Effective date: 30 June 2026 ·
Applies to: GRCfy Maestro — AI-Enabled Audit Features ·
Issued by: GRCfy Technologies Private Ltd
Section 01
Purpose of This Disclosure
GRCfy Maestro is a compliance audit management platform. Certain subscription tiers include
optional AI-assisted features that help auditors evaluate evidence against control requirements.
This document explains what AI technology we use, how it processes your data, and the safeguards
in place to protect sensitive information.
Human-in-the-Loop by design. No AI analysis runs automatically. Every AI evaluation
is explicitly triggered by an auditor and its output is advisory only. The auditor reviews the
AI-generated findings and makes the final compliance determination. AI output is never automatically
committed to audit records without human review.
Section 02
AI Technology Used
Feature
AI Model
Provider
Tier
AI Evidence Validation Evaluates accepted evidence against individual audit controls; returns pass/fail finding, confidence score, executive summary, and auditor field notes.
AI Evidence Validation — Enterprise Same as above, with deeper regulatory cross-referencing, section-level citations, and multi-document synthesis. Recommended for BRSR, ESG, and certification audits.
Data residency: All AI inference is performed on AWS Bedrock in the
ap-south-1 region (Mumbai, India). Evidence text does not leave India's
geographic boundary during AI processing.
Section 03
Data Flow — What Is Sent to AI
Understanding exactly what data leaves your environment is critical. Here is the precise data flow:
1
Text extraction
When evidence files (PDF, DOCX, XLSX, images) are accepted by an auditor, text is extracted in-process. PDF and Office documents are parsed entirely on our servers — no third-party service is involved. Images and scanned PDFs use AWS Textract (OCR only; Mumbai, India) to extract text.
2
PII scrubbing — Layer 1: Internal Engine
The extracted text is passed through our internal PII scrubber (PiiScrubberService) before any external call. Runs entirely in-process on our servers — no external API, zero cost, zero latency. Replaces 11 categories of identifiers with redacted placeholders: email addresses, Indian phone numbers (+91 format), Aadhaar numbers, PAN numbers, credit/debit card numbers, IPv4 addresses, IPv6 addresses, Indian passport numbers, IFSC bank codes, dates of birth (DD/MM/YYYY), and UPI VPAs. Layer 1 is the only coverage for IFSC, UPI, DOB, and IPv6 — the Guardrail does not carry patterns for these.
The Layer 1 output is independently re-processed by an AWS Bedrock Guardrail. No content, topic, or word filters are active — deliberately disabled to avoid blocking compliance terminology. The Guardrail has three tiers of detection: (a) 9 ML-based entity types — NAME, ADDRESS, EMAIL, PHONE, USERNAME, IP_ADDRESS (Mask), and CREDIT_DEBIT_CARD_NUMBER, PASSWORD, AWS_SECRET_KEY (Block — request rejected if detected); (b) 4 India-specific custom regex patterns independently re-checking AADHAAR, PAN, PASSPORT_IN, and MOBILE_IN. For these four types, both Layer 1 and Layer 2 carry independent regex — genuine double-regex coverage. For NAME, ADDRESS, USERNAME, PASSWORD, and AWS credentials, the Guardrail is the only layer. Together: true defence-in-depth where both layers independently process every piece of evidence text.
4
AI inference
The scrubbed text, the control title, and the control description are transmitted to the Claude model via AWS Bedrock (ap-south-1). No other personal data, user details, or organisational metadata is included in the prompt. The model returns a structured JSON response with compliance findings.
5
Human review
AI findings are displayed to the auditor in the platform's "AI Insights" panel. The auditor reviews, adjusts, and determines the final compliance status. No AI-generated finding is automatically written to the audit record.
6
Audit trail
Each AI analysis is logged in the platform's immutable audit trail: timestamp, user ID, control reference, AI model used, and confidence score. Raw evidence text is not logged.
What is NOT sent to AI: Original evidence files are never transmitted. User names, email addresses, organisation names, subscription details, client metadata, or any data beyond the scrubbed evidence text and control description are not included in AI prompts.
Section 04
Privacy & Data Protection Commitments
No model training on your data
We access Claude via the AWS Bedrock API under commercial service terms. Under these terms,
Anthropic and Amazon do not use customer-submitted prompts or responses to train, improve, or
fine-tune their AI models. Your audit evidence and compliance data are never used as training material.
No persistent storage in AI systems
Evidence text passed to Claude is processed in-request only. AWS Bedrock does not retain prompt
content after the API call completes. GRCfy Maestro does not cache, store, or log the scrubbed
evidence text that is sent to the AI model.
India data residency
AI inference for all GRCfy Maestro customers runs exclusively on AWS Bedrock in ap-south-1
(Mumbai, India). This applies to both Standard (Claude Haiku) and Enterprise (Claude Sonnet)
tiers. Text extracted by AWS Textract (for image OCR) also uses ap-south-1.
DPDP Act 2023 alignment
The two-layer PII scrubbing pipeline (structured regex + Bedrock Guardrail) is designed to prevent
personal data from reaching the AI model. Where residual personal data may remain after scrubbing
(e.g., within a complex audit narrative), the Bedrock Guardrail provides a second filter. Processing
occurs under a valid Data Processing Agreement between GRCfy Technologies and the subscriber.
Subscriber responsibility: If evidence documents submitted by your organisation
contain personal data that is integral to the compliance narrative (e.g., an HR policy referencing
employee categories, or a data map referencing data subject classes), that data may be processed
by the AI model after scrubbing passes. Subscribers should review their evidence submission
practices in the context of their own data protection obligations.
Section 05
Sub-processors Involved in AI Processing
Sub-processor
Role
Data Processed
Location
Anthropic PBC via Amazon Web Services
AI model inference (Claude Haiku 4.5 and Claude Sonnet 4.6)
Scrubbed evidence text + control title + control description. No personal identifiers, no user metadata.
AWS ap-south-1 (Mumbai, India)
Amazon Web Services Bedrock, Textract
Bedrock: AI inference gateway and Guardrail (PII entity filter). Textract: OCR for images and scanned PDFs.
Bedrock: scrubbed prompt + control context. Textract: image/scan file (raw, for OCR only; not persisted).
AWS ap-south-1 (Mumbai, India)
Both sub-processors operate under AWS's standard data processing addendum (DPA), which incorporates
Anthropic's usage policy prohibiting training on API-submitted data.
Section 06
Limitations & Important Caveats
AI output is not a legal opinion. AI-generated findings are analytical aids, not professional audit opinions. Compliance determinations must be made by qualified auditors exercising professional judgment.
Confidence scores are probabilistic. A high confidence score indicates the model's internal assessment, not a guarantee of accuracy. Low-confidence findings warrant additional review.
Context boundaries. The AI model receives only the scrubbed evidence text and the control definition — it does not have access to prior audit history, industry-specific regulatory guidance, or organisation-specific context beyond the submitted document.
Language. AI features are optimised for English-language evidence. Accuracy may vary for documents in other languages or mixed-language content.
PII scrubbing is a risk-reduction measure, not a guarantee. The two-layer scrubbing pipeline removes the vast majority of structured and named personal identifiers. Unusual formats or deeply embedded personal references may pass through in rare cases.
Section 07
Contact & Queries
If you have questions about AI processing in GRCfy Maestro, or wish to discuss the implications
for your organisation's data protection obligations, contact us at:
For organisations that require this disclosure in a countersigned PDF format, or that need
additional contractual assurances about AI processing, contact legal@grcfy.com.