Security & data
Built for a regulated lender, not a demo.
A verification touches a borrower’s photos and a lender’s loan data. Here is exactly how that is handled — described plainly, without badges we haven’t earned.
Human-gated by design
Software recommends; a named officer approves. No tranche is released automatically — the accountability stays with your team.
Append-only activity trail
Every view, check and decision is recorded and appended to the file. Entries are not edited or removed, so an audit can reconstruct any case end to end.
Organisation isolation
Each lender’s files, photos and decisions are scoped to their own organisation, with role-based access for officers, reviewers and administrators.
Spoof-resistant capture
The guided flow issues a one-time capture origin token. Gallery uploads and re-shared images don’t carry one, so recycled photos are surfaced for review.
Data residency in India
Files and photos are hosted in the Mumbai region. The AI stage read uses a disclosed sub-processor (Anthropic). The design follows India’s DPDP data-protection rules.
Least data by default
We collect what a verification needs — the site photos and the loan/stage context — and nothing more. Data is exported and removed on request.
What we don’t claim
We don’t carry third-party security seals yet, and we don’t claim a check can’t be beaten. What we do claim is narrow and testable: the checks are detection signals, a person makes every decision, and the trail is append-only. If your risk team wants to probe any of it, we’ll walk through it in detail.
Talk to us
Bring your security questions.
Data-handling, access model, sub-processors, residency — happy to take your risk team through all of it before any pilot.
Book a review