What we can prove, and what we cannot
Compliance status with the unfinished items named, every sub-processor listed, our security practice written out, and a quarterly audit of our own feature claims.
- Delaware LLC
- SOC 2 Type II
- USA Data Centers (AWS)
In short
KanchanFlow is an RFQ-to-Order CRM operated by Soor LLC from Delaware, USA, running on USA data centers with a SOC 2 Type II audit in place. This page lists what is certified, what is not yet audited, what we will never certify, and every sub-processor that touches your data.
1. Data and compliance
Where we stand today
Two lists, kept separate on purpose. Mixing an achieved audit with an aspiration in one badge row is the oldest trick in enterprise software, and we are not doing it.
In place today
- Delaware-Registered LLC
- SOC 2 Type II
- CCPA Compliant
- GDPR Compliant
- USA-Based Team
- USA Data Centers (AWS)
- 99.9% uptime target
Hosting is USA (AWS US-East + US-West). The uptime target is 99.9%, measured on the application, and the team operating it is USA-based.
Not yet, or never
- ISO 27001Planned· Wave 3
Wave 3 — not yet audited
- AS9100 / CMMC certificationPlanned· Never
Never — KanchanFlow is the CRM, not the certifier. We ship an immutable audit log for compliance-driven manufacturers.
Neither of these appears anywhere else on this website as a badge, a logo or an implication. If you ever find one that does, that is a bug — tell us and we will pull it.
2. Feature truth audit
We audit our own marketing
Every feature this website advertises carries a status badge — live, beta, building or planned — and the badge is not a marketing decision. Once a quarter we take the full list of claims made across the site and check each one against the code that is supposed to back it.
The rules are deliberately blunt. LIVE means it is in production and a customer outside our own workspace has used it. BETA means it works and has been customer-tested but is not finished. BUILDING means it is in development with a visible target. PLANNED means we intend to build it and have no date, and saying so is more useful than inventing one.
When a claim fails the check, one of three things happens: the badge is downgraded, the wording is edited to describe what the software actually does, or the claim comes off the site entirely. The result is published on what's shipping.
| Quarterly check | Outcome |
|---|---|
| Does a shipped code path back the claim? | Yes / No, per feature |
| Is it running in production, not behind a flag? | Determines LIVE versus BETA |
| Has a customer used it outside our own workspace? | Required for LIVE |
| Does the marketing wording match what it actually does? | Wording is edited down if not |
| Does it have a visible target date if not shipped? | Required for BUILDING; PLANNED carries no date |
3. Integration trust
Every connector shows when it was last tested
Integrations rot quietly. An API version is deprecated, a field is renamed, an auth flow changes, and a connector that worked in March is silently broken by September while its marketing page still says "works with".
So every integration page carries a visible last-tested date, and we re-test every connector at least quarterly against a live sandbox. If a connector fails a test, its page says so before support hears about it from you.
- A visible last-tested date on every integration page
- Quarterly re-test minimum, against a live sandbox for each vendor
- A failing connector is marked on its own page, not quietly patched later
- Deprecations we know about are stated with the date they take effect
- Connectors nobody uses get retired rather than left as decoration
4. Sub-processors
Everyone who touches your data
This is the complete list. We give customers notice before adding to it, and the DPA carries the objection mechanism.
| Sub-processor | Purpose | Region |
|---|---|---|
| Amazon Web Services | Application hosting, database, object storage and backups | USA — US-East (N. Virginia) and US-West (Oregon) |
| Meta Platforms (WhatsApp Business Platform) | Delivery and receipt of WhatsApp messages on your registered WABA numbers | USA / global Meta infrastructure |
| Stripe | Card and ACH subscription billing for USD customers | USA |
| Razorpay | Subscription billing for INR customers | India |
| Microsoft Azure Document Intelligence | OCR of RFQ attachments, spec sheets and purchase orders | USA region endpoints |
| Transactional email provider | Delivery of quotes, notifications and system email from the product | USA |
Razorpay appears because INR-billed customers are charged in India; it processes billing data only and never touches RFQ, quote or customer records. The full processor terms, including standard contractual clauses and breach notification, are in the data processing addendum.
5. Security practices
How the system is actually run
- Encryption in transit — TLS 1.2 or better on every connection, including API, webhooks and the mobile apps
- Encryption at rest — AES-256 on databases, object storage and backups
- Role-based access control — roles map to the eight shop roles, with record-level scoping by territory and by dealer
- Audit logging — authentication, permission changes, quote revisions, price overrides and exports are logged; Enterprise gets the immutable audit log and compliance dashboard
- Backups — encrypted daily backups with point-in-time recovery, retained 30 days, restore-tested quarterly
- RTO and RPO targets — 4-hour recovery time objective and 1-hour recovery point objective, against a 99.9% uptime target
- Least privilege for our own staff — production access is scoped, time-bound and logged; no standing production database access
- Responsible disclosure — report a vulnerability to [email protected] — we acknowledge within two US business days and will not pursue good-faith researchers
- Uptime target
- 99.9%
- Measured on the application, not the marketing page.
- RTO
- 4 hours
- Recovery time objective for a full-region incident.
- RPO
- 1 hour
- Maximum data loss window in a recovery scenario.
- Backup retention
- 30 days
- Encrypted, with point-in-time recovery, restore-tested quarterly.
Responsible disclosure
Found something? Email [email protected] with steps to reproduce. We acknowledge within two US business days, keep you updated through the fix, and will not pursue good-faith research. Please do not test against another customer's workspace or run load tests against production.
6. Data residency
USA by default, elsewhere by contract
| Tier | Default residency | Alternative residency |
|---|---|---|
| Starter | USA (AWS US-East + US-West) | Not available |
| Professional | USA (AWS US-East + US-West) | Not available |
| Enterprise | USA (AWS US-East + US-West) | EU or India, by contract |
Every tier defaults to the USA and stays there unless a signed Enterprise contract says otherwise. Backups sit in the same jurisdiction as the primary. If you need a residency we do not offer, tell us before you buy rather than after — the answer may be no, and it is a cheaper no now.
Trust and security questions
Yes, under NDA. Write to [email protected] or ask your account contact. We share the report itself rather than a summary slide, because a summary slide is not evidence of anything.
Related
Data processing addendum
Processor role, sub-processors, SCCs and 72-hour breach notification.
Read morePrivacy policy
What we collect, why, and how long we keep it.
Read moreWhat's shipping
The current feature truth audit.
Read moreAll integrations
Connectors with visible last-tested dates.
Read moreAbout Soor LLC
Who runs this, where, and since when.
Read moreContact
Security, privacy, sales and support routes.
Read moreSee a live quote draft built from a real RFQ
Fourteen days, no credit card, sample data pre-loaded. If it does not fit your shop, we will tell you in the first call.
- Delaware LLC
- SOC 2 Type II
- USA Data Centers (AWS)