Skip to content
Proxaradocs
Review pack/The boundary

Data statement

Where the servicer product runs and who can reach what it holds: inference and the analysis record in your Azure tenant, and no standing access for Proxara.

Updated 2026-09-22

Each installation generates its own data statement from its own configuration and its own egress manifest, and that is the one your compliance team reads against the deployed resources. This page is the standard one: what every installation of Proxara for servicers says, before your system names are in it.

The statement

Inference and the primary analysis record run in the customer's Azure environment. Customer-authorised adapters exchange records with the customer's existing servicing, claims and Microsoft 365 services. Proxara has no standing access to borrower records.

Where it runs

  • In one resource group in your own Azure subscription, created by one installer that your administrator runs. See The installer.
  • Every resource belongs to you: the network, the registry, the storage, the database, the key vault, the logs and the managed identity.
  • The signed image is imported by digest into a registry in your own subscription. The model's weights are layers of that image, pinned by digest.

What can reach it

  • Nothing from outside. There is no public application ingress, and nothing listens. The network security groups deny all inbound. Azure creates a managed load balancer and an outbound address for the environment; no application listens on them.
  • No identity outside your tenant holds a role on any resource. Proxara holds no standing access to anything.

What it can reach

  • The reader, the one pinned model that reads documents, has no route to the internet. Its subnet allows outbound traffic only to the private endpoints and the Azure monitoring service tag.
  • The service reaches the private endpoints and the named hosts its adapters use, through one egress client that refuses any other host and logs every call. The hosts, their purpose and how the list is enforced are on the Egress manifest.

Microsoft 365

  • Mail: an Exchange Application RBAC role assignment, Application Mail.Read and Application Mail.Send, scoped to one shared mailbox, the one your attorneys' correspondence is already copied to. No tenant-wide Graph mail permission is granted, because a tenant-wide grant would override the mailbox scope.
  • SharePoint: Lists.SelectedOperations.Selected on one document library, which holds the loan summaries, the portfolio workbook and your policy file. Sites.Selected is not used, because it would grant the whole site.

What it keeps, and where

  • Every input lands in a private container in your storage account, is hashed and recorded, and is never altered afterwards.
  • The feed rows are mapped by code and never reach the model. The model reads only documents.
  • The credentials for your servicing system, claims tool and imaging system are held in your Key Vault.
  • No log carries a borrower identifier or a document body.

What comes in from Proxara

  • The public court record for your loans: county dockets and bankruptcy dockets, collected on our side, public data keyed by case number, published as a signed bundle and pulled by the service.
  • The reference bundle, signed and pulled: the rule versions, the Handbook and Mortgagee Letter texts, FEMA's disaster declarations, HUD's debenture rate tables and the software release manifest.
  • New software arrives as a new signed release. Nothing is pushed into the environment.