A factory in Pune sends 40,000 supplier photocopies a month. Each photocopy carries a GSTIN, invoice amounts, maybe a PAN. That is vendor financial data. The CFO asks: where does it live? The answer is in the privacy policy on /privacy. India-hosted. Single tenant. Data never trains shared models.
Residency is a buying question, not a product feature. If your legal team says "India-hosted," we are India-hosted. If they say "single tenant," we are single tenant. If they say "no shared training," we do not train on your scans. These are commitments written into the privacy policy and terms. They are not marketing copy.
India-hosted. Single tenant. Data never trains shared models. On-prem is not the default SKU. Read /privacy and /terms. Do not invent ISO numbers we have not published. Do not assume subprocessors without checking.
India. Single tenant. No shared training.
Written in /privacy and /terms.
ISO, SOC 2, encryption details
If not there, we do not do it. Ask.
What scans carry
GSTINs, invoice amounts, supplier names, sometimes PANs. These are financial identifiers. They are not personal data in the GDPR sense (we do not process EU personal data). But they are financial data. India's data protection framework is evolving. Read the current law. Do not treat a blog as a notification.
What we do with the scans: extract fields, run validators, export to Tally. What we do not do: sell the data, share it with third parties, train shared models on it. That is a commitment. It is in the privacy policy.
On-prem
Not the default SKU. Hosting is the default. On-prem is a conversation. If your legal team says "on-prem because the server must be in our data centre," that is a conversation we can have. It is not the product we sell on the website. The website sells hosted extraction.
On-prem changes the architecture. We do not host. You host. The validators run on your infrastructure. The extraction runs on your infrastructure. The review UI runs on your infrastructure. That is a different product. It is not what we sell today.
What we will not do
We will not invent ISO 27001 compliance if we have not published it. We will not claim SOC 2 if we have not been audited. We will not promise "GDPR compliant" when we do not process EU data. Read the privacy policy. If it does not say it, we do not do it.
We will not promise "your data is encrypted at rest" if we have not published the encryption standard. Read the policy. If it is not there, ask. Do not assume.
The bake-off question
Ask the vendor: "Where do scans live? Who can access them? Do they train shared models? Is on-prem available?" If they cannot answer from their published policy, they have not thought about it. We can answer from ours. Read it.
Where are scans stored?+
India. Single tenant. Read /privacy.
Shared models?+
No. Data never trains shared models.
On-prem?+
Not default. Hosting is. On-prem is a conversation.