Our platform

A neutral evidence & assurance layerfor co-lending, identity & supply chain

AssureLocker compiles identity, trade, capacity, exposure and acceptance into source-cited, cryptographically-anchored evidence — delivered before underwriting and reusable across lenders. We are a Technology Service Provider: we verify, synthesise and surface; the lender decides and funds; the holder consents and controls.

What we build

Products & capabilities

By family

Co-lending assurance [AssureCLA →]

The compliance operating system for co-lending arrangements — every control recomputed from both partners' own records. Signals only; the lender decides.

Supply-chain-finance evidence [AssureSCF →]

Verified evidence at every step of the SCF lending lifecycle — before you lend, as you fund, after disbursement — with the first-financing check before money moves.

Business-lending intelligence [AssureLens →]

The structural truth around a verified borrower, and how fast it is changing — built on verified identity and lender-authorised data. Design-partner stage; evaluated on synthetic data today.

Identity assurance [AssureVerifID →]

Verify an individual or a business once; reuse the proof everywhere, on the holder's consent — the components of the AssureVerifID suite.

What “Live” means: Live capability means the workflow is implemented, deployed and executable end to end in our environment using the disclosed source posture. It does not imply external production adoption by a bank or NBFC — customer deployments are always identified separately. See platform status for runtime health.

The trust spine

One verifiable, post-quantum foundation under every product

Decentralised identity

did:web with an ISO-3166 jurisdiction code; Identity Trust Registry; assurance scoring with decay.

Verifiable credentials

SD-JWT VCs over OID4VP / OID4VCI, with selective disclosure and StatusList revocation.

Post-quantum crypto

ML-DSA-65 (FIPS 204) issuer signing for long-lived artefacts; ML-KEM-768 key encapsulation.

Anchoring

Evidence-hash and membership-event anchoring in an immutable registry — hashes only, never borrower data.

Open-credit ready

Artefacts are OCEN-shaped and map onto ONDC-credit derived-data formats — compatible, not dependent or connected.

Consent & privacy

DPDP-aligned: explicit, revocable consent; data minimisation (derived aggregates, not raw payloads).

Assurance Agents

A platform capability, not a product: assistive agents that draft commentary and prepare evidence across the suites — always source-cited, always human-approved, never deciding. The first deployment runs inside AssureCLA.

Neutral by construction

A Technology Service Provider that is party to no transaction it attests: we never lend, price, decide, broker or hold funds. The evidence we recompute is independent of every counterparty — which is exactly what keeps it usable when partners, auditors or inspectors disagree.

Secure, lender-respecting connectivity

Broad intake without custody grabs: registry and consent rails, tape and webhook adapters for lender systems — while privileged checks (CERSAI, Account Aggregator) always run on the lender's own credentials inside the lender's boundary. Signals leave; raw records never do.

Transparency

Data-source & environment posture

Which rail backs which signal, its environment, and how access is obtained. We complement RBI’s ULI — it moves the data, we verify it. A lender-side ULI connector (land & vehicle asset-backing, under the lender’s own ULI membership) now ships, DEMO by default until a pilot lender enables it.

Platform API & webhooksLive production

AssureLocker gateway

OAuth2 client-credentials; sandbox + production modes; HMAC-signed webhooks.

Identity (DigiKYC)Partner-mediated

GoI Authorised Partner API

Live via an authorised verification service provider (a DigiLocker-authorised partner); consent-backed OAuth2 + PKCE.

GSTIN · e-invoice (IRN) · e-wayPartner-mediated

Licensed GSP (Sandbox.co.in)

Taxpayer-authorised, server-to-server via a licensed GSP.

CIN · DIN · Udyam · Video-KYCPartner-mediated

GoI Authorised Partner API

API, encrypted. Udyam is existence-only.

Account Aggregator cashflowLender-side

AA / FIU (via AssureConnect)

Runs on the lender's own AA-FIU credentials; aggregates retained, raw FI data discarded. Not enabled in the shared demo environment.

CERSAI charge / receivables searchLender-side

CERSAI (via AssureConnect)

Per-lender CERSAI membership + DSC, inside the lender's trust boundary. No shared live access.

