Mannjal deploys inside your own cloud or on our India-hosted infrastructure, with role-based access and maker-checker controls. The security documentation to review the controls for your deployment scope is available on request.
Run Mannjal inside your own cloud or physical servers as a dedicated instance, or on Mannjal's India-hosted infrastructure with per-lender segregation. Deployment scope determines the exact control boundary.
On Mannjal-hosted infrastructure, data is hosted in India with Mumbai as primary and Delhi as disaster recovery, and cross-border transfer controls are applied at the platform layer. On your own infrastructure, data stays inside your perimeter. Both options support data-localization and DPDP-aware obligations based on deployment scope.
Integrations use your own application programming interface credentials with the providers you already contract. Mannjal routes and logs configured calls; it does not proxy your keys.
Workflow actions, application programming interface calls and document events are timestamped, tied to the user who performed them and exportable on demand for audit review.
Section-level permissions, user-specific access and maker-checker steps enforce segregation of duties on configured cases the platform carries.
Application programming interface activity, document events and status-change history are logged with a timestamp and the acting user in exportable trails.
The platform runs logically segregated portals or instances, with access boundaries drawn around each participating entity.
KYC, bureau, bank-statement, and e-sign checks run through the providers you already contract, under your own regulatory agreements and credentials.




The platform also routes configured GST / Udyam, NACH / eNACH and lender-system handoffs through the same integration layer, logged with the same evidence model as other checks. The exact set applies based on program scope.
For Mannjal-hosted deployments, the platform stores and processes data in India, with Mumbai primary and Delhi as disaster recovery. Security and residency evidence is available for review under NDA.
On Mannjal-hosted infrastructure, the platform runs with:
The evidence pack covers web application, software composition and source code review assessments, and operating practices aligned with ISO 27001:2022. No payment-system data is stored or processed in the Mannjal-hosted scope. In a self-hosted deployment, the infrastructure controls above sit with the deploying entity; the full split of responsibility is set out in our CAIQ, shared under NDA. Residency and audit statements describe the Mannjal-hosted platform; the scope of a self-hosted deployment may differ.
Mannjal completes standard security questionnaires, including the CAIQ v4.1 mapped to the Cloud Controls Matrix, so you can score us against the framework you already use. Audit evidence and questionnaire responses are available under NDA on request.
Architecture, data-flow, and the independent audit detail you need to sign off, shared under NDA.