Transparency Notice
AI Processing Disclosure

Effective date: 30 June 2026  ·  Applies to: GRCfy Maestro — AI-Enabled Audit Features  ·  Issued by: GRCfy Technologies Private Ltd

Section 01

Purpose of This Disclosure

GRCfy Maestro is a compliance audit management platform. Certain subscription tiers include optional AI-assisted features that help auditors evaluate evidence against control requirements. This document explains what AI technology we use, how it processes your data, and the safeguards in place to protect sensitive information.

Human-in-the-Loop by design. No AI analysis runs automatically. Every AI evaluation is explicitly triggered by an auditor and its output is advisory only. The auditor reviews the AI-generated findings and makes the final compliance determination. AI output is never automatically committed to audit records without human review.
Section 02

AI Technology Used

Feature AI Model Provider Tier
AI Evidence Validation
Evaluates accepted evidence against individual audit controls; returns pass/fail finding, confidence score, executive summary, and auditor field notes.
Claude Haiku 4.5
claude-haiku-4-5-20251001
Anthropic / AWS Bedrock
ap-south-1 (Mumbai, India)
Standard
AI Evidence Validation — Enterprise
Same as above, with deeper regulatory cross-referencing, section-level citations, and multi-document synthesis. Recommended for BRSR, ESG, and certification audits.
Claude Sonnet 4.6
claude-sonnet-4-6
Anthropic / AWS Bedrock
ap-south-1 (Mumbai, India)
Enterprise
Data residency: All AI inference is performed on AWS Bedrock in the ap-south-1 region (Mumbai, India). Evidence text does not leave India's geographic boundary during AI processing.
Section 03

Data Flow — What Is Sent to AI

Understanding exactly what data leaves your environment is critical. Here is the precise data flow:

1
Text extraction
When evidence files (PDF, DOCX, XLSX, images) are accepted by an auditor, text is extracted in-process. PDF and Office documents are parsed entirely on our servers — no third-party service is involved. Images and scanned PDFs use AWS Textract (OCR only; Mumbai, India) to extract text.
2
PII scrubbing — Layer 1: Internal Engine
The extracted text is passed through our internal PII scrubber (PiiScrubberService) before any external call. Runs entirely in-process on our servers — no external API, zero cost, zero latency. Replaces 11 categories of identifiers with redacted placeholders: email addresses, Indian phone numbers (+91 format), Aadhaar numbers, PAN numbers, credit/debit card numbers, IPv4 addresses, IPv6 addresses, Indian passport numbers, IFSC bank codes, dates of birth (DD/MM/YYYY), and UPI VPAs. Layer 1 is the only coverage for IFSC, UPI, DOB, and IPv6 — the Guardrail does not carry patterns for these.
3
PII scrubbing — Layer 2: AWS Bedrock Guardrail (ML entities + India regex)
The Layer 1 output is independently re-processed by an AWS Bedrock Guardrail. No content, topic, or word filters are active — deliberately disabled to avoid blocking compliance terminology. The Guardrail has three tiers of detection: (a) 9 ML-based entity types — NAME, ADDRESS, EMAIL, PHONE, USERNAME, IP_ADDRESS (Mask), and CREDIT_DEBIT_CARD_NUMBER, PASSWORD, AWS_SECRET_KEY (Block — request rejected if detected); (b) 4 India-specific custom regex patterns independently re-checking AADHAAR, PAN, PASSPORT_IN, and MOBILE_IN. For these four types, both Layer 1 and Layer 2 carry independent regex — genuine double-regex coverage. For NAME, ADDRESS, USERNAME, PASSWORD, and AWS credentials, the Guardrail is the only layer. Together: true defence-in-depth where both layers independently process every piece of evidence text.
4
AI inference
The scrubbed text, the control title, and the control description are transmitted to the Claude model via AWS Bedrock (ap-south-1). No other personal data, user details, or organisational metadata is included in the prompt. The model returns a structured JSON response with compliance findings.
5
Human review
AI findings are displayed to the auditor in the platform's "AI Insights" panel. The auditor reviews, adjusts, and determines the final compliance status. No AI-generated finding is automatically written to the audit record.
6
Audit trail
Each AI analysis is logged in the platform's immutable audit trail: timestamp, user ID, control reference, AI model used, and confidence score. Raw evidence text is not logged.
What is NOT sent to AI: Original evidence files are never transmitted. User names, email addresses, organisation names, subscription details, client metadata, or any data beyond the scrubbed evidence text and control description are not included in AI prompts.
Section 04

Privacy & Data Protection Commitments

No model training on your data

We access Claude via the AWS Bedrock API under commercial service terms. Under these terms, Anthropic and Amazon do not use customer-submitted prompts or responses to train, improve, or fine-tune their AI models. Your audit evidence and compliance data are never used as training material.

No persistent storage in AI systems

Evidence text passed to Claude is processed in-request only. AWS Bedrock does not retain prompt content after the API call completes. GRCfy Maestro does not cache, store, or log the scrubbed evidence text that is sent to the AI model.

India data residency

AI inference for all GRCfy Maestro customers runs exclusively on AWS Bedrock in ap-south-1 (Mumbai, India). This applies to both Standard (Claude Haiku) and Enterprise (Claude Sonnet) tiers. Text extracted by AWS Textract (for image OCR) also uses ap-south-1.

DPDP Act 2023 alignment

The two-layer PII scrubbing pipeline (structured regex + Bedrock Guardrail) is designed to prevent personal data from reaching the AI model. Where residual personal data may remain after scrubbing (e.g., within a complex audit narrative), the Bedrock Guardrail provides a second filter. Processing occurs under a valid Data Processing Agreement between GRCfy Technologies and the subscriber.

Subscriber responsibility: If evidence documents submitted by your organisation contain personal data that is integral to the compliance narrative (e.g., an HR policy referencing employee categories, or a data map referencing data subject classes), that data may be processed by the AI model after scrubbing passes. Subscribers should review their evidence submission practices in the context of their own data protection obligations.
Section 05

Sub-processors Involved in AI Processing

Sub-processor Role Data Processed Location
Anthropic PBC
via Amazon Web Services
AI model inference (Claude Haiku 4.5 and Claude Sonnet 4.6) Scrubbed evidence text + control title + control description. No personal identifiers, no user metadata. AWS ap-south-1
(Mumbai, India)
Amazon Web Services
Bedrock, Textract
Bedrock: AI inference gateway and Guardrail (PII entity filter). Textract: OCR for images and scanned PDFs. Bedrock: scrubbed prompt + control context. Textract: image/scan file (raw, for OCR only; not persisted). AWS ap-south-1
(Mumbai, India)

Both sub-processors operate under AWS's standard data processing addendum (DPA), which incorporates Anthropic's usage policy prohibiting training on API-submitted data.

Section 06

Limitations & Important Caveats

Section 07

Contact & Queries

If you have questions about AI processing in GRCfy Maestro, or wish to discuss the implications for your organisation's data protection obligations, contact us at:

For organisations that require this disclosure in a countersigned PDF format, or that need additional contractual assurances about AI processing, contact legal@grcfy.com.