mako

Terms

What mako does with your data, who else sees it, and what this platform does and does not decide.

You bring your own provider keys

Your organisation supplies its own API keys for every AI provider this platform calls. Those are your provider accounts and your billing relationship. mako adds no margin, holds no pooled key, and resells nothing — the usage figures on the usage page are an estimate for your own planning, and your provider's bill is the authoritative number.

Where your documents go

A document you upload is sent to the providers you chose, for as long as it takes to transcribe and read it. What each provider does with that data — whether it is retained, and whether it is used for training — is governed by that provider's own terms, not by these. Read them before uploading a borrower's financials.

These are the providers that can be configured. Which of them ever receives a document is entirely a choice made inside your own organisation — signed in, this section lists the ones you actually connected, and nothing else.

  • Google Geminidocument transcription, extraction and underwriting commentarytheir terms
  • OpenAIdocument classification, extraction and underwriting commentarytheir terms
  • Anthropic Claudedocument classification, extraction and underwriting commentarytheir terms
  • DeepSeekdocument classification, extraction and underwriting commentary(check their published terms)
  • LlamaParsedocument transcription for extraction(check their published terms)
  • Mistral OCRdocument transcription for extraction(check their published terms)
  • Tavilyborrower web enrichment and adverse-media search(check their published terms)
  • Exaborrower web enrichment and adverse-media search(check their published terms)
  • Brave Searchborrower web enrichment and adverse-media searchtheir terms

What mako stores

Borrower records, extracted figures and reports are held in a Supabase Postgres database. Uploaded files are held in a private storage bucket (underwriting-documents) that is never publicly readable — a file is served only through a signed link that expires in five minutes.

Every organisation's data is isolated at the database level by row-level security, so a member of another organisation cannot read your files even by asking the database directly.

How your keys are held

Provider keys are encrypted into Supabase Vault. The database stores only the last four characters and a pointer to the encrypted secret. Only server-side code decrypts a key, and only to make a call to that provider. A key is never returned to the browser, never written to a log, and never shown again after you save it.

What this platform decides

Nothing. Everything here is decision-support. The serviceability arithmetic is deterministic and shows its full working; the AI layer classifies documents, extracts figures and drafts commentary. No output approves, declines or conditionally approves a facility, and every extracted figure is editable by an analyst, with the change recorded.

Extracted figures are a starting point, not a verified record. They carry a confidence score and a citation back to the page they came from precisely so that a human checks them.

Deleting your data

You can delete every borrower record your organisation holds at any time, from Settings → Your data. That removes borrower files, documents, extracted figures, assessments and reports, and the stored files behind them.

The audit trail is kept but anonymised: entries lose their link to the borrower and their details, and retain only who acted and when. An audit log that can be erased is not an audit log — and one that still names a deleted borrower is not a deletion.

These terms describe how the software behaves. They are not legal advice, and they do not replace whatever agreement Your organisation has with its own providers or its own customers.