Security & data residency

Enterprise-grade tenant isolation, regional data processing by design, and compliance-oriented architecture. Accie OCR is live in India, with more regions later. Your data stays in the region where the product is available.

Quick answer

Accie is designed so your data does not leave your operating region by default. Accie OCR is live in India today. Every tenant is isolated at the authentication, storage, and database layer. We design for compliance from the start — not as a checkbox, but as an architectural principle.

Tenant isolation

Every organisation on Accie is treated as a separate security boundary — not just a partitioned table row:

  • Organisation context comes exclusively from authenticated session tokens or API keys — client-supplied org IDs are never trusted.
  • Document bytes and customer data live in object storage under organisation-scoped prefixes. Access is always via short-lived signed URLs — no persistent open links.
  • Database tables use row-level security (Postgres RLS) keyed on organisation — preventing cross-tenant data leakage at the query layer.

Available regions

India

Live

Accie OCR is live. Documents and account data are processed and retained in India, aligned with the Digital Personal Data Protection (DPDP) Act framework.

More regions

Coming later

Additional countries will be announced only after regional infrastructure is deployed. Data for customers in that region will stay in that region.

This matters for businesses in regulated industries, governments requiring local data retention, CA and accounting firms managing client-sensitive documents, and any organisation expanding across borders.

Contact us for a current data map, region list, and subprocessor details for your specific deployment.

Compliance orientation

We design with compliance frameworks in mind — not as a collection of certification badges, but as an influence on how the product behaves:

  • Purpose limitation — data collected for document extraction is not reused for model training or profiling without explicit opt-in.
  • Access control — role-based access, API key scoping, and organisation-level boundaries limit who can see what.
  • Retention awareness — customers control their document retention. We don't hold data indefinitely.
  • Auditability — extraction jobs, API calls, and user actions are logged at the organisation level.

This is not a claim of legal advice or a completed certification checklist. It describes how we build. For specific compliance requirements — DPDP, PDPA, GDPR, or others — contact us to discuss your needs and our current data map.

Expanding globally

As Accie expands to serve customers in more countries, we commit to:

  • Stating available regions clearly — we won't imply global coverage that doesn't exist yet.
  • Deploying regional infrastructure before announcing regional availability.
  • Maintaining the same tenant isolation and residency architecture in every region.

Privacy policy →  ·  contact@accie.ai for security questions

Security principles

  • Authentication-driven isolation Every request is validated against a session or API key — no trust placed in client-supplied tenant identifiers.
  • Storage scoping Documents live under organisation-namespaced storage prefixes. Short-lived signed URLs, no persistent open access.
  • Database RLS Row-level security at the Postgres layer prevents data leakage across tenants even if application logic has a bug.
  • Regional by default Processing infrastructure deployed per region — data doesn't cross borders by default.
  • No cross-tenant training Your document data is not used to train shared models without explicit consent.
  • Transparent subprocessors Contact us for a current list of subprocessors and infrastructure providers for your region.