Enterprise

The document layer for regulated KYC

Extract, verify, mask and redact identity documents at volume. Processed in Mumbai, held in memory only, never written to disk. Built for teams whose compliance function has to be able to explain, in writing, where a customer’s Aadhaar number went.

Talk to our technical team → — for integration questions, a security review or a volume estimate.

What we do, and what we deliberately do not

Most KYC vendors sell everything: Aadhaar, PAN, bank account verification, GST, DigiLocker, video KYC, AML screening. We sell one layer of that stack and try to be the best available at it — what happens to the document itself.

Extract
Read the fields off an Aadhaar or PAN card as JSON, with the Aadhaar checksum validated so a mis-read is caught rather than stored.
Verify
Check a physical Aadhaar card against the digitally signed QR code printed on it, so a tampered card is caught before it enters the file.
Mask
Redact the first eight digits and leave the last four readable — the UIDAI-recognised masked form, so the document stays usable as a KYC record.
Redact
Cover every identifier on any document, not just the ones we recognise: Aadhaar, VID, PAN, passport, voter EPIC, driving licence, GSTIN, IFSC, phone and email.
Bulk
The same four operations across a batch, returned as a ZIP with a manifest giving per-document status.
We do not do identity verification against UIDAI or NSDL. We do not call the Aadhaar authentication API, we are not a KUA or AUA, and we do not tell you whether a person exists. We tell you what is printed on a document, whether the document's own signature holds up, and we make the document safe to store. If you need authentication against the UIDAI database, you need a licensed AUA and we are not one.

Why the document layer is where the risk sits

A KYC pipeline has five stages and the identity check is only one of them. The document arrives, gets read, gets checked, gets stored, and gets shared with an auditor, an insurer, a co-lender or a collections agency. Four of those five stages involve a file sitting somewhere with a full Aadhaar number on it.

What an enterprise agreement adds

Custom volume
Quota and per-minute throughput are set per plan, not per tier. Tell us your monthly volume and your peak and we size both.
Per-endpoint scope
Buy masking without buying extraction. A key reaches only the endpoints on your plan and is refused with a 403 everywhere else — enforced by the API, not by trust.
Contractual SLA
Availability and support-response commitments in writing, with remedies. Not offered on self-serve plans.
IP allowlisting
Restrict a key to your egress ranges, so a leaked credential is unusable from anywhere else.
Custom retention
Documents are never retained at all. What is configurable is how long the request metadata and access logs live.
DPA
A data processing agreement covering our role as processor, sub-processors, breach notification and deletion on termination.
Security questionnaire
We complete yours. Most of the answers are on our security page already, which is deliberate — it is faster for both of us.
Dedicated support
A named contact and an agreed response time, rather than a shared inbox.

Questions we get asked

Do you store the documents we send?

No. Documents are held in memory for the duration of the request and are never written to disk. There is no object store, no temporary file and no queue holding your files. What is recorded per call is metadata only: which key, which endpoint, the file type, the size in bytes, how long it took, how many regions were redacted, and the status code. No document content and no extracted values.

Where is the data processed?

AWS ap-south-1, Mumbai. Documents are processed there and nowhere else. Nothing you send leaves India.

Are you an AUA or KUA? Do you call UIDAI?

No, to all three. We do not authenticate against the UIDAI database and we are not licensed to. We read what is printed on the document, verify the document's own signed QR code where one is present, and redact identifiers. Identity authentication against UIDAI requires a licensed AUA and that is a different service.

Can we buy one endpoint rather than the whole suite?

Yes, and this is enforced rather than promised. Each endpoint has a scope; your plan lists the scopes it includes; a key calling anything else is refused with a 403 naming what it does have. A masking plan genuinely cannot reach the extraction endpoints, which return the number in the clear.

Will you sign a DPA and complete our security questionnaire?

Yes to both, on an enterprise agreement. Our security page is written to answer most standard questionnaire items directly so the process is short.

Read next

Talk to us about your document volume

Tell us how many documents a month you process and what your peak looks like. We will size a plan, provision a key with a test quota, and answer a security questionnaire if you need one.