Regulatory posture
Where we sit —
and where we don’t.
AssureLocker is a technology service provider for consent-backed identity, KYB/KYC and risk-signal workflows. It supplies evidence and signals; the lender’s system of record makes the credit decision and disburses. One page on the boundary, data handling, evidence tiers, standards and jurisdiction.
“Signals, not decisions. Lender-side, consent-based, no custody, no underwriting.”
What AssureLocker does
- Verify evidence against authoritative sources and label each signal by tier
- Assemble Risk Signals / Verified Receivables Packs and run conflict checks
- Detect first-financing / duplicate-financing signals (AssureFirst) — a lender-side CERSAI search plus a fingerprint recorded in an immutable registry, so the same receivable financed twice is caught
- Orchestrate the assessment room and deliver review-ready packs to the lender
- Operate lender-side connectors (AssureConnect) inside the lender's boundary
- Anchor tamper-evident hashes (state, VC and event hashes) where enabled
What it does not do
- Lend, guarantee an outcome, hold or move funds, set advance rates or make the credit decision
- Score credit, train a credit model, or operate as an AI credit-decision engine — a signal's confidence reflects evidence quality, not creditworthiness; the lender owns its own FREE-AI / fairness assessment of how it uses our signals
- Run a receivables exchange or bid-and-discount platform — that is the RBI-licensed TReDS operators' domain; we are complementary (off-exchange, pre-shipment, unsecured)
- Match borrowers to lenders or run a loan marketplace — signals go to the lender you already have a relationship with, who owns the customer and the decision
- Broker, introduce or refer for commission, take a cut of the deal, or act as a recovery agent
- Resell raw verification calls — the value is the corroborated, tiered, scored signal, not a single lookup
- Retain raw Account Aggregator FI data (aggregates only)
- Consent-bound and purpose-limited; signals are point-in-time and confidential to the named parties.
- Minimum retention by design — for Account Aggregator data we compute aggregates and discard the raw FI payload.
- Privileged registry rails (CERSAI, AA, CKYC) run inside the lender’s trust boundary via AssureConnect, on the lender’s own credentials — never shared.
- Registry / API-verified — Checked live against an authoritative source (e.g. GSTN, MCA21, DGFT).
- Consent-pulled — Retrieved with the subject's consent (e.g. AA cashflow on the lender's FIU).
- Issuer-attested — Confirmed by the issuing party or a licensed channel.
- Document-signed — Backed by a cryptographically signed document (e.g. DSC).
- Self-declared — Stated by the party; labelled as the weakest tier.
- W3C Verifiable Credentials, OID4VP and SD-JWT for selective disclosure
- Working towards SOC 2 Type I and ISO/IEC 27001:2022, with independent VAPT
- DPDP-aligned consent, purpose limitation and minimum-retention by design
- Tamper-evident audit trail; cryptography detailed on the Trust page
India is the first jurisdiction. Identifiers carry an ISO 3166-1 country code, and the platform is designed to be jurisdiction-abstracted. Empanelment, outsourcing approval and production access to privileged rails are handled lender-by-lender under the applicable RBI outsourcing, digital-lending, data-protection and registry-access rules.
Signals, evidence, lender-side connectors, consent and an audit trail — no lending, no custody, no decisioning. Final regulatory classification depends on function, not posture statements alone; we keep our function on the right side of that line.