Edific

Security & deployment

Where the processing happens is the decision, not a detail.

Your firm handles confidential client documents — invoices, statements, KYC files, contracts — that cannot leave your environment. For a regulated firm that isn’t a preference. It’s the constraint everything else has to fit inside.

Edific is built around that constraint. The engine deploys on your own server or VPS, inside your perimeter. Documents are processed where they already live — nothing is sent to a third-party API, nothing is retained by anyone but you.

The architecture

GDPR compliance stops being a policy question and becomes an architectural fact.

Six things worth knowing about how Edific actually runs — the data cannot leak from a place it never went.

Runs on your infrastructure

Deployed on your own server or VPS, inside your perimeter — not a portal you upload client files to.

GDPR by architecture

The data never moves, so compliance is structural, not contractual — there is no third-party processor to vet.

The evaluation gate

Every number is validated before you see it. Totals must reconcile; nothing passes on confidence alone.

Logged by default

Every field carries a confidence score and a log entry — which document, which field, which reviewer.

Art. 28 DPA included

Written for how the system actually works, not a generic template.

Read the DPA
Accountable delivery

A named point of contact owns your engagement — build, deployment, and the signed DPA — one name on the contract, not a support queue.

Said plainly

What we don’t claim

Edific is not ISO 27001 or SOC 2 certified. Those are real audits — months of work and real spend — and we won’t put a badge on this site for compliance work we haven’t done. We don’t run a public trust portal or claim continuous monitoring either, because there is no vendor system for us to monitor: the documents are processed on your server, not ours.

A certificate says a vendor’s systems were audited at a point in time — trust extended to a third party. Here there is no third party in the loop to certify: the data never leaves the environment you already control, and every decision the system makes is logged with a confidence score you can inspect yourself. For a firm handling confidential client documents, we think that is the stronger guarantee. Judge it on that basis, not on badges we don’t have.

Questions worth asking

Asked before, answered plainly

The questions worth asking before you send us a document. Can’t find your answer here?

Nowhere. Edific runs on your own server or VPS; it is never sent to us or a third party. That is a design decision, not a setting you can turn off.

Edific. A named point of contact owns your engagement end to end — the same person you talk to signs the DPA and stands behind the result. Less brand, more accountability.

On our published test — 3 hard receipts, ~15% for standard OCR — Edific got 18 of 18 fields correct. Small, deliberately hard sample, presented as exactly that. The number that matters is the one from a pilot on your own documents.

Its job is to be wrong loudly. The evaluation gate flags uncertain fields for human review before export, and any slip is traceable in the audit log and fixed at the source.

Scoped per engagement, not per seat — it follows volume, document types, and infrastructure. You get a fixed quote after a pilot. No pilot, no quote.

Yes, structurally. Processing happens on your own infrastructure, and the Art. 28 DPA describes the architecture as it actually works.

Next step

See it on your own documents

Not a deck. Not a demo dataset. Send a batch of your real documents — the difficult ones — and get back verified, structured data with every field scored and logged. Then decide.

Runs on your infrastructure. Covered by a DPA. Edific accountable for the result.