Our platform
A neutral evidence & acceptance layerfor identity & supply chain
AssureLocker compiles identity, trade, capacity, exposure and acceptance into source-cited, cryptographically-anchored evidence — delivered before underwriting and reusable across lenders. We are a Technology Service Provider: we verify, synthesise and surface; the lender decides and funds; the holder consents and controls.
How it fits together
Swipe to explore the full diagram →
What we build
Products & capabilities
The trust spine
One verifiable, post-quantum foundation under every product
Decentralised identity
did:web with an ISO-3166 jurisdiction code; Identity Trust Registry; assurance scoring with decay.
Verifiable credentials
SD-JWT VCs over OID4VP / OID4VCI, with selective disclosure and StatusList revocation.
Post-quantum crypto
ML-DSA-65 (FIPS 204) issuer signing for long-lived artefacts; ML-KEM-768 key encapsulation.
Anchoring
Evidence-hash and membership-event anchoring in an immutable registry — hashes only, never borrower data.
Open-credit ready
Artefacts are OCEN-shaped and map onto ONDC-credit derived-data formats — compatible, not dependent or connected.
Consent & privacy
DPDP-aligned: explicit, revocable consent; data minimisation (derived aggregates, not raw payloads).
Transparency
Data-source & environment posture
Which rail backs which signal, its environment, and how access is obtained. We complement RBI’s ULI — it moves the data, we verify it. A lender-side ULI connector (land & vehicle asset-backing, under the lender’s own ULI membership) now ships, DEMO by default until a pilot lender enables it.
Transparency
Data-source & environment posture
Which rail backs which signal, its environment, and how access is obtained. We complement RBI’s ULI — it moves the data, we verify it. A lender-side ULI connector (land & vehicle asset-backing, under the lender’s own ULI membership) now ships, DEMO by default until a pilot lender enables it.
| Capability | Source / rail | Environment | Access model |
|---|---|---|---|
| Platform API & webhooks | AssureLocker gateway | Live production | OAuth2 client-credentials; sandbox + production modes; HMAC-signed webhooks. |
| Identity (DigiKYC) | GoI Authorised Partner API | Partner-mediated | Live via an authorised verification service provider (a DigiLocker-authorised partner); consent-backed OAuth2 + PKCE. |
| GSTIN · e-invoice (IRN) · e-way | Licensed GSP (Sandbox.co.in) | Partner-mediated | Taxpayer-authorised, server-to-server via a licensed GSP. |
| CIN · DIN · Udyam · Video-KYC | GoI Authorised Partner API | Partner-mediated | API, encrypted. Udyam is existence-only. |
| Account Aggregator cashflow | AA / FIU (via AssureConnect) | Lender-side | Runs on the lender's own AA-FIU credentials; aggregates retained, raw FI data discarded. Not enabled in the shared demo environment. |
| CERSAI charge / receivables search | CERSAI (via AssureConnect) | Lender-side | Per-lender CERSAI membership + DSC, inside the lender's trust boundary. No shared live access. |
| CKYC | CKYC registry (via AssureConnect) | Lender-side | Pulled lender-side on the lender's own CKYC credentials, inside their trust boundary via AssureConnect. No shared live access. |
| ULI land & vehicle asset-backing | RBI ULI (via AssureConnect) | Lender-side | Consumed under the lender's own ULI/RBIH membership, inside their trust boundary. Raw land/vehicle record retained at the lender; only a normalised signal + provenance hash is returned. DEMO by default until a pilot lender enables it. |
| IEC / DGFT (export signals) | DGFT public API | Live production | Unauthenticated DGFT enquiry endpoint — no credentials required. Returns entity name, status, PAN, and issue date. Used in Export & Post-Shipment Signals to confirm the borrower holds an active IEC. |
| Forex inflow corroboration | AA / FIU (via AssureConnect) | Lender-side | Scans the borrower's AA-linked bank narrations for inward remittances (SWIFT / NOSTRO / MT103 patterns) and matches against the overseas buyer name. Runs lender-side; raw narrations are never transmitted. |
| Immutable registry anchoring | Immutable registry | Live production | Hashes only (IST state + VC + event hashes) recorded in an immutable registry — no PII ever leaves our systems. |
AssureLocker gateway
OAuth2 client-credentials; sandbox + production modes; HMAC-signed webhooks.
GoI Authorised Partner API
Live via an authorised verification service provider (a DigiLocker-authorised partner); consent-backed OAuth2 + PKCE.
Licensed GSP (Sandbox.co.in)
Taxpayer-authorised, server-to-server via a licensed GSP.
GoI Authorised Partner API
API, encrypted. Udyam is existence-only.
AA / FIU (via AssureConnect)
Runs on the lender's own AA-FIU credentials; aggregates retained, raw FI data discarded. Not enabled in the shared demo environment.
CERSAI (via AssureConnect)
Per-lender CERSAI membership + DSC, inside the lender's trust boundary. No shared live access.
CKYC registry (via AssureConnect)
Pulled lender-side on the lender's own CKYC credentials, inside their trust boundary via AssureConnect. No shared live access.
RBI ULI (via AssureConnect)
Consumed under the lender's own ULI/RBIH membership, inside their trust boundary. Raw land/vehicle record retained at the lender; only a normalised signal + provenance hash is returned. DEMO by default until a pilot lender enables it.
DGFT public API
Unauthenticated DGFT enquiry endpoint — no credentials required. Returns entity name, status, PAN, and issue date. Used in Export & Post-Shipment Signals to confirm the borrower holds an active IEC.
AA / FIU (via AssureConnect)
Scans the borrower's AA-linked bank narrations for inward remittances (SWIFT / NOSTRO / MT103 patterns) and matches against the overseas buyer name. Runs lender-side; raw narrations are never transmitted.
Immutable registry
Hashes only (IST state + VC + event hashes) recorded in an immutable registry — no PII ever leaves our systems.
AssureLocker supplies evidence and risk signals; it does not lend, hold funds or make the credit decision. Environments shown reflect the shared platform — production access to privileged rails is enabled lender-by-lender under the applicable access rules.
Policy engine
Your policy. Our signals. Your decision.
A no-code policy engine lets each lender configure how and when evidence is gathered and flagged, and how fresh consent must be — never the lending decision itself. You set the sensitivity; the Regulated Entity decides.
When to gather what
Verification trigger rules
Risk officers choose which verification modules run for their deal flow.
- Invoice > ₹10 L → require Udyam & IEC
- GSTIN state ≠ registered state → multi-state AA tax flow
When to flag
Discrepancy & threshold gates
Sensitivity dials on the verification tools — calibrating anomalies, not declaring anyone creditworthy.
- Flag if PO/invoice date vs e-Way date differ by > 7 days
- Flag if PAN ↔ GST name match < 95% (Jaro-Winkler)
How fresh
Consent expiry & recency
The lender's own data-protection standards, executed on the audit trail.
- Fresh Account Aggregator consent if cached financials > 30 days
- Auto-revoke the attestation access key 72 h after a pack
⚠️ TSP boundary: AssureLocker provides verified evidence and signal grading only. All credit scoring, underwriting parameters, and capital allocations are executed solely by the Regulated Entity (Lender).
What we are — and are not
A Technology Service Provider: we never lend, hold or move funds, and never make the credit decision. We are not a lender, a TReDS clone, a lending marketplace or a payment intermediary — we are the neutral evidence and acceptance layer beneath the lending stack, and we feed every lender on it. OCEN-compatible, not dependent on or connected to the network.