Your session expired"
  • WhatsApp Messages Are Not Coming In
  • Review Link Shows "404 Not Found"
  • "This may already exist" Duplicate Warnings

For your clients

  • Signing in to your client portal
  • Setting a password from your link
  • Messages with attachments
  • Paying your invoices online
  • Signing documents online
  • Leaving a review
Docs/Security & Privacy/Data Encryption and PAN Handling

Data Encryption and PAN Handling

What Oris Work stores encrypted, how PAN is protected, and what never leaves in an export.


What is encrypted

  • PAN and similar sensitive identifiers on a client’s practice profile are encrypted before they are saved.
  • Credentials you give Oris Work to connect other services — your own SMTP password for email sending, email and calendar connection tokens, and payment gateway keys — are stored encrypted.
  • Two-factor authentication secrets are stored encrypted.
  • Account passwords are never stored as plain text; they are stored as salted one-way hashes. The same applies to API keys and password-reset tokens, so even Oris Work staff cannot read them back.

How PAN is handled

  • You can record a client’s PAN on their practice profile. It must be in the format AAAAA9999A (five letters, four digits, one letter).
  • It is shown in full only to signed-in staff whose role allows reading the client’s practice profile.
  • It is used to fill engagement letters you generate for that client.
  • In payroll, once a PAN is saved the screen shows only the last four digits as a placeholder.

Access is logged

Each time a client’s PAN is read for a profile view, an engagement document view or an engagement-letter generation, Oris Work writes an entry to a PII access log: which field, who accessed it, in which workspace, and for what purpose. The log stores a non-reversible fingerprint of the value, never the PAN itself. Logging is best-effort and never blocks the read. There is no screen for this log in the app today.

Exports never include PAN

The Clients export deliberately leaves PAN out. If you need PAN for a purpose, open the client and read it there, where access is logged.

Good practice

  • Put PAN in the PAN field, not in notes, activity text or file names. Those free-text places are not encrypted.
  • Give Read access to client practice profiles only to the roles that need it (see Custom Roles).
  • Turn on two-factor authentication for yourself and consider requiring it for all members.

Related guides

DPDP Consent and the PII Access Log

How consent is captured for e-signing and marketing, and how sensitive-data access is recorded.

How Workspaces Are Kept Separate

A plain-language overview of how one firm’s data is kept apart from another’s.

Custom Roles

Build your own permission sets with Read, Write and Delete per module and assign them to team members.

Exporting Your Data

Download your clients, deals and activities as CSV, or a full JSON archive, from Settings.