Skip to content

Borrower files stay in your environment.

Proxara is installed by your IT inside your own Azure account, and every page of every file is read and worked there.

Privacy is the first requirement.

A mortgage file holds everything about a borrower, so nothing in Proxara depends on moving one. Proxara never holds a borrower file, has no login to your systems and keeps no standing access.

  • Nothing leaves.

    Documents are read and results are written inside your own Azure account. No file, page or value goes to Proxara, to a model service or to any new party.

  • Encrypted, in your name.

    Files sit on encrypted storage in your subscription and are reached only over TLS. Every secret is in your own Key Vault, with purge protection on.

  • Deleted when the work is done.

    When a loan closes, or sits idle past the period you set, its documents, page images and text are deleted, and the deletion is logged. The result PDF stays in your store.

Where it runs.

In your own Azure subscription, in a resource group you choose, or on a GPU server you prepare inside your firewall. Your administrator runs one command. It checks before it builds anything, and everything it creates is in your name.

  1. 01
    It checks first.

    Your tenant, the people you named, the A100 quota, the region, the permissions and your network policy, and the monthly price. Only the empty environment it reads the quota from exists by then; a block stops it there.

  2. 02
    It verifies what it pulls.

    The application, the pinned model and the rule release arrive signed. Every signature and every file hash is checked before anything runs.

  3. 03
    It builds in your name.

    One container app on one A100, encrypted storage, your Key Vault and one sign-in registration in your Entra. No database, cache, cluster or gateway of its own.

  4. 04
    It hands over.

    All seven components are checked, the ownership confirmed, your address printed and a receipt kept for every stage.

The model runs where the data is.

One open-weight model reads the documents, on the GPU in your own Azure account. It listens only inside its container and makes no outbound call. No page is ever sent to a model service.

It reads. Code decides.
The model reads each page and points at the words it used. Income, ratios, limits and rules are ordinary code that gives the same answer every run.
Pinned in the release.
The model’s version and every file’s hash are fixed in the signed release and checked when it is staged. A new model arrives only as a new release, after the full regression.
One GPU, nothing beside it.
One A100 in your account, billed by the second while awake. No second GPU, no separate reading service and no call to a public model.

Who can open a loan.

Only the people you assign, through the Microsoft sign-in they already use. Proxara has no account in your tenant and no way in.

Your own sign-in.
People sign in with their work account in your Microsoft Entra. The installer registers one single-tenant application, with no password and no certificate to hold.
Two roles, assigned by you.
Mortgage.User opens the page. Mortgage.Specialist adds specialist review. Assignment is required, so a person without a role sees nothing.
One result, shared on purpose.
A loan officer can send one result to an assigned specialist in your organization. A new link replaces the last, and either can be revoked.
On the record.
Opening a loan’s documents is logged by person, and every export and every deletion is logged, in your environment.

What it connects to, and what it reaches.

It works through access you already hold. Everything it reads arrives by a path you control, and everything it writes lands in your own systems.

Your systems

  • Arive

    Reads the loan by number from the MISMO 3.4 export Arive already produces, with your own keys, and writes a link to the result back into the loan record.

  • DU and LPA

    Submits the loan and takes back the findings through the lender access you already hold, with your own credentials, and works each round inside your environment.

  • UWM

    Hands over the chosen structure as a MISMO 3.4 file, which ChatUWM accepts for a One-Click AUS run.

  • Microsoft Teams

    Opens as a tab behind your tenant’s sign-in. A notice goes to a channel only through a Workflows webhook your administrator sets up.

Every outbound call

The publisher’s registry
The signed application image, pulled with a limited token at install and update.
The signed rule feed
Rule releases, read with a read-only token, polled hourly, each verified before it runs.
The model’s pinned source
The model files, while they are staged, each checked against the signed manifest.
Azure and Microsoft Entra
Your resources, the registration and tokens for its own identities.
The virus-signature mirror
Signatures for the scanner that checks every file, when the application starts and then daily.

Beyond these, only what you add: your Teams webhook, the webhook an API key names, Arive’s API with your keys, and DU and LPA through your own lender access. There is no telemetry, no heartbeat and no crash reporting.

Questions security teams ask.

How do updates arrive?
As signed releases. Your environment pulls each with a limited token, verifies the signature and upgrades in place under its own identity. A rule release is bound to the exact application image it was signed for.
How does support work without access?
From a diagnostics bundle your IT exports: versions, timings, rule identifiers, error classes and health. It carries no borrower data, and nobody at Proxara can read it without you.
How does it fit the Safeguards Rule?
The FTC Safeguards Rule is the floor it is built to: encryption at rest and in transit, access through your own sign-in and roles, access logged per document and per person, every export logged, and working files deleted when a loan closes.
What does it cost to run?
The A100 bills by the second while awake, about USD 2.16 an hour, and nothing while stopped except storage. On the 06:00 to 20:00 Eastern window that is about USD 992 a month with storage and logs included, before tax, printed in the installer’s quote before anything that holds a file is created.

Put your questions to the people who built it.

Book a call with the engineers, or write to security@proxara.ai. The resources are declared as Bicep, so your team can read every one before anything runs.