Extract, verify, mask and redact identity documents at volume. Processed in Mumbai, held in memory only, never written to disk. Built for teams whose compliance function has to be able to explain, in writing, where a customer’s Aadhaar number went.
Talk to our technical team → — for integration questions, a security review or a volume estimate.
Most KYC vendors sell everything: Aadhaar, PAN, bank account verification, GST, DigiLocker, video KYC, AML screening. We sell one layer of that stack and try to be the best available at it — what happens to the document itself.
A KYC pipeline has five stages and the identity check is only one of them. The document arrives, gets read, gets checked, gets stored, and gets shared with an auditor, an insurer, a co-lender or a collections agency. Four of those five stages involve a file sitting somewhere with a full Aadhaar number on it.
pdftotext. We rasterise, so the number is genuinely gone.403 everywhere else — enforced by the API, not by trust.No. Documents are held in memory for the duration of the request and are never written to disk. There is no object store, no temporary file and no queue holding your files. What is recorded per call is metadata only: which key, which endpoint, the file type, the size in bytes, how long it took, how many regions were redacted, and the status code. No document content and no extracted values.
AWS ap-south-1, Mumbai. Documents are processed there and nowhere else. Nothing you send leaves India.
No, to all three. We do not authenticate against the UIDAI database and we are not licensed to. We read what is printed on the document, verify the document's own signed QR code where one is present, and redact identifiers. Identity authentication against UIDAI requires a licensed AUA and that is a different service.
Yes, and this is enforced rather than promised. Each endpoint has a scope; your plan lists the scopes it includes; a key calling anything else is refused with a 403 naming what it does have. A masking plan genuinely cannot reach the extraction endpoints, which return the number in the clear.
Yes to both, on an enterprise agreement. Our security page is written to answer most standard questionnaire items directly so the process is short.
Where documents go, what is retained, how keys are stored and what the API enforces.
Rate limits, retry behaviour, error semantics and what an availability commitment covers.
Every endpoint, every response header, every error code.
Loan file masking, co-lending packets and what an auditor asks for.
Tell us how many documents a month you process and what your peak looks like. We will size a plan, provision a key with a test quota, and answer a security questionnaire if you need one.