Their Aadhaar card is not a product photo.
When a customer sends you an identity document, WA.cr seals it into a vault the CDN never fronts, masks the ID numbers they type into the chat, and writes down every single time somebody looks — with the reason they gave.
Media is built to be served.
Everything that makes a product photo easy to work with makes a customer's Aadhaar card dangerous to hold: a shareable URL, a cached edge copy, a searchable filename, a delete button. That is the right default for a product photo and the wrong one for an identity document.
The filename alone discloses
aadhaar-front.jpg tells you what it is before anyone opens it. A vaulted document is left out of the media library listing and its search entirely — exclusion, not redaction, because there is nothing to redact in a filename.
A shareable link is a bearer token
Anyone a signed URL reaches can open the file, while the access log still names whoever asked for it. The vault issues no such link: bytes are streamed on the caller’s own session, so a look cannot be passed on.
An edge cache remembers for a year
The media CDN caches immutably and keys on the object path. Vault bytes never go near it — they are served from a private bucket in Mumbai with public access prevented, and never from the branded media domain.
Three ways in — and nothing by accident.
A document is in the vault because someone put it there. Media you have already received is never swept in: guessing which existing images are identity documents would lock a workspace out of its own media on a wrong guess.
- 01
Ask for it in the chat
An agent arms the conversation and asks in their own words — WA.cr sends no message of its own. The next files that contact sends go straight to the vault instead of the media library.
Armed for 24 hours · up to 5 files · one live request per conversation
- 02
Collect it through a WhatsApp Flow
Mark a Flow’s upload step as one that collects identity documents, and every file submitted through it is vaulted on arrival — an onboarding or KYC form that never lands anything sensitive in ordinary media.
Per-Flow switch · optional document type · applies to new submissions
- 03
Move one that is already there
Something sensitive that arrived as a normal attachment can be filed into the vault by hand. The access log records that those bytes were once servable, rather than pretending the file was always sealed.
Recorded as previously shared · an explicit act, never a sweep
Sealed on arrival, off the CDN.
Vaulted bytes go to a private bucket in Mumbai with public access prevented — not to the media store, and never behind the branded media domain. Until a workspace opens one deliberately, a sealed document is simply not servable.
Out of every ordinary door
Vault originals are refused by every byte-serving media route, for everyone — including the people who hold the reveal permission. The reveal endpoint is the only way in, which is what makes the access log complete.
Out of the library and its search
Sealed documents do not appear in the media library, in its search results, or in the media API. They live on their own page, with their own permissions.
Nothing deletes a customer's document
There is no operator delete, by design. A document is destroyed by policy, by retention, or by a data-subject erasure — never by somebody clicking the wrong button on a bad day.
Aadhaar is locked, not just sealed
WA.cr is not an authorised Aadhaar agency, so it holds no openable unmasked UID image. An Aadhaar original is stored and locked: no permission in the workspace opens it, not even the Owner’s. The console says so plainly rather than implying the file is gone.
The number they typed, not just the file they sent.
A vault protects a document somebody uploaded. It does nothing for the customer who types their Aadhaar number into the chat, or reads their PAN aloud in a voice note you transcribe — the easier disclosure, and the more common one.
In the thread, everyone sees:
XXXX XXXX 0124
The last four digits stay visible and the spacing is preserved — the same form UIDAI itself publishes as a masked Aadhaar, so the customer can still confirm you have the right document. A chip under the message names what was hidden, so nobody is left guessing whether a number was there at all.
- Aadhaar number
- PAN
- Passport number
- GSTIN
- Voter ID
- Driving licence number
- Passport data line
It would rather miss than guess
Nothing matches on shape alone. Every detection carries a validating checksum — the Verhoeff digit on an Aadhaar, the mod-36 character on a GSTIN — or a context word beside it, and the shapes that collide with things people legitimately type carry both. Rupee amounts and phone numbers are never mistaken for identifiers.
Including on the lock screen
Masking applies wherever text reaches a screen: the thread, voice-note transcripts and the inbox preview line. Push notifications are masked always and carry no reveal — a lock screen sits outside every permission you have granted.
Nothing stored is rewritten
Masking happens as the message is read, so the record still holds exactly what was sent — “I never sent you that number” stays answerable — and sharper detection later covers your whole history, retroactively.
Opening one is an act, not a setting.
Sometimes a real person genuinely has to look. That stays possible — it just stops being invisible.
A written reason, every time
Between 5 and 500 characters, typed by the person opening the document, before anything is served. The reason is stored on the audit row — not as a dropdown of tidy excuses, but as a sentence somebody has to stand behind.
A 120-second window
A reveal grants two minutes on the original, streamed through the caller’s own session. Long enough to read the document, too short to be worth passing on — and there is no link to pass on in the first place.
One message at a time
Revealing a masked number shows it in a panel beside the thread; it is never written back into the conversation. Close it and the mask returns. A second look costs a second reason, because a “reveal this thread” button would be one audit row for an unbounded number of disclosures.
Four permissions, and a record of every look.
Seeing that a document exists, handling it, and opening it are three different rights — because for most of the work your team does, the masked view is enough.
See that it exists
The document list, its type and status, and every masked field.
Held by Owner · Manager · Agent · Viewer
Handle documents
Ask a customer for one, file one, add notes, and read the access history.
Held by Owner · Manager · Agent
Break the glass
Open an original, or reveal a masked number — with a written reason.
Held by Owner · Manager
Seal and unseal
Close a single document to everyone, or reopen one that was sealed.
Held by Owner · Manager
A Manager can never lock out the Owner
A strict workspace can bind even Owner accounts out of break-glass. Sealing, though, is deliberately never restrictable — so whoever owns the workspace always keeps a way back into their own documents.
The product's first read audit
Every other audit row in WA.cr records a change. Here the question a regulator actually asks is “who looked at this, and why” — so views, reveals and seals are all written down, and the record itself never stores a document’s contents, a file path or a value.
On Enterprise, priced per deal.
Secure documents is for regulated and high-compliance businesses — lending, insurance, healthcare, travel, anyone whose onboarding asks a customer for identity proof. It is quoted rather than sold self-serve, because it usually arrives with questions your compliance team wants answered first.
Losing the plan never unseals anything
The entitlement gates intake, never access. A workspace that moves off Enterprise stops being able to vault new documents, and keeps every document it already has — sealed, audited and reachable. A downgrade must never turn identity documents back into ordinary media.
What it supports, plainly
Data residency in Mumbai, a written reason on every disclosure, and a complete record of who opened what — the evidence a DPDP obligation asks you to produce. Retention and erasure are handled as policy, with your team, rather than by a switch on this page.
Where it is today. Sealing, masking, break-glass reveal and the access log are live. Automatic redaction of a document’s own pages is still in build — until it lands, a vaulted document stays sealed and unprocessed, which is the safe state rather than a preview we cannot vouch for. We would rather tell you that now than in an audit.
The same care, applied to everything else.
Where your data lives, who inside your workspace can reach it, and what the audit trail records — for every conversation, not only the sensitive ones.
Ask us what it would take to hold yours.
Tell us which documents your onboarding collects and what your compliance team needs to see. We will walk you through the vault, the audit trail and what Enterprise costs for a workspace your size.