Compliance is a property of the platform, not a checklist.
Every compliance rule is enforced in the platform — not in a slide, not in a policy PDF, not in agent training.
The Architecture of Trust
Security is not an afterthought added by an infrastructure team; it is baked into the very data model that runs the platform.
India-region by default
All borrower data, recordings, and decisioning workloads run in an India region. No borrower data leaves the country for routine operations.
RBI calling-hour locks
Outbound calls are restricted to the 8 AM–7 PM IST window at the dialer layer. Agents cannot override.
TRAI DNC / NDNC enforcement
DNC and NDNC registry lookups gate every outbound channel — voice, SMS, and WhatsApp.
DPDP audit posture
Immutable, partition-aware audit log captures every request and response, with PII redaction policy enforced in code.
Data-layer tenant isolation
Tenant scoping is enforced at the data layer — not just by application code.
Recording and retention
100% call recording with retention-aware policy. Per-tenant configuration.
The posture, at a glance.
- Data residency
- >_India region · by default
- Calling-hour policy
- >_08:00–19:00 IST · platform-enforced
- Frequency cap
- >_≤ 3 calls / contact / day
- Call recording
- >_100% · per-tenant retention
- Tenant isolation
- >_Defense-in-depth at the data layer
- AI region
- >_In-region only · no cross-border calls
Book a 30-minute walkthrough
See Credmux run a real recovery workflow.
We'll show calling, Smart Collect attribution and decisioning, payment-link orchestration, and field visit evidence — using common DPD bands and industry-standard workflows.
Or write to compliances@credmux.com