About AssureLocker

Independent evidence and control infrastructure for regulated lending.

AssureLocker turns fragmented identity, registry, tax, trade and banking evidence into reusable, consent-backed, independently verifiable signals — built for regulated finance. Lenders, anchors and institutions act on the evidence; every credit and onboarding decision stays with them.

It interoperates with India Stack-style registries, consent flows and verifiable-credential standards — producing timestamped records verified against authoritative sources, shared at the holder's discretion through a portable wallet.

We are evidence integrity infrastructure beneath lenders, not a balance-sheet lender.

Vision

A future where every regulated lending decision — starting with co-lending and the trade finance beneath it — is made on evidence that is source-verified, consented and independently provable, not on uploaded documents and manual trust.

Mission

To turn fragmented identity, registry, tax, trade and banking evidence into reusable, consent-backed, independently verifiable signals for regulated lenders — making good risk visible, without ever taking the credit or onboarding decision away from the institution that owns it.

Holder-first & consent-gated

Identity lives in the holder's wallet, not an institution's database. Every share is consent-gated and revocable — proofs, not raw documents.

Verifiable evidence, not claims

We check registry, tax, trade and banking sources and turn them into independently verifiable signals — cryptographically verifiable, tamper-evident, timestamped, and traceable to the authoritative source.

The decision stays with the institution

AssureLocker is a Technology Service Provider. We surface evidence and signals; the regulated lender or institution owns every credit and onboarding decision.

Explainable, and accountable

Every signal is sourced, evidence-tiered and cited, and we hand a lender's model-governance team a vendor audit pack mapped to its FREE-AI obligations. We measure evidence integrity, not creditworthiness — and we don't discharge the lender's own fairness duties.

High-grade, post-quantum security

Records are signed with post-quantum ML-DSA-65; holder keys are non-extractable, hardware-backed where the device supports it; mutual-TLS at the edge, data minimised and consent-audited, DPDP/GDPR-aligned — with ISO 27001:2022 and SOC 2 readiness in progress.

DPI-native, provenance-anchored

A distinctive solution built on India's digital public infrastructure — Account Aggregator, GST, MCA, Udyam, ULI and DigiLocker — with identity state and evidence hashes anchored to an immutable registry, turning identity and supply-chain credit-risk opacity into verifiable, reusable provenance.

What we built

One evidence foundation. Four regulated-lending suites.

The evidence foundation is AssureVerifID — source-verified identity, the common entity-and-signatory assurance layer every regulated-lending workflow relies on. Individuals and entities onboard once — DigiLocker, CKYC, registry + OTP, or biometric match — and receive a W3C Verifiable Credential recorded in an immutable, independently-verifiable registry. From then on they present a cryptographic proof, not a raw document — reusable KYC and KYB across participating relying institutions and workflows.

On that foundation sit four regulated-lending suites. AssureCLA runs a neutral assurance overlay across co-lending arrangements — AssurePlane independently recomputes each RBI-mandated control from both lenders’ own books, AssurePool carries that same evidence through a sale or transfer. AssureSCF is a verified-evidence layer across PO, invoice and export finance — AssureSignal, AssureAccept and AssureMonitor are live; AssureFirst, the shared verification registry beneath them, is at design-partner stage. AssureLens turns exposure and credit-accumulation signals into explained alerts, also at design-partner stage. Each suite is built and demo-ready; live regulated-entity connectivity comes next, one design partner at a time. Each signal carries its evidence tier; the lender decides.

The registry records only identity state transitions and VC/evidence hashes — never raw PII. The holder carries the credential; the institution receives a proof or a signal — and every credit and onboarding decision stays with the regulated institution.

Explore the products

Identity (KYC) — onboarding paths

DigiLocker / partner-mediated

OAuth 2.0 + PKCE; via an authorised verification service provider

Registry + OTP

Document registry lookup with mobile OTP

Liveness / face-match

Via approved providers, where required and permitted by law

CKYC (KIN + OTP)

Central KYC Registry lookup — lender-side via AssureConnect

Transparency

Every signal, labelled by evidence tier

We are honest about how strongly each thing is evidenced — registry-verified, consent-pulled, issuer-attested, document-signed or self-declared — and exactly which rail backs which signal, in which environment.

See the live posture
AssureLocker data-source and environment posture table

Technology

Built components, sandbox workflows and roadmap integrations — clearly separated.

DigiLocker / partner-mediated import

PKCE + HMAC; subject to production access & integration approvals

W3C VC + SD-JWT

Selective disclosure, not full payloads

ML-DSA-65 signing

NIST FIPS 204 post-quantum

Immutable registry

IST state + VC hashes recorded, tamper-evident

OID4VP compliant

Signed authorization requests, vp_token

DPDP/GDPR controls mapped

DPO fields, consent audit, data minimisation — readiness work in progress

Company

Private-sector trust infrastructure, built in India

AssureLocker is built and operated by AssureLocker Pvt Ltd. (inc. in progress), a Chennai-based technology company building independent evidence and control infrastructure for regulated lending — verifiable credentials, consented data, registry-grade verification and an immutable registry.

We serve lenders, anchors and the businesses they finance — turning fragmented identity, registry, tax, trade and banking evidence into reusable, independently verifiable signals. We measure evidence; the regulated institution owns every credit and onboarding decision.

At a glance

Legal entity

AssureLocker Pvt Ltd. (inc. in progress)

Headquarters

Chennai, Tamil Nadu, India

Focus

Independent evidence and control infrastructure for regulated lending

GSTIN

33********1K1ZS

The Founder Story

The insight that led to AssureLocker

Founder-led — a career spent building the plumbing of digital trust. It began with identity and trade-finance evidence, and evolved into the control infrastructure for co-lending.

