How the private receivables scanner is operated.
Factual architecture, data isolation boundaries, and infrastructure controls protecting temporary scan files and derived financial analytics.
24-Hour Ephemeral Lifetime
Uploaded CSVs and derived analysis records automatically expire and purge after 24 hours.
Server-Mediated Isolation
Sessions authenticate via HttpOnly cookie with SHA-256 token hashing. No browser DB keys.
Zero Model Training
Deterministic financial logic only. Financial rows are never transmitted to LLMs or AI providers.
Governed Infrastructure
Hosted on Microsoft Azure App Service in Central India with Supabase private storage.
Private Session Pipeline Architecture
Generates cryptographic session token. Stored in HttpOnly cookie; only SHA-256 hash transmitted.
Stateless compute in Central India. Executes deterministic financial rules. Zero LLM API calls.
Encrypted at rest. Isolated by Row Level Security; no browser Supabase client key exists.
Scheduled hourly cron purge job permanently deletes files and records at 24 hours, or immediately upon user request.
Product Operator
Project Origin is a founder-operated product. Security, privacy, deletion, and data-access requests can be directed to Sailesh Krishnan at saileshkrishnan7@gmail.com.
Hosting and Processing Region
The application runs on Microsoft Azure App Service in Central India. Temporary scanner records and private object storage use Supabase. Operational telemetry and failure monitoring use Azure Application Insights and Log Analytics. The public scanner's calculations are 100% deterministic and do not invoke external artificial intelligence models.
Current Subprocessors
Microsoft Azure provides application hosting, Key Vault secret references, background scheduling, and operational monitoring. Supabase provides the PostgreSQL database and private object storage. The public scanner does not send uploaded CSV content to OpenAI, Resend, Stripe, QuickBooks, or Xero.
Session and Data Isolation
Anonymous scanner sessions use a cryptographically strong random token stored in an HttpOnly, SameSite cookie. Only a SHA-256 token hash is stored server-side. Temporary scanner tables and the source-file bucket cannot be directly queried through the browser; all access is mediated by server routes tied to the active, unexpired session token.
Retention and Deletion
Source CSVs and derived analysis artefacts expire after 24 hours. The “Delete Now” control is accessible throughout the workflow and immediately removes the source file, invoice snapshots, customer records, repairs, findings, reports, and temporary feedback. Non-sensitive audit records may persist solely for operational debugging.
Secrets and Access Controls
Production credentials are server-only and resolved through Azure Key Vault references. Database service-role credentials are never exposed in browser bundles. Application logs and operational telemetry are engineered to sanitize uploaded financial amounts, customer names, and raw invoice text.
Verification Performed
Releases undergo automated Row Level Security tests, cross-session isolation denial checks, schema migration verification, security-header audits, webhook replay resistance, and continuous end-to-end scanner smoke suites. Dependency vulnerabilities are audited prior to every deployment.
Current Assurance Boundary
An external independent penetration test and production load audit have not yet been conducted. The public scanner currently operates on an Azure-managed App Service endpoint secured with HTTPS. These boundaries are published transparently and will be updated as external certifications become available.
Data Use & Consent
Uploaded financial data is never utilized for machine learning model training. Optional product feedback, newsletter subscription, and contact permissions require separate affirmative consent, and granting contact permission does not retain the underlying financial CSV.