Aniket Raj

About the Founder

Aniket Raj

Founder, MandateRoom


Why I built this

Before MandateRoom, I rebuilt this product 29 times.

Each iteration taught me something. The early versions lacked features because I did not yet understand what users actually needed. Later versions became too ambitious as I tried to replicate everything larger platforms offered. Complexity grew, security became harder to guarantee, and the product drifted away from the people it was meant to serve.

I was trying to achieve strong security, complete functionality, and low friction simultaneously. Every architectural decision improved one thing and damaged another.

MandateRoom is the thirtieth iteration. It is the first one I finished.

The reason is simple: I finally understood that for a product handling confidential documents, security cannot be a feature you add later. It has to be part of the architecture from day one.


What I was trying to solve

The people using this product are serious professionals handling confidential processes. They do not need complexity. They need confidence.

Confidence that the document they shared at 9am cannot be downloaded and forwarded by noon. Confidence that if a process changes course, they can lock someone out immediately and know it worked. Confidence that if a document leaks, they can prove exactly who had access and when.

That is what I built MandateRoom to deliver.

Not more features. Not more dashboards. Not more settings to configure.

Just confidence.

The design principle I kept returning to: 100% signal, 0% noise. Every feature that is in this product is there because it completes the workflow. Every feature that is not in this product was removed because it would have added friction without adding security.


What I am, honestly

I am a 26-year-old sole proprietor based in Ghaziabad, India. I have no VC funding, no security team, no SOC 2 certification, and no corporate entity in the US yet.

What I do have:

A product built on infrastructure that serious companies trust — Cloudflare R2 for storage, Vercel for hosting, Supabase for authentication. All three hold independent SOC 2 certifications.

Security controls I designed and built myself: server-side document rendering so original files never reach the browser, dynamic watermarking with viewer identity on every page, cryptographically signed audit logs using HMAC-SHA256 that are tamper-evident by design, and instant access revocation that takes effect on the next request with no cache residual.

I built this on zero capital beyond the domain registration. That is not a boast — it is context. When capital comes in, the first allocations go to security infrastructure, legal structure, and compliance. In that order.


How I think about this product

I am fully invested in this. Not part-time, not as an experiment. This is the work.

I will be wrong about things. The product will have gaps.

Some will be things I missed. Others will be things customers reveal through real-world use.

Either way, they get fixed.

What I will not do is hide limitations behind marketing language. The security page on this site lists exactly what we have and exactly what we do not have. That page exists because the people buying this product are smart enough to find out anyway — and I would rather they hear it from me first.

MandateRoom Version 1 is not the end state. It is the first version that meets the standard I set for shipping.


Contact

Questions about the product, the security architecture, or anything else — email me directly. I respond personally, usually within a few hours.

hello@mandateroom.comlinkedin.com/in/aniket-raj-founder