Skip to content
Security and data handling

Clear data boundaries, product by product.

Each LeanFintech product handles data according to its job. A parse request, a consented inbox connection, and a reverse-feed batch need different retention rules, so we document them separately instead of making one blanket claim.

Retention by product

What is kept, and what is not.

Retention follows the product contract. Enterprise deployments can add terms agreed during architecture and security review.

01

CASParser parsing

Uploaded CAS PDFs are processed in memory. The original PDF and the parsed portfolio data are discarded after the API response is sent. Only usage metadata, such as credits consumed and timestamps, is logged.

CASParser data handling
02

Inbox

Inbox uses explicit provider consent, read-only access, and purpose limitation. Retention is configurable, because evidence links between a structured record and its source message are part of the product. Users can revoke access, and customers control disconnection and deletion.

Inbox consent model
03

RTA Sync and Reconciliation

RTA Sync normalizes the CAMS and KFintech files you supply. RTA Reconciliation is stateless: it compares the batches you send and does not retain a prior batch. Neither product executes investment orders.

RTA Sync overview
04

Verification

PAN KYC Status returns registry status for the PAN you submit. DigiLocker requires explicit consent and a stated purpose before a session starts, and the investor authorizes access on DigiLocker.

Verification layer
Platform controls

How requests are protected.

  • HTTPS with TLS 1.2 or higher enforced on API endpoints
  • API-key authentication, with short-lived access tokens for frontend use
  • A unique request ID on every API request, with usage logs for support and compliance
  • Detection of tampered or modified CAS PDFs
  • Access controls and monitoring against unauthorized access
For enterprise review

Bring your security questionnaire.

Security and compliance scope differs by product and deployment. For hosting, sub-processors, retention terms, and regulatory scope that apply to your integration, request the security documentation during an architecture review.

Questions

Security, answered.

Does CASParser store uploaded CAS files or parsed data?

No. CAS PDFs are processed in memory, and the original file and parsed portfolio data are discarded after the API response is sent. Only usage metadata, such as credits consumed and timestamps, is logged.

Does Inbox retain email data?

Inbox retention is configurable per integration. Access is consented, read-only, and purpose-limited, and users can revoke it at any time.

How is data protected in transit?

API traffic uses HTTPS, with TLS 1.2 or higher enforced on API endpoints.

Where is CASParser hosted?

CASParser infrastructure is hosted in India. For hosting and sub-processor details for other products or enterprise deployments, request the security documentation.