DN

Deepak Norman

Founder & CEO

RBI HaRBInger 2025 finalist. 16 years at a major Australian bank — trade & supply-chain finance, payments and cash-management technology — a 30-year career across banking, telecom, DPI, digital trust and AI.

TM

Theo Manohar

Chief Financial Officer

30+ years in Finance, Internal Audit and Administration across Policy, Governance and Execution.

Current work & recognition

Deepak Norman formerly contributed to India’s national blockchain initiative at IIT Madras — a permissioned ledger system integrating digital identity, programmable governance, and secure public-private data flows, laying groundwork for transformative change in payments, digital trust, and service delivery.

A strategic technology leader and transformation specialist, Deepak brings three decades of experience across banking, telecommunications, and digital platforms. He has led large-scale programs at ANZ and Telstra, and held senior roles delivering digital portfolios and cloud transformations at Link Group. A certified GAICD and CISA, Deepak combines deep expertise in payments, SaaS, enterprise IT, and risk governance — leadership spanning high-impact portfolios, global cross-functional teams, and executive stakeholder engagement to drive customer-focused innovation and operational resilience.

Why we built AssureLocker

AssureLocker did not begin as a lending product. It began as a trust problem.

For years, the missing ingredient in MSME and trade finance has not been capital alone. Banks, NBFCs and financiers have capital. What they often lack is cheap, reusable confidence: confidence that the buyer is real, the seller is genuine, the invoice exists, the goods moved, the warehouse receipt is not duplicated, the receivable has not already been pledged, and the evidence a borrower presents can survive audit, dispute and recovery.

Our founder has lived that problem from both sides.

Our founder spent 16 years at a major Australian bank — and more than two decades across large-scale banking and digital-transformation environments — in Global Transaction Banking, payments, cash management, trade and supply-chain finance, technology risk and regulated-platform delivery. From inside the bank the issue was clear: many viable transactions stall not because the business is weak, but because the evidence around the transaction is fragmented, slow, self-reported or hard to trust.

That same career runs through the other side of the problem — years spent building the rails that make digital trust possible: decentralised identity, verifiable credentials, trust registries, permissioned registries and standards-based infrastructure. Not a speculative technology story: the practical application of cryptographic evidence, consented data and registry verification to a real financing problem.

AssureLocker brings those two worlds together.

It started where the evidence was thinnest — source-verified identity, and the trade behind a purchase order or receivable. But the same gap — no cheap, shared, provable truth between counterparties — turned out to be the defining problem of co-lending: two regulated lenders sharing one loan under RBI-mandated controls, with no independent record either side can trust. So the evidence foundation evolved into a control layer— independently recomputing and proving each co-lending control from both lenders’ own books.

Today AssureLocker is the independent control and evidence infrastructure for regulated lending — co-lending first, and the identity and trade finance it grew from. We do not lend. We do not price credit. We do not move funds. We do not replace the bank, NBFC or financier. Instead, we help them answer the questions that slow financing down:

  • Is this entity verified?
  • Is this buyer relationship genuine?
  • Is this invoice or receivable real?
  • Has this asset or receivable already been pledged elsewhere?
  • Is there registry-grade evidence behind the transaction?
  • Which parts of the evidence are independently verifiable, and which are merely attested?

AssureLocker turns scattered trade evidence into structured, consented and tamper-evident signals a lender can verify, reuse and audit.

Where authoritative sources exist — GST e-invoice, e-way bill, CERSAI, e-NWR repositories, DGFT, ICEGATE, bank-side data and other regulated registries — we verify against them. Where no universal source exists — insurance, bills of lading, quality certificates — we do not overclaim: we classify the evidence honestly through issuer confirmation, trust ladders and risk-adjusted attestation.

That distinction matters.

The future of regulated lending — co-lending, and the trade finance beneath it — will not be built on uploaded PDFs and manual trust. It will be built on evidence and controls that are source-linked, consented, tamper-evident, portable and independently provable across financing relationships. AssureLocker exists to make that possible.

It gives lenders better signals without taking their decisions away. It gives borrowers a way to carry verified transaction evidence without repeating the same documentation burden again and again. And it gives the market a cleaner way to separate financeable transactions from unverifiable claims.

AssureLocker is not trying to make lenders take more risk.

It is trying to make good risk visible.

Build on
verifiable trust.

Whether you're securing your identity or underwriting trade on better evidence — start here.

AssureLocker
AssureLocker Pvt Ltd. (inc. in progress)
3rd floor, Innov8, SKCL Tech Square, SIDCO Industrial Estate, Guindy,
Chennai, Tamil Nadu 600032

AssureLocker is a verification & orchestration platform — not a lender. It supplies verified evidence and risk signals checked against authoritative sources (GSTN, MCA21, EPFO, CERSAI, Account Aggregator) and orchestrates the assessment room. It does not lend, hold or move funds, operate escrow, set advance rates, or make the credit decision — the lender's system of record makes that decision and disburses. AssureLocker Pvt Ltd. (inc. in progress), the provider of AssureLocker, operates strictly as a Technology Service Provider. Every signal is labelled by evidence tier — registry-verified, lender-side, issuer-confirmed, document-signed or self-declared (missing where unresolved); some integrations are in sandbox, lender-side or pilot, and records are written to an immutable registry (hashes only — never raw PII). Signals and figures are point-in-time and consent-bound; confidential to the named parties.

Explainable, evidence-tiered signals — auditable on request. Our algorithmic-accountability approach →

© 2026 AssureLocker Pvt Ltd.. All rights reserved. · Site version: al-20260905-192031-5156ce245