MYSTRI AUDIT

Data & confidentiality

The questions every firm should ask — answered plainly, in writing. This page is part of the product on purpose.

Where does our clients' data live?

In an encrypted database and file store dedicated to your firm — one instance per firm, no shared data pots. Today that infrastructure sits in Singapore; an India region is on the roadmap and we will tell you the day it moves. Nothing lives in anyone's inbox or laptop.

Who can see it?

Your firm's logins only. We operate the infrastructure; we do not browse your data. Every access and every consequential action is recorded in the audit log you can open any time.

Is our data used to train AI?

Never. Not by us, not by anyone. AI processing runs under Anthropic's commercial API terms, which contractually prohibit training on your data.

What exactly goes to the AI, and what happens to it?

Only the document being processed — a bill image, a notice text — never your database. Under the commercial terms it is encrypted in transit, never used for training, and deleted within roughly 30 days (held only for abuse screening). We send the minimum: the bill, not the client master; the notice, not the case history.

Is that safer than how this data moves today?

Compare honestly: today clients WhatsApp bills and offices email registers over Gmail — US-hosted services with no no-training contract. This pipeline is contractually stronger than the profession's daily practice.

What do you NEVER collect?

GST portal passwords (the architecture doesn't need them — you download files with your own login) and DSCs (signing stays on your machine, always). The system cannot file anything on any portal, by design.

Does anything get sent or filed automatically?

No. Every draft — returns pack, client message, notice reply — waits in the Review Queue for a human's explicit approval. The only ungated messages are routine document reminders, which you can also route through review.

What if we leave?

Complete export of your data, then verified deletion. Your data is yours; the exit door is part of the agreement.

Legal posture

Under the DPDP Act, your firm is the data fiduciary and Mystri is your processor — we sign a Data Processing Addendum saying exactly that. For the extra-cautious we offer an upgrade ladder: India-region AI processing, zero-data-retention terms, and redaction mode (roadmap).

Questions? hello@mystri.ai · Back to sign in