EnterpriseHosted in Mumbai

Their Aadhaar card is not a product photo.

When a customer sends you an identity document, WA.cr seals it into a vault the CDN never fronts, masks the ID numbers they type into the chat, and writes down every single time somebody looks — with the reason they gave.

01The problem

Media is built to be served.

Everything that makes a product photo easy to work with makes a customer's Aadhaar card dangerous to hold: a shareable URL, a cached edge copy, a searchable filename, a delete button. That is the right default for a product photo and the wrong one for an identity document.

The filename alone discloses

aadhaar-front.jpg tells you what it is before anyone opens it. A vaulted document is left out of the media library listing and its search entirely — exclusion, not redaction, because there is nothing to redact in a filename.

A shareable link is a bearer token

Anyone a signed URL reaches can open the file, while the access log still names whoever asked for it. The vault issues no such link: bytes are streamed on the caller’s own session, so a look cannot be passed on.

An edge cache remembers for a year

The media CDN caches immutably and keys on the object path. Vault bytes never go near it — they are served from a private bucket in Mumbai with public access prevented, and never from the branded media domain.

02Intake

Three ways in — and nothing by accident.

A document is in the vault because someone put it there. Media you have already received is never swept in: guessing which existing images are identity documents would lock a workspace out of its own media on a wrong guess.

  1. 01

    Ask for it in the chat

    An agent arms the conversation and asks in their own words — WA.cr sends no message of its own. The next files that contact sends go straight to the vault instead of the media library.

    Armed for 24 hours · up to 5 files · one live request per conversation

  2. 02

    Collect it through a WhatsApp Flow

    Mark a Flow’s upload step as one that collects identity documents, and every file submitted through it is vaulted on arrival — an onboarding or KYC form that never lands anything sensitive in ordinary media.

    Per-Flow switch · optional document type · applies to new submissions

  3. 03

    Move one that is already there

    Something sensitive that arrived as a normal attachment can be filed into the vault by hand. The access log records that those bytes were once servable, rather than pretending the file was always sealed.

    Recorded as previously shared · an explicit act, never a sweep

03The vault

Sealed on arrival, off the CDN.

Vaulted bytes go to a private bucket in Mumbai with public access prevented — not to the media store, and never behind the branded media domain. Until a workspace opens one deliberately, a sealed document is simply not servable.

Out of every ordinary door

Vault originals are refused by every byte-serving media route, for everyone — including the people who hold the reveal permission. The reveal endpoint is the only way in, which is what makes the access log complete.

Out of the library and its search

Sealed documents do not appear in the media library, in its search results, or in the media API. They live on their own page, with their own permissions.

Nothing deletes a customer's document

There is no operator delete, by design. A document is destroyed by policy, by retention, or by a data-subject erasure — never by somebody clicking the wrong button on a bad day.

Aadhaar is locked, not just sealed

WA.cr is not an authorised Aadhaar agency, so it holds no openable unmasked UID image. An Aadhaar original is stored and locked: no permission in the workspace opens it, not even the Owner’s. The console says so plainly rather than implying the file is gone.

04Masking

The number they typed, not just the file they sent.

A vault protects a document somebody uploaded. It does nothing for the customer who types their Aadhaar number into the chat, or reads their PAN aloud in a voice note you transcribe — the easier disclosure, and the more common one.

In the thread, everyone sees:

XXXX XXXX 0124

The last four digits stay visible and the spacing is preserved — the same form UIDAI itself publishes as a masked Aadhaar, so the customer can still confirm you have the right document. A chip under the message names what was hidden, so nobody is left guessing whether a number was there at all.

  • Aadhaar number
  • PAN
  • Passport number
  • GSTIN
  • Voter ID
  • Driving licence number
  • Passport data line

It would rather miss than guess

Nothing matches on shape alone. Every detection carries a validating checksum — the Verhoeff digit on an Aadhaar, the mod-36 character on a GSTIN — or a context word beside it, and the shapes that collide with things people legitimately type carry both. Rupee amounts and phone numbers are never mistaken for identifiers.

Including on the lock screen

Masking applies wherever text reaches a screen: the thread, voice-note transcripts and the inbox preview line. Push notifications are masked always and carry no reveal — a lock screen sits outside every permission you have granted.

Nothing stored is rewritten

Masking happens as the message is read, so the record still holds exactly what was sent — “I never sent you that number” stays answerable — and sharper detection later covers your whole history, retroactively.

05Break glass

Opening one is an act, not a setting.

Sometimes a real person genuinely has to look. That stays possible — it just stops being invisible.

A written reason, every time

Between 5 and 500 characters, typed by the person opening the document, before anything is served. The reason is stored on the audit row — not as a dropdown of tidy excuses, but as a sentence somebody has to stand behind.

A 120-second window

A reveal grants two minutes on the original, streamed through the caller’s own session. Long enough to read the document, too short to be worth passing on — and there is no link to pass on in the first place.

One message at a time

Revealing a masked number shows it in a panel beside the thread; it is never written back into the conversation. Close it and the mask returns. A second look costs a second reason, because a “reveal this thread” button would be one audit row for an unbounded number of disclosures.

06Access

Four permissions, and a record of every look.

Seeing that a document exists, handling it, and opening it are three different rights — because for most of the work your team does, the masked view is enough.

  • See that it exists

    The document list, its type and status, and every masked field.

    Held by Owner · Manager · Agent · Viewer

  • Handle documents

    Ask a customer for one, file one, add notes, and read the access history.

    Held by Owner · Manager · Agent

  • Break the glass

    Open an original, or reveal a masked number — with a written reason.

    Held by Owner · Manager

  • Seal and unseal

    Close a single document to everyone, or reopen one that was sealed.

    Held by Owner · Manager

A Manager can never lock out the Owner

A strict workspace can bind even Owner accounts out of break-glass. Sealing, though, is deliberately never restrictable — so whoever owns the workspace always keeps a way back into their own documents.

The product's first read audit

Every other audit row in WA.cr records a change. Here the question a regulator actually asks is “who looked at this, and why” — so views, reveals and seals are all written down, and the record itself never stores a document’s contents, a file path or a value.

07Availability

On Enterprise, priced per deal.

Secure documents is for regulated and high-compliance businesses — lending, insurance, healthcare, travel, anyone whose onboarding asks a customer for identity proof. It is quoted rather than sold self-serve, because it usually arrives with questions your compliance team wants answered first.

Losing the plan never unseals anything

The entitlement gates intake, never access. A workspace that moves off Enterprise stops being able to vault new documents, and keeps every document it already has — sealed, audited and reachable. A downgrade must never turn identity documents back into ordinary media.

What it supports, plainly

Data residency in Mumbai, a written reason on every disclosure, and a complete record of who opened what — the evidence a DPDP obligation asks you to produce. Retention and erasure are handled as policy, with your team, rather than by a switch on this page.

Where it is today. Sealing, masking, break-glass reveal and the access log are live. Automatic redaction of a document’s own pages is still in build — until it lands, a vaulted document stays sealed and unprocessed, which is the safe state rather than a preview we cannot vouch for. We would rather tell you that now than in an audit.

Ask us what it would take to hold yours.

Tell us which documents your onboarding collects and what your compliance team needs to see. We will walk you through the vault, the audit trail and what Enterprise costs for a workspace your size.

We use a few cookies to improve WA.cr. How we use cookies