Legal
Terms of Service
These Terms of Service govern your use of AssureLocker websites, DigiKYC/DigiKYB verification, evidence and Risk Signals Packs, export-trade evidence, governed credential sharing and step-up assurance for trade and supply-chain financing, entity services, and support and verification workflows.
Effective date: 28 March 2026
1. Acceptance of these terms
AssureLocker is operated by Right Vectors India ("we", "us", "our") — the entity you contract with under these Terms. These Terms of Service govern your access to and use of the AssureLocker website, applications, APIs, credential services, support channels, and related products and services. By accessing or using AssureLocker, you agree to be bound by these terms, our Privacy Policy, any additional product notices or service-specific terms, and any applicable institution, partner, or regulatory terms presented to you.
If you are using AssureLocker on behalf of a company, institution, partnership, or governmental body, you represent that you have the authority to bind that organization to these terms. In that case, references to you also include the organization you represent.
If you do not agree to these terms, you must not access or use AssureLocker.
2. What AssureLocker provides
AssureLocker is a verification, evidence, and risk-signal platform for trade and supply-chain financing — including purchase-order finance, invoice factoring and receivables finance, export finance, supplier and reverse finance, and dynamic discounting. Its products include standalone individual identity verification (DigiKYC) and business or entity verification (DigiKYB); financing-evidence packs such as the PO Risk Signals Pack, the Verified Receivables Pack, and the Export Evidence Pack; verifiable export-trade evidence such as certificate-of-origin corroboration, Legal Entity Identifier (LEI) checks, and bank-realisation references; governed, consent-based credential sharing and step-up assurance controls for regulated verifiers; and related entity, attester, regulator, account, support, and audit functionality.
Services may include verifying entities and trade relationships against authoritative and registry sources through partner-mediated or registry-based pathways, assembling evidence and Risk Signals Packs with an evidence tier on each signal, and orchestrating consent-based information flows between businesses and the lenders or anchor buyers that finance them. AssureLocker reduces fraud, double-financing, and verification risk through structured, consented evidence, audit trails, and lender-controlled decisioning; it does not eliminate risk, and tamper-evident records let a relying party detect alteration but are not a guarantee against every form of compromise.
AssureLocker may add, change, suspend, limit, or retire features at any time. Some features may be available only to certain user categories, geographies, organizations, attesters, regulators, sandbox environments, or approved production users. Some workflows shown in product materials may be sandbox, partner-mediated, or roadmap-dependent.
2A. Financial-services boundary
AssureLocker is, and operates strictly as, a technology service provider. AssureLocker is not a lender, a Lending Service Provider (LSP) or digital lending agent, a banking or business correspondent, a factor, a TReDS or other exchange operator, a payment system, an account aggregator, or a financial-information user. AssureLocker does not lend, underwrite, provide credit decisions, guarantee loan approval, broker, solicit, recommend or arrange loans, set pricing or advance rates, provide financial, legal or credit advice, operate escrow, hold or move client money, or control fund flows. Any lending decision, sourcing, contract, disbursement, repayment instruction, lien, assignment or enforcement action is the sole responsibility of the relevant regulated lender and/or contracting parties.
AssureLocker provides risk scoring and evidence corroboration only. Risk Signals Packs and related outputs are decision-support evidence — they are not legal, financial, credit, underwriting, or investment advice, and must not be relied upon as such. The ultimate credit underwriting decision, and responsibility for verifying a borrower, counterparty or transaction, rest entirely with the funding lender or regulated institution, which remains the regulated entity responsible for customer onboarding, credit policy, contracts, disbursement, repayment instructions, grievance handling, and regulatory compliance for its own customers.
2B. AssureConnect — lender-side connector boundary
Where a lender deploys AssureConnect, it is provided strictly as a local software utility that runs inside the lender's own infrastructure and security perimeter. The lender retains sole custody, control, and ownership of all endpoints, hosting and security environments, network boundaries, and access credentials, and is responsible for the configuration, hardening, monitoring, patching, and operation of AssureConnect within its environment in accordance with its own policies and applicable law.
Privileged registry and consent-based calls — for example CERSAI charge searches or Account Aggregator data fetches — execute within the lender's environment using the lender's own corporate credentials, memberships, and authorisations. Accordingly, the bank or NBFC (or its authorised entity) remains at all times the exclusive legally recognised participant for those calls — for example the Financial Information User (FIU), registry member, or charge-search subscriber — and is solely responsible for holding, using, and maintaining the relevant credentials, memberships, and regulatory authorisations.
AssureLocker accepts no liability for credential misuse, for unauthorised access or data exposure occurring within the lender's host environment, or for any regulatory non-compliance arising from the lender's local data infrastructure, configuration, or operations. AssureConnect is designed so that AssureLocker only processes and ingests localised risk signals and normalised metadata derived inside the lender's perimeter; it does not store, extract, or transmit out raw, unconsented financial information or restricted third-party data from the lender's secure environment, and any signals returned are consent-scoped and minimised by design.
2C. No affiliation, endorsement, or partnership
AssureLocker is independent and is not affiliated with, endorsed by, sponsored by, certified by, or in any partnership or joint venture with any regulator, government body, standards organisation, registry, exchange, or software vendor referenced on this site or within the services, except where a formal written agreement expressly states otherwise. References to such third parties are descriptive — for interoperability, evidence-provenance or educational purposes — and do not imply any relationship, approval, or accreditation.
Without limitation, AssureLocker is not affiliated with or endorsed by: regulators and public bodies including the Reserve Bank of India (RBI), the Reserve Bank Innovation Hub (RBIH), the Securities and Exchange Board of India (SEBI), the Ministry of Electronics and Information Technology (MeitY), and the Ministry of Corporate Affairs; identity and trade-provenance bodies including the Global Legal Entity Identifier Foundation (GLEIF), Legal Entity Identifier India Ltd (LEIL), TradeTrust / IMDA Singapore, OpenAttestation, UNCITRAL (MLETR) and the ICC Digital Standards Initiative; trade-finance rails and their operators including TReDS and RXIL, M1xchange, Invoