Security & compliance
Built for a regulated credit function.
A CISO's questions are the first ones we answer, not the last. Here is how Neurafin is architected for data residency, explainability and model governance.
Data residency you choose.
Neurafin deploys in your jurisdiction. Our production environment runs on GCP asia-south1 (Mumbai), with AWS and Azure as secondary options. Data residency is configurable per client — it is a deployment parameter, not a negotiation.
Explainable by construction.
Every decision returns the clause it was made under. Explainability is not a report we generate after the fact — it is how the decision is produced. The decision ledger records each decision, its inputs, the clause invoked and the actual outcome. That is both the audit trail and the training signal.
Model governance — no proprietary black box.
We train no proprietary foundation models. The intelligence sits in the orchestration layer, the policy corpus and the decision ledger. We use Gemini for the underlying language capability, and we are precise about that on purpose — a founder who claims a proprietary LLM in 2026 gets discounted; a founder who is clear about where the moat sits does not.
DPDP alignment.
Consent and privacy logging is handled through DPDP-compliant tooling. Personal data is processed under the lender's own consent framework, and the decision ledger gives a complete, queryable record of what was used to reach each decision.
Alongside your core, not instead of it.
Neurafin integrates with your existing LOS/LMS, core banking and bureau feeds by REST and webhook — read and write-back. There is no core replacement and no multi-year programme. You keep your systems of record; we add the intelligence layer.
Roadmap · stated as intent
On the roadmap — stated as intent, not fact.
We hold no security certification today, and we will not claim one we do not have. SOC 2 Type I is planned to be initiated as we onboard our first pilots. We will publish certifications here when they are earned, dated, and verifiable — and not before.
Questions from your CISO?
We would rather answer the hard ones early. Tell us your requirements and we will walk your security team through the architecture.
Request a demo