For real estate

Tenant KYC and property documents without the liability

Brokers, property managers, rental platforms and builders collect identity documents constantly and almost never have a place to put them safely. The documents end up in WhatsApp, in email and on a shared drive.

Talk to our technical team → — for integration questions, a security review or a volume estimate.

Who holds what, and for how long

Rental platforms
Tenant Aadhaar and PAN for every application, including the ones that never convert. Those rejected applications are pure liability with no business value.
Brokers
Documents forwarded by WhatsApp to owners and back. Every device in the chain keeps a copy.
Property managers
Tenant files retained for the tenancy and long after it ends.
Builders
Buyer KYC for booking, plus registration documents containing prior owners' identifiers.
Masking at collection means the copy that gets forwarded is already safe. It is the only control that survives a document being shared over channels you do not own — which, in this industry, is all of them.

Two ways in, depending on what you are

The rejected applicant problem

A rental platform screens perhaps twenty applicants per property and signs one. The other nineteen handed over an Aadhaar and a PAN, and there is no business reason left to hold either.

What you keep
Nineteen sets of identity documents with no live tenancy attached to them. Pure liability: no revenue, no operational use, full breach exposure.
Why they survive
Nobody built the deletion job. It was never anyone's sprint, and the documents are invisible until a breach makes them visible.
The fix
Mask at upload. Then a rejected application leaves behind a document that identifies the person enough to audit the decision, and not enough to be worth stealing.
This applies equally to a broker's phone, a builder's booking desk and a society office's visitor register. Any process that collects identity documents from people it will mostly say no to has the same shape.

Who in this industry actually needs an API

Questions we get asked

Can we mask tenant Aadhaar before sharing with an owner?

Yes. That is the common case: the owner needs to see who the tenant is, not their full Aadhaar number. Masking leaves the last four digits readable so the document still identifies the person.

Do we need an API for a handful of documents a week?

Probably not. The browser tool runs entirely on your own machine, uploads nothing, and is free. The API is for platforms processing documents continuously.

Can it handle a sale deed with prior owners' identifiers?

Yes. The generic redaction endpoint finds identifiers wherever they are printed, including on people who are not your customer.

What should we do with documents from applicants we rejected?

Ideally never hold the unmasked version. Mask at upload and a rejected application leaves a document that still evidences the decision without being worth stealing. Deleting them later works too, if somebody actually builds that job — most teams do not.

Is masking enough, or do we need consent and a retention policy too?

Masking is a technical control, not a legal one. It reduces what you hold; it does not replace telling people what you collect and why. Ask your counsel about the rest — we are not going to pretend an API is a compliance programme.

Related

Talk to us about your document volume

Tell us how many documents a month you process and what your peak looks like. We will size a plan, provision a key with a test quota, and answer a security questionnaire if you need one.