CKYCLender-side

CKYC registry (via AssureConnect)

Pulled lender-side on the lender's own CKYC credentials, inside their trust boundary via AssureConnect. No shared live access.

ULI land & vehicle asset-backingLender-side

RBI ULI (via AssureConnect)

Consumed under the lender's own ULI/RBIH membership, inside their trust boundary. Raw land/vehicle record retained at the lender; only a normalised signal + provenance hash is returned. DEMO by default until a pilot lender enables it.

IEC / DGFT (export signals)Live production

DGFT public API

Unauthenticated DGFT enquiry endpoint — no credentials required. Returns entity name, status, PAN, and issue date. Used in Export & Post-Shipment Signals to confirm the borrower holds an active IEC.

Forex inflow corroborationLender-side

AA / FIU (via AssureConnect)

Scans the borrower's AA-linked bank narrations for inward remittances (SWIFT / NOSTRO / MT103 patterns) and matches against the overseas buyer name. Runs lender-side; raw narrations are never transmitted.

Immutable registry anchoringLive production

Immutable registry

Hashes only (IST state + VC + event hashes) recorded in an immutable registry — no PII ever leaves our systems.

AssureLocker supplies evidence and risk signals; it does not lend, hold funds or make the credit decision. Environments shown reflect the shared platform — production access to privileged rails is enabled lender-by-lender under the applicable access rules.

Policy engine

Your policy. Our signals. Your decision.

A no-code policy engine lets each lender configure how and when evidence is gathered and flagged, and how fresh consent must be — never the lending decision itself. You set the sensitivity; the Regulated Entity decides.

01

When to gather what

Verification trigger rules

Risk officers choose which verification modules run for their deal flow.

  • Invoice > ₹10 L → require Udyam & IEC
  • GSTIN state ≠ registered state → multi-state AA tax flow
02

When to flag

Discrepancy & threshold gates

Sensitivity dials on the verification tools — calibrating anomalies, not declaring anyone creditworthy.

  • Flag if PO/invoice date vs e-Way date differ by > 7 days
  • Flag if PAN ↔ GST name match < 95% (Jaro-Winkler)
03

How fresh

Consent expiry & recency

The lender's own data-protection standards, executed on the audit trail.

  • Fresh Account Aggregator consent if cached financials > 30 days
  • Auto-revoke the attestation access key 72 h after a pack
Output is a Signals Verdict ChecklistMatchMismatchPending — manual overridenever “approve” or “reject”.

⚠️ TSP boundary: AssureLocker provides verified evidence and signal grading only. All credit scoring, underwriting parameters, and capital allocations are executed solely by the Regulated Entity (Lender).

What we are — and are not

A Technology Service Provider: we never lend, hold or move funds, and never make the credit decision. We are not a lender, a TReDS clone, a lending marketplace or a payment intermediary — we are the neutral evidence and acceptance layer beneath the lending stack, and we feed every lender on it. OCEN-compatible, not dependent on or connected to the network.

AssureLocker
AssureLocker Pvt Ltd. (inc. in progress)
3rd floor, Innov8, SKCL Tech Square, SIDCO Industrial Estate, Guindy,
Chennai, Tamil Nadu 600032

AssureLocker is a verification & orchestration platform — not a lender. It supplies verified evidence and risk signals checked against authoritative sources (GSTN, MCA21, EPFO, CERSAI, Account Aggregator) and orchestrates the assessment room. It does not lend, hold or move funds, operate escrow, set advance rates, or make the credit decision — the lender's system of record makes that decision and disburses. AssureLocker Pvt Ltd. (inc. in progress), the provider of AssureLocker, operates strictly as a Technology Service Provider. Every signal is labelled by evidence tier — registry-verified, lender-side, issuer-confirmed, document-signed or self-declared (missing where unresolved); some integrations are in sandbox, lender-side or pilot, and records are written to an immutable registry (hashes only — never raw PII). Signals and figures are point-in-time and consent-bound; confidential to the named parties.

Explainable, evidence-tiered signals — auditable on request. Our algorithmic-accountability approach →

© 2026 AssureLocker Pvt Ltd.. All rights reserved. · Site version: al-20260905-192031-5156ce245