Security & trust

The evidence to review our controls

Mannjal deploys inside your own cloud or on our India-hosted infrastructure, with role-based access and maker-checker controls. The security documentation to review the controls for your deployment scope is available on request.

What to check

Four things, answered plainly

Deployment

Your cloud, or ours

Run Mannjal inside your own cloud or physical servers as a dedicated instance, or on Mannjal's India-hosted infrastructure with per-lender segregation. Deployment scope determines the exact control boundary.

Data residency

In India, by design

On Mannjal-hosted infrastructure, data is hosted in India with Mumbai as primary and Delhi as disaster recovery, and cross-border transfer controls are applied at the platform layer. On your own infrastructure, data stays inside your perimeter. Both options support data-localization and DPDP-aware obligations based on deployment scope.

Credentials & access

Your keys stay yours

Integrations use your own application programming interface credentials with the providers you already contract. Mannjal routes and logs configured calls; it does not proxy your keys.

Audit logs

Audit evidence in exportable trails

Workflow actions, application programming interface calls and document events are timestamped, tied to the user who performed them and exportable on demand for audit review.

Inside the platform

The controls you'll ask about, built into the workflow

Access control

Role-based, down to the section

Section-level permissions, user-specific access and maker-checker steps enforce segregation of duties on configured cases the platform carries.

Traceability

Workflow actions, timestamped

Application programming interface activity, document events and status-change history are logged with a timestamp and the acting user in exportable trails.

Data boundaries

Segregated by design

The platform runs logically segregated portals or instances, with access boundaries drawn around each participating entity.

See how the platform enforces this
Integrations

Works with the providers you already use

KYC, bureau, bank-statement, and e-sign checks run through the providers you already contract, under your own regulatory agreements and credentials.

Decentro
eNACH · KYC · KYB
AuthBridge
KYC · KYB
Signzy
Soft pull · e-sign
ScoreMe
Bank statement analysis

The platform also routes configured GST / Udyam, NACH / eNACH and lender-system handoffs through the same integration layer, logged with the same evidence model as other checks. The exact set applies based on program scope.

The evidence

Independently verified

For Mannjal-hosted deployments, the platform stores and processes data in India, with Mumbai primary and Delhi as disaster recovery. Security and residency evidence is available for review under NDA.

On Mannjal-hosted infrastructure, the platform runs with:

AES-256 at rest TLS 1.3 in transit WAF, OWASP-hardened Anti-DDoS Host IDS/IPS IP-whitelisting 2FA Privileged access management GCP IAM, least privilege Database access monitoring BCP/DR simulation tested, recovery targets defined Role-based access

The evidence pack covers web application, software composition and source code review assessments, and operating practices aligned with ISO 27001:2022. No payment-system data is stored or processed in the Mannjal-hosted scope. In a self-hosted deployment, the infrastructure controls above sit with the deploying entity; the full split of responsibility is set out in our CAIQ, shared under NDA. Residency and audit statements describe the Mannjal-hosted platform; the scope of a self-hosted deployment may differ.

Vendor due diligence

Ready for your TPRM review

Mannjal completes standard security questionnaires, including the CAIQ v4.1 mapped to the Cloud Controls Matrix, so you can score us against the framework you already use. Audit evidence and questionnaire responses are available under NDA on request.

CAIQ v4.1 / CCM v4 Audit evidence under NDA ISO 27001:2022 aligned Report shared under NDA
Security & deployment docs

Get the full security and deployment documentation

Architecture, data-flow, and the independent audit detail you need to sign off, shared under NDA.