Skip to content

Everything runs in your own Azure tenant.

One installer your administrator runs. It reads the files you already receive, writes back into the systems you already use, and reaches nothing else.

One installer, run once by your administrator, in your own tenant.

proxara_env-01
Private environment
Overview
Folders
Access log
Keys
Microsoft AzureMicrosoft 365

One invocation, under your own permissions. Nothing goes back to Proxara.

1Install

Every resource comes from one template, in a resource group you name, and our signed image is imported into your own registry.

2Grant

An Exchange role on one shared mailbox and a grant on one SharePoint library, nothing tenant-wide. Your system credentials go into your own Key Vault.

3Verify

It checks every feed, a test write to MSP, the claims tool, the imaging system, the mailbox, the library and GPU quota. A gap is named, and a re-run resumes.

4Run

It starts on your existing caseload, every live default read once, then keeps every position current through claim.

One environment per servicer. Nothing pooled, nothing shared.

It works with what you already run.

It reads the MSP or Sagent files you already receive, the AACER feed, the attorney portal’s export, one shared mailbox and your imaging export. It writes back into MSP, Cloud-Claims or ICE Claims and one SharePoint library, and prepares the Catalyst claim where you submit direct.

Connected
Attorney mailOne mailbox
Loan summariesOne library
Imaging exportRead and filed
MSP nightly fileRead

One pinned model reads the documents.

Feed rows never touch it. It runs on a GPU in your tenant that starts when documents are waiting and stops when they are read, with no route to the internet.

It runs on your own Azure bill.

Measured on a 20,000-loan workload over three real days in a clean subscription, cold starts and model loading included.

$167

Fixed, each month.

The service on half a CPU, the database, the registry, the private endpoints and the network, at East US retail rates.

$3.29

Per hour the reader runs.

The GPU starts when documents are waiting and stops when they are read. None stays warm, and start-up is counted.

$600

The tested ceiling, each month.

Illustratively $364 plus metered storage, logs and transactions. The cost report is generated from the measured figures.

What it reaches, and nothing else.

The reader has no route to the internet. The service reaches only the hosts in the egress manifest your compliance team reads, through one client that refuses any other host and logs every call.

Microsoft Graph
The one shared mailbox and the one SharePoint library.
Microsoft Entra ID
Sign-in for its own managed identity.
Your servicing system
MSP through your own Interchange and DIS access, or Sagent’s write APIs.
Your claims and imaging
Claim records in, the merged claim and its documentation back.
Proxara’s bundles
Signed rules, court records and releases, pulled by the service.

No public application ingress, and nothing listens. Where you run a firewall, the installer routes outbound through it, so your perimeter enforces the same list.

Questions your IT will ask.

What access does Proxara keep?
None. No identity outside your tenant holds a role, and Proxara has no standing access to borrower records.
What does it get in Microsoft 365?
An Exchange role scoped to one shared mailbox and a grant on one SharePoint library. Nothing tenant-wide.
Can the reader reach the internet?
No. Its subnet has no route out, only to the private endpoints inside your tenant and Azure’s own monitoring.
What does it write to MSP?
Extended deadlines, holds and re-projections in the workstations’ own fields, a loan-history note, and a task only when an answer is needed.
What if our MSP write access is not granted?
It is a prerequisite, confirmed at onboarding. The installer checks it with a test write before anything runs.
How do we verify the image?
It is signed with cosign and ships its SLSA provenance and an SBOM. Every build is scanned for vulnerabilities.
What goes in the logs?
Every outbound call, with its host. No borrower identifier and no document body is logged.

Yours throughout.

The paperwork, for your compliance team.

The data statement, the egress manifest and the installer runbook, as your reviewer will read them. Questions about the boundary go to security@proxara.ai.