Security & compliance

Built for regulated
financial workflows.

Credit data is sensitive by definition. Proczo is designed around consent, isolation and auditability from day one.

๐Ÿ—‚๏ธ

DPDP-ready consent ledger

Every consented fetch (GST OTP, Account Aggregator, ITR) is stored with grantor, purpose, timestamp and expiry โ€” and surfaced in the report's annexures.

๐Ÿ”

Encryption everywhere

TLS 1.2+ in transit; AES-256 at rest. Documents in S3 are encrypted with KMS keys; database volumes are encrypted by default.

๐Ÿข

Org-scoped isolation

Every subject, report, document and credit entry is keyed to your organization. API keys and webhooks are org-scoped with least-privilege roles.

๐Ÿ“œ

Immutable audit trail

Agent runs, overrides, finalizations and exports are appended to a tamper-evident audit log โ€” exportable for internal audit and regulators.

๐Ÿ‡ฎ๐Ÿ‡ณ

Data residency in India

All storage and AI inference runs in AWS ap-south-1 (Mumbai). Nothing leaves the region โ€” including model calls via AWS Bedrock.

๐Ÿง 

No training on your data

Models are invoked via AWS Bedrock with zero data retention. Your borrowers' data never trains anyone's model โ€” including ours.

Access control

Roles that mirror your credit desk.

RoleCan doCannot do
Org AdminBilling, seats, API keys, webhooks, score-weight versionsโ€”
AnalystCreate reports, override scores with reasons, finalizeManage billing or keys
MemberRead reports, use "Ask this report"Create, override or finalize

Security review? We'll come prepared.

Get our security whitepaper, DPDP note and architecture diagram for your infosec team.