Security & data

Built for a regulated lender, not a demo.

A verification touches a borrower’s photos and a lender’s loan data. Here is exactly how that is handled — described plainly, without badges we haven’t earned.


Human-gated by design

Software recommends; a named officer approves. No tranche is released automatically — the accountability stays with your team.

Append-only activity trail

Every view, check and decision is recorded and appended to the file. Entries are not edited or removed, so an audit can reconstruct any case end to end.

Organisation isolation

Each lender’s files, photos and decisions are scoped to their own organisation, with role-based access for officers, reviewers and administrators.

Spoof-resistant capture

The guided flow issues a one-time capture origin token. Gallery uploads and re-shared images don’t carry one, so recycled photos are surfaced for review.

Data residency in India

Files and photos are hosted in the Mumbai region. The AI stage read uses a disclosed sub-processor (Anthropic). The design follows India’s DPDP data-protection rules.

Least data by default

We collect what a verification needs — the site photos and the loan/stage context — and nothing more. Data is exported and removed on request.

What we don’t claim

We don’t carry third-party security seals yet, and we don’t claim a check can’t be beaten. What we do claim is narrow and testable: the checks are detection signals, a person makes every decision, and the trail is append-only. If your risk team wants to probe any of it, we’ll walk through it in detail.


Talk to us

Bring your security questions.

Data-handling, access model, sub-processors, residency — happy to take your risk team through all of it before any pilot.

Book a review