Controls you can review. Scope you can decide.

Autofill lives or dies on one question: where does the data go? Ranasi is local-first by design. Ultimate Yearly adds Zero Trust for the agent channel — who may fill, which fields are forbidden, sandbox before post — and exports audit JSON to your SIEM. Cloud is optional, narrow, and documented. Ranasi is not a SIEM, EDR, or 24/7 SOC.

We document real product controls and the principles behind them. This is not a claim of ISO, SOC 2, FedRAMP, or PCI certification. Ask for a vendor questionnaire, subprocessors list, DPA discussion, and attestation roadmap when your review process requires them.

Confidence to pay. Confidence to standardize.

Ranasi is sold as a paid platform — not a free consumer toy — so security and legal teams can treat it like other serious software: clear plans, clear data paths, and a reviewable control story.

  • Primary workflow tool — customize once, Auto-Fill across Firefox, Firefox for Android, and desktop
  • Endpoint control remains yours — forms and uploads stay on the device; MDM / DLP still apply
  • Cloud is a choice — local fill, Ranasi Server AI, or your own OpenAI key
  • Procurement path — vendor questionnaire, subprocessors, DPA discussion, and attestation roadmap on request

What protects your data in practice

Concrete behaviors reviewers can verify — not slogans.

  • Device-held profilesForms, typed values, uploads, and signatures live in storage on the endpoint you manage — not a shared customer data lake Ranasi can browse.
  • Least data to the cloudLicense checks and optional Server AI only. Payment card fields are stripped from server fill. Basic can stay fully local.
  • Explicit AI scopeTurn Server AI off by staying on local fill, or use your own OpenAI key so the request runs under your account and policies.
  • Form Test without retentionPractice Auto-Fill on forms.ranasi.com. Layouts may be optional; filled values are never saved as an answer archive on that site.
  • Encrypted in transitLicense and Server AI calls use HTTPS. Checkout is handled by our payment provider under their PCI-aligned processes.
  • Reviewable & accountablePublished Security page, Privacy Policy, and Terms. Vendor questionnaires, subprocessors, and DPA discussions available on request.
  • Zero Trust for the agent channelUltimate Yearly: who may fill, which fields are forbidden, sandbox before post, field DLP, dual control. Audit JSON exports to the customer's SIEM. Not a SIEM, EDR, CSPM, or 24/7 SOC.

Zero Trust for the agent channel — not a SIEM

Security organizations cannot skip control over how agents enter software. Ranasi ships that control. It does not replace the rest of the stack.

  • Who may fill — org IAM, SSO/SCIM, dual control before post
  • Which fields are forbidden — block card/SSN, field DLP on org_policies
  • Sandbox before post — held jobs + HITL when policy requires review
  • Evidence, not a lake — fill receipts (field UIDs) and screenshot hashes; typed values stay on the device
  • Export to your SIEM— audit JSON for the customer's existing SIEM. Ranasi is not the SIEM
  • Never — CrowdStrike endpoint, cloud CSPM, 24/7 SOC, CyberArk-class PAM

Every path. Explicitly scoped.

Show this table to Infosec. If a path is not required by policy, leave it unused — Basic and local fill never need Server AI.

PathLeaves device?What movesWhere
Local profilesNoForms, typed values, files, images, signatures, attachments, JSONEndpoint only (browser / desktop storage you control)
License activate / validateYes · narrowLicense key + instance idRanasi API over HTTPS (api.ranasi.com)
Server AI Auto-Fill (Pro+)Yes · optionalField metadata + non-card values for mappingRanasi API over HTTPS; card fields stripped
Your OpenAI key (optional)Yes · your accountSame fill payload under your key & policiesOpenAI under your contract — optional BYOK
Form TestLayouts optionalFilled answers stay in page DOM onlyforms.ranasi.com — no answer archive
Org Vault (Ultimate)Yes · templates you publishForm structure, labels, types, hints, optional defaults — not live typed answersRanasi API (region pin us/eu)
Fill receipts (Ultimate)Yes · no valuesActor, portal host, form id, field UIDs, mode, countsRanasi API, retained 365 days
Fill evidence (Ultimate Yearly)Yes · no pixels / no valuesConfidence, form version, screenshot SHA-256, countsRanasi API — screenshot files stay on the filling device
Audit export (Ultimate Yearly)Yes · UIDs / hashesFill receipts and evidence metadata as SIEM JSONCustomer's SIEM — Ranasi is not the SIEM
CheckoutPayment onlyBilling details for purchasePaddle as Merchant of Record (PCI-aligned)

Principles security programs already use

Language Infosec and privacy teams recognize — so Ranasi fits existing control libraries without pretending to hold certificates we have not published.

  • ISO/IEC 27001 principlesConfidentiality, integrity, and availability: minimize what leaves the device, protect API traffic, and keep clear purpose limits on processing — without claiming ISO certification.
  • Privacy by designLocal storage by default. Optional cloud features are explicit. Form Test defaults to not remembering filled answers on the site.
  • Data minimization & purpose limitServer fill sends only what mapping needs. No permanent warehouse of customer form profiles on Ranasi servers.
  • NIST-minded control thinkingIdentify what data exists on the endpoint, protect transit, detect narrow cloud use, and respond via clear policies and contacts — mapped to how Infosec teams already reason, not a NIST certification claim.
  • GDPR-minded handlingDevice-held profiles support data minimization. License and optional AI processing are purpose-limited. Contact us for deletion / DPA discussions when required — not a claim of formal GDPR certification.
  • AccountabilityPublic Security, Privacy, and Terms. Honest non-certification disclaimer. Questionnaire support when your review process needs it.

Local by default · narrow cloud · ready to scale

One product story for every plan — same local-first controls, clearer as you grow.

Local by default

Forms, uploads, and signatures stay on the endpoint. Apply your own MDM and DLP. Evaluate optional cloud AI deliberately — or keep fill on-device.

Narrow, documented cloud

License checks and optional Server AI are explicit paths. Policy teams can approve or decline cloud assist without ambiguity. Card fields stay off Server AI.

Ready to standardize

Enterprise / Ultimate unlock native desktop. Free, Basic, and Pro stay on the browser extension (Free is 10 fields). Ultimate Yearly adds Zero Trust for the agent channel and export to your SIEM. Enterprise / Ultimate add generate, Export as generate source, uploads, and Form Test — with a clear security review path when you need one.

A review path Infosec can finish

  1. Confirm device storageForms, uploads, and signatures stay on the endpoint. Apply your existing extension / desktop MDM and DLP policies.
  2. Decide AI scopeAllow Ranasi Server AI, require BYOK OpenAI, or keep fill local. Card fields are stripped from Server AI either way.
  3. Test without retention riskUse Form Test on forms.ranasi.com knowing filled answers are not archived there.
  4. Request the vendor packEmail enterprise@ranasi.com or use /support for questionnaire support, subprocessors, DPA discussion, and attestation roadmap.
  5. Purchase and standardizeChoose Enterprise or Ultimate when org-scale generate, Export as generate source, uploads, and Form Test are required — then activate with your license key.

Vendor questionnaire & security pack

Request a written response pack: architecture summary, data-flow paths, subprocessors, DPA discussion, and attestation roadmap — without marketing fluff.