Skip to content
KanchanFlow
Trust Center

What we can prove, and what we cannot

Compliance status with the unfinished items named, every sub-processor listed, our security practice written out, and a quarterly audit of our own feature claims.

  • Delaware LLC
  • SOC 2 Type II
  • USA Data Centers (AWS)
Diagram titled "What we can prove", showing the seven RFQ-to-order stages from enquiry intake through to accepted order.

In short

KanchanFlow is an RFQ-to-Order CRM operated by Soor LLC from Delaware, USA, running on USA data centers with a SOC 2 Type II audit in place. This page lists what is certified, what is not yet audited, what we will never certify, and every sub-processor that touches your data.

1. Data and compliance

Where we stand today

Two lists, kept separate on purpose. Mixing an achieved audit with an aspiration in one badge row is the oldest trick in enterprise software, and we are not doing it.

In place today

  • Delaware-Registered LLC
  • SOC 2 Type II
  • CCPA Compliant
  • GDPR Compliant
  • USA-Based Team
  • USA Data Centers (AWS)
  • 99.9% uptime target

Hosting is USA (AWS US-East + US-West). The uptime target is 99.9%, measured on the application, and the team operating it is USA-based.

Not yet, or never

  • ISO 27001Planned· Wave 3

    Wave 3 — not yet audited

  • AS9100 / CMMC certificationPlanned· Never

    Never — KanchanFlow is the CRM, not the certifier. We ship an immutable audit log for compliance-driven manufacturers.

Neither of these appears anywhere else on this website as a badge, a logo or an implication. If you ever find one that does, that is a bug — tell us and we will pull it.

2. Feature truth audit

We audit our own marketing

Every feature this website advertises carries a status badge — live, beta, building or planned — and the badge is not a marketing decision. Once a quarter we take the full list of claims made across the site and check each one against the code that is supposed to back it.

The rules are deliberately blunt. LIVE means it is in production and a customer outside our own workspace has used it. BETA means it works and has been customer-tested but is not finished. BUILDING means it is in development with a visible target. PLANNED means we intend to build it and have no date, and saying so is more useful than inventing one.

When a claim fails the check, one of three things happens: the badge is downgraded, the wording is edited to describe what the software actually does, or the claim comes off the site entirely. The result is published on what's shipping.

Quarterly checkOutcome
Does a shipped code path back the claim?Yes / No, per feature
Is it running in production, not behind a flag?Determines LIVE versus BETA
Has a customer used it outside our own workspace?Required for LIVE
Does the marketing wording match what it actually does?Wording is edited down if not
Does it have a visible target date if not shipped?Required for BUILDING; PLANNED carries no date
Read the current audit

3. Integration trust

Every connector shows when it was last tested

Integrations rot quietly. An API version is deprecated, a field is renamed, an auth flow changes, and a connector that worked in March is silently broken by September while its marketing page still says "works with".

So every integration page carries a visible last-tested date, and we re-test every connector at least quarterly against a live sandbox. If a connector fails a test, its page says so before support hears about it from you.

  • A visible last-tested date on every integration page
  • Quarterly re-test minimum, against a live sandbox for each vendor
  • A failing connector is marked on its own page, not quietly patched later
  • Deprecations we know about are stated with the date they take effect
  • Connectors nobody uses get retired rather than left as decoration
See all integrations

4. Sub-processors

Everyone who touches your data

This is the complete list. We give customers notice before adding to it, and the DPA carries the objection mechanism.

Cross-referenced by our data processing addendum. Notice is given before a new sub-processor is added.
Sub-processorPurposeRegion
Amazon Web ServicesApplication hosting, database, object storage and backupsUSA — US-East (N. Virginia) and US-West (Oregon)
Meta Platforms (WhatsApp Business Platform)Delivery and receipt of WhatsApp messages on your registered WABA numbersUSA / global Meta infrastructure
StripeCard and ACH subscription billing for USD customersUSA
RazorpaySubscription billing for INR customersIndia
Microsoft Azure Document IntelligenceOCR of RFQ attachments, spec sheets and purchase ordersUSA region endpoints
Transactional email providerDelivery of quotes, notifications and system email from the productUSA

Razorpay appears because INR-billed customers are charged in India; it processes billing data only and never touches RFQ, quote or customer records. The full processor terms, including standard contractual clauses and breach notification, are in the data processing addendum.

5. Security practices

How the system is actually run

  • Encryption in transit — TLS 1.2 or better on every connection, including API, webhooks and the mobile apps
  • Encryption at rest — AES-256 on databases, object storage and backups
  • Role-based access control — roles map to the eight shop roles, with record-level scoping by territory and by dealer
  • Audit logging — authentication, permission changes, quote revisions, price overrides and exports are logged; Enterprise gets the immutable audit log and compliance dashboard
  • Backups — encrypted daily backups with point-in-time recovery, retained 30 days, restore-tested quarterly
  • RTO and RPO targets — 4-hour recovery time objective and 1-hour recovery point objective, against a 99.9% uptime target
  • Least privilege for our own staff — production access is scoped, time-bound and logged; no standing production database access
  • Responsible disclosure — report a vulnerability to [email protected] — we acknowledge within two US business days and will not pursue good-faith researchers
Uptime target
99.9%
Measured on the application, not the marketing page.
RTO
4 hours
Recovery time objective for a full-region incident.
RPO
1 hour
Maximum data loss window in a recovery scenario.
Backup retention
30 days
Encrypted, with point-in-time recovery, restore-tested quarterly.

Responsible disclosure

Found something? Email [email protected] with steps to reproduce. We acknowledge within two US business days, keep you updated through the fix, and will not pursue good-faith research. Please do not test against another customer's workspace or run load tests against production.

6. Data residency

USA by default, elsewhere by contract

No offshore replication on any tier. EU and India residency require a separate deployment, which is why it is contractual rather than a settings toggle.
TierDefault residencyAlternative residency
StarterUSA (AWS US-East + US-West)Not available
ProfessionalUSA (AWS US-East + US-West)Not available
EnterpriseUSA (AWS US-East + US-West)EU or India, by contract

Every tier defaults to the USA and stays there unless a signed Enterprise contract says otherwise. Backups sit in the same jurisdiction as the primary. If you need a residency we do not offer, tell us before you buy rather than after — the answer may be no, and it is a cheaper no now.

Trust and security questions

Yes, under NDA. Write to [email protected] or ask your account contact. We share the report itself rather than a summary slide, because a summary slide is not evidence of anything.

See a live quote draft built from a real RFQ

Fourteen days, no credit card, sample data pre-loaded. If it does not fit your shop, we will tell you in the first call.

  • Delaware LLC
  • SOC 2 Type II
  • USA Data Centers (AWS)