Thin client · lender-side

Privileged checks,inside the lender's boundary.

Privileged rails like CERSAI, AA/FIU, CKYC and GeM/PFMS need the lender's own credentials and IP — they can't be handed to a third party. AssureConnect runs them inside the lender's boundary; raw payloads never leave it, and AssureLocker receives only the coded signal, masked summary and provenance hash.

Why it has to be lender-side

The registries bar third-party credential sharing — so we don't try.

CERSAI (and CKYCR, which it operates) prohibit credential sharing and pass-through, and require a unique IP per Reporting Entity. Account Aggregator fetches run under the lender's own FIU. The compliant design isn't to hold those credentials centrally — it's to run the check at the lender and return only the result. That's AssureConnect, and it's what makes the lender-side signals in our packs possible.

The connectors

CERSAI

Id-Based Search for prior charges / double-financing on a receivable — run under the lender's CERSAI membership.

CKYC

CKYCR identity lookup (operated by CERSAI) — same Reporting-Entity rules; lender-run, signal back.

Account Aggregator

Consent-gated cashflow via the lender's own FIU — aggregates only; the raw FI payload is discarded.

GeM / PFMS

Government-buyer signals through the lender's connector — repayment-source certainty for public buyers.

How a check runs

1

Deploy in the lender's VPC

AssureConnect runs as a connector inside the lender's own environment, holding the lender's credentials, DSC and registered IP. No raw registry records, FI payloads, credentials, DSCs or keys leave the lender boundary.

2

Run the privileged check there

When a deal needs CERSAI / AA / CKYC / GeM, the call is made by the lender's connector under the lender's identity — never by AssureLocker.

3

Return a signal, not a record

The connector posts back only a binary/coded signal + a masked summary + a provenance hash. AssureLocker never receives raw registry records or credentials.

Hardened egress (HTTPS-only + SSRF guard + optional mTLS), per-lender DEMO→LIVE gating, and an append-only audit on every live, credential-bound pull.

Storage & security

A messaging layer — not a data store.

AssureConnect is stateless — each check is an independent, credential-bound message. It does not warehouse your data, so it adds no new storage footprint and no new data-custody or security liability. It rides on the credentials and infrastructure you already run.

Processed, then discarded

Raw registry records and FI payloads are processed in-memory inside your environment and dropped. They never persist and never cross the boundary.

Kept: signals + hashes only

What remains is kilobytes, not gigabytes — the coded signal, a SHA-256 provenance hash, and a thin append-only audit line (time, check, result). Account Aggregator keeps only derived aggregate bands, never raw FI data.

Nothing centralised

AssureLocker holds no copy of your raw records or credentials — only the signal + provenance hash that crosses the boundary. There is no central data lake to secure.

Inside the assessment room

AssureConnect powers the privileged signals in every deal.

In the PO and invoice-factoring assessment rooms, the tripartite journey runs the data engine, the borrower interrogator, the analysis engine and the report writer — and when a step needs CERSAI, AA, CKYC or a government-buyer check, AssureConnect runs it lender-side and returns the signal into the pack. The lender sees one coherent, evidence-tiered Risk Signals / Verified Receivables Pack; the privileged data never leaves their boundary.

AssureLocker is a Technology Service Provider. AssureConnect carries signals, never credentials or raw records; the lender owns the credit decision.

Keep your credentials. Get the signals.

What AssureLocker does not do

  • Lend, or guarantee any financing outcome
  • Hold or move funds, or operate escrow
  • Set advance rates or make the credit decision
  • Broker loans or act as a recovery agent

Signals and evidence only — the lender’s system of record makes the credit decision and disburses.

Design-partner programme

Shape it on real deals

A closed programme for NBFCs, banks and supply-chain financiers — influence the signals and thresholds, run a controlled pilot on a ring-fenced deal set, and get preferential early-partner terms.

AssureLocker
Right Vectors India
3rd floor, Innov8, SKCL Tech Square,
SIDCO Industrial Estate, Guindy,
Chennai, TN 600032

AssureLocker is a verification & orchestration platform — not a lender. It supplies verified evidence and risk signals checked against authoritative sources (GSTN, MCA21, EPFO, CERSAI, Account Aggregator) and orchestrates the assessment room. It does not lend, hold or move funds, operate escrow, set advance rates, or make the credit decision — the lender's system of record makes that decision and disburses. Right Vectors India, the provider of AssureLocker, operates strictly as a Technology Service Provider. Every signal is labelled by evidence tier — registry-verified, lender-side, issuer-confirmed, document-signed or self-declared (missing where unresolved); some integrations are in sandbox, lender-side or pilot, and records are written to an immutable registry (hashes only — never raw PII). Signals and figures are point-in-time and consent-bound; confidential to the named parties.

Explainable, evidence-tiered signals — auditable on request. Our algorithmic-accountability approach →

© 2026 Right Vectors India. All rights reserved. · Site version: al-20260721-155225-34ff216c8

Aligned with India Stack. Made in India.