Built for regulated
financial workflows.
Credit data is sensitive by definition. Proczo is designed around consent, isolation and auditability from day one.
DPDP-ready consent ledger
Every consented fetch (GST OTP, Account Aggregator, ITR) is stored with grantor, purpose, timestamp and expiry โ and surfaced in the report's annexures.
Encryption everywhere
TLS 1.2+ in transit; AES-256 at rest. Documents in S3 are encrypted with KMS keys; database volumes are encrypted by default.
Org-scoped isolation
Every subject, report, document and credit entry is keyed to your organization. API keys and webhooks are org-scoped with least-privilege roles.
Immutable audit trail
Agent runs, overrides, finalizations and exports are appended to a tamper-evident audit log โ exportable for internal audit and regulators.
Data residency in India
All storage and AI inference runs in AWS ap-south-1 (Mumbai). Nothing leaves the region โ including model calls via AWS Bedrock.
No training on your data
Models are invoked via AWS Bedrock with zero data retention. Your borrowers' data never trains anyone's model โ including ours.
Roles that mirror your credit desk.
| Role | Can do | Cannot do |
|---|---|---|
| Org Admin | Billing, seats, API keys, webhooks, score-weight versions | โ |
| Analyst | Create reports, override scores with reasons, finalize | Manage billing or keys |
| Member | Read reports, use "Ask this report" | Create, override or finalize |
Security review? We'll come prepared.
Get our security whitepaper, DPDP note and architecture diagram for your infosec team.