Where the processing happens is the decision, not a detail.
Your firm handles confidential client documents — invoices, statements, KYC files, contracts — that cannot leave your environment. For a regulated firm that isn’t a preference. It’s the constraint everything else has to fit inside.
Edific is built around that constraint. The engine deploys on your own server or VPS, inside your perimeter. Documents are processed where they already live — nothing is sent to a third-party API, nothing is retained by anyone but you.
GDPR compliance stops being a policy question and becomes an architectural fact.
Six things worth knowing about how Edific actually runs — the data cannot leak from a place it never went.
Runs on your infrastructure
Deployed on your own server or VPS, inside your perimeter — not a portal you upload client files to.
GDPR by architecture
The data never moves, so compliance is structural, not contractual — there is no third-party processor to vet.
The evaluation gate
Every number is validated before you see it. Totals must reconcile; nothing passes on confidence alone.
Logged by default
Every field carries a confidence score and a log entry — which document, which field, which reviewer.
Accountable delivery
A named point of contact owns your engagement — build, deployment, and the signed DPA — one name on the contract, not a support queue.
What we don’t claim
Edific is not ISO 27001 or SOC 2 certified. Those are real audits — months of work and real spend — and we won’t put a badge on this site for compliance work we haven’t done. We don’t run a public trust portal or claim continuous monitoring either, because there is no vendor system for us to monitor: the documents are processed on your server, not ours.
A certificate says a vendor’s systems were audited at a point in time — trust extended to a third party. Here there is no third party in the loop to certify: the data never leaves the environment you already control, and every decision the system makes is logged with a confidence score you can inspect yourself. For a firm handling confidential client documents, we think that is the stronger guarantee. Judge it on that basis, not on badges we don’t have.
Asked before, answered plainly
The questions worth asking before you send us a document. Can’t find your answer here?
Nowhere. Edific runs on your own server or VPS; it is never sent to us or a third party. That is a design decision, not a setting you can turn off.
Edific. A named point of contact owns your engagement end to end — the same person you talk to signs the DPA and stands behind the result. Less brand, more accountability.
On our published test — 3 hard receipts, ~15% for standard OCR — Edific got 18 of 18 fields correct. Small, deliberately hard sample, presented as exactly that. The number that matters is the one from a pilot on your own documents.
Its job is to be wrong loudly. The evaluation gate flags uncertain fields for human review before export, and any slip is traceable in the audit log and fixed at the source.
Scoped per engagement, not per seat — it follows volume, document types, and infrastructure. You get a fixed quote after a pilot. No pilot, no quote.
Yes, structurally. Processing happens on your own infrastructure, and the Art. 28 DPA describes the architecture as it actually works.
Next step
See it on your own documents
Not a deck. Not a demo dataset. Send a batch of your real documents — the difficult ones — and get back verified, structured data with every field scored and logged. Then decide.
Runs on your infrastructure. Covered by a DPA. Edific accountable for the result.

