Now onboarding a founding cohort of NBFCs — pilot FI volume on us for the first month.
Trust & Security

Built to survive your auditor.

Forward this page to your compliance team. Everything below is implemented and demoable today — and where something is a roadmap item, it says so.

Chain of custody

From the officer’s camera to your audit file — every link verifiable.

1 · Capture

GPS must lock before a report can be submitted. Coordinates, accuracy, timestamp and slot name are burned into every photograph on the officer's device.

2 · Hash

Each image is SHA-256 hashed on the device — the hash covers exactly the stamped file that is stored. Voice notes are stored the same way.

3 · Chain

Every state transition (routed, assigned, visit, submitted, QC, delivered) appends a hash-linked entry to the case's audit chain. Only the workflow engine can write it — direct inserts are closed at the database level.

4 · Verify

The one-click Auditor Pack re-computes the entire chain at export and states the result: report PDF + every evidence file + manifest with hashes, sealed in one archive.

DPDP — in practice, not on a slide

We are your Data Processor. Provably.

Purpose-bound consent, recorded

Every case carries a consent artifact — who attested, when, through which channel (console, bulk, or API). No consent, no case.

Retention enforced, not promised

Each organisation sets an evidence retention period. Expired evidence on closed cases is purged automatically on a daily job.

Aadhaar is never stored

Templates and capture flows are built without Aadhaar fields, by design.

Data stays in India

Application and database run in Mumbai (ap-south-1).

Grievance register

A documented, timestamped complaint trail for outsourced field activity — the RBI outsourcing expectation, built in.

Officer accountability

Every action is attributed to an individual login. Field officers are database-isolated to their own tasks; applicants can QR-verify the officer at the door.

Platform security

Today — and what’s on the roadmap.

Live today
  • Row-level security on every table — each organisation sees only its own rows
  • Role-based access control: credit, ops, finance, agency, officer — least privilege per role
  • API keys stored as SHA-256 hashes; shown once, revocable, per-org
  • Webhooks signed with HMAC-SHA256; delivery log with retry & replay
  • Internal engine functions sealed from anonymous access (least-privilege grants)
  • Evidence in a private bucket — access via short-lived signed URLs only
On the roadmap — stated honestly
  • ISO 27001 certification (process discipline is being built to that bar)
  • Independent VAPT report (scheduled ahead of first bank integration)
  • SSO / SAML for enterprise identity providers
  • Data-processing agreements templated per lender

We list the roadmap because your procurement team will ask — and because a vendor who claims everything is done usually hasn’t been asked hard questions yet.

Want the Auditor Pack in your hands?

Run the pilot — every delivered report in it comes with the sealed, re-verified evidence archive.