Client Password Management for CA Firms
Somewhere in your firm, client GST and MCA portal passwords are sitting in a shared spreadsheet or a notes app that half the team can open. Here's how Turia's encrypted password vault replaces that habit.
Last reviewed 25 August 2026

Quick Answer
Turia's password vault is a centralized, encrypted store for client GST, Income Tax, MCA, and other portal credentials, built into Turia's practice management platform. Every credential sits behind role-based access with a logged access trail, so only staff who need a specific client's login for a task can retrieve it, and revoking a departing staff member's access cuts off every credential they could see at once.
The Spreadsheet Every Firm Swears Is Temporary
Ask any CA firm where client portal passwords live, and the honest answer is rarely a proper system. It's a shared spreadsheet named "passwords_final_v2," a notes app on someone's personal phone, or a WhatsApp message pinned in a staff group. It works, until it doesn't, an article clerk leaves mid-filing-season and nobody remembers to change the GST login they had access to, or a client calls asking why their MCA password stopped working after a laptop was shared around the office.
This is the default state for a lot of Indian CA and CS practices, because until recently there wasn't a purpose-built alternative that was faster than a spreadsheet, not just more secure than one. Turia's password vault is built specifically for that gap.
How the Vault Actually Works
1. Add a credential record
A team member with the right permission creates a record for a client's portal login, GST, Income Tax e-filing, MCA, or any third-party software the firm uses on the client's behalf.
2. Store the details
Client name, service or portal name, login URL, username, the encrypted password itself, and free-text notes for whatever context the next person needs.
3. Set access
The record is scoped to specific roles or team members, not visible firm-wide by default.
4. Retrieve when needed
An authorized staff member pulls up the credential from inside the client's record when a task requires it, without the password ever being pasted into a chat or a separate document.
5. Review the trail
Access is logged, so a partner can see who opened a given credential and when, useful for internal accountability and ICAI-aligned data-handling discipline.
What Makes It Different From a Spreadsheet
Encrypted storage
Credentials are never stored or displayed as plain text, unlike a spreadsheet cell anyone can read at a glance.
Role-based access control
Only staff assigned to a client, or with the right permission level, can open that client's credentials.
Centralized, per-client organization
Passwords live next to the client record they belong to, not scattered across personal notes apps and old chat threads.
Access logging
A record of who accessed a credential and when, useful for internal review and offboarding checks.
A Realistic Use Case: Staff Turnover During Filing Season
In onboarding conversations with CA firms, one scenario comes up more than any other: an article clerk or associate leaves the firm, often during a busy filing period, and nobody is entirely sure which client portals they had access to. If those credentials lived in a shared spreadsheet, the safe response is usually "change everything," which is slow and disruptive during a period the firm can least afford it.
With a role-based vault, the fix is narrower and faster: revoke that person's access in Turia, and every credential they could see is immediately out of reach, without touching the credentials themselves or interrupting anyone else's work. That's the practical difference between a password manager and a spreadsheet with a password in it, one assumes turnover will happen and is built to handle it cleanly, the other assumes nobody will ever leave.
How the Vault Fits With the Rest of Turia
The password vault isn't a standalone tool bolted on to the platform, it sits inside the same client record used across Turia's other modules. Credentials are attached directly to the client they belong to, alongside contact details, service history, and documents, in client management. Digital signature certificates and portal credentials are two different but related risk areas, both benefit from the same discipline of expiry tracking, access control, and audit visibility, tracked separately in the License Register. When a task requires a portal login, filing a GST return, responding to an MCA notice, the assigned staff member can retrieve the credential from within the same task management workflow, instead of pausing to message someone for a password.
Secure credential handling is part of the same operational discipline as tracking GST, TDS, and ROC deadlines through compliance management, both are about reducing the chance that something falls through during peak season. This kind of access-logged, role-based data handling also aligns with the discipline ICAI guidance expects of practising firms handling client statutory logins.
100s of CA firms use Turia Practice every day












Independently reviewed by CA firms using Turia:
Real Case Study
Final Thoughts
Most firms don't set out to store client passwords insecurely, it happens gradually, one shared spreadsheet edit at a time, until it's simply how things are done. Fixing that doesn't require a separate security product; it requires a vault that's actually faster to use than the workaround it's replacing, attached to the same client records and tasks your team already works in every day.
Frequently Asked Questions
What is Turia's password vault?
It's a centralized, encrypted store built into Turia's practice management platform for client login credentials, GST, Income Tax, MCA portal, and other software logins, organized by client, with role-based access so only authorized staff can view a given credential.
Are passwords stored in plain text in Turia?
No. Credentials are encrypted and never displayed as plain text within the interface the way they would be in a spreadsheet cell, staff retrieve what they need to complete a task without the password being exposed in a chat message or separate document.
Who can access a client's stored credentials in Turia?
Access is role-based: only team members assigned to a client, or with the appropriate permission level, can view that client's stored credentials. It isn't visible firm-wide by default, which is the main practical difference from a shared spreadsheet.
Does Turia log who accesses a client's password?
Yes, access to stored credentials is logged, so a partner or admin can review who opened a given client's login details and when, useful both for internal accountability and for offboarding checks when staff leave.
What happens to credential access when a staff member leaves the firm?
Because access is role-based rather than a shared file everyone can open, revoking a departing staff member's account immediately cuts off every credential they could see, without needing to change each password individually or interrupt other staff mid-filing-season.
Is the password vault a separate add-on or included in Turia's plans?
The password vault is part of Turia's core practice management platform rather than a separate paid add-on. It's included on every Turia plan, priced as a flat annual fee based on firm size, with a 7-day free trial.
Can I migrate existing client passwords from a spreadsheet into Turia?
Yes. Firms typically move existing credential lists into Turia as part of onboarding, alongside client records and task history, rather than re-entering everything manually. Contact Turia's team for help with the migration.
How is Turia's password vault different from a personal password manager?
A personal password manager is built around one person's logins. Turia's vault is built around a firm's client relationships, credentials are attached to the client record itself, scoped by role, shared appropriately across a team, and logged for accountability, which a single-user password manager isn't designed to handle.
Does using a password vault help with ICAI data-handling expectations?
Storing client statutory portal credentials securely, with controlled access and an audit trail, aligns with the kind of data-handling discipline ICAI guidance encourages for practising firms. Turia's vault supports that by design, though firms should confirm their own compliance obligations directly with ICAI guidance rather than relying solely on any software vendor's claims.
What client credentials can I store in Turia's vault?
Common examples include GST portal logins, Income Tax e-filing credentials, MCA portal access, and logins for third-party software used on a client's behalf. Each record can include the login URL, username, encrypted password, and notes for additional context.
Move Client Credentials Out of Spreadsheets
Start your 7-day free trial or book a walkthrough with our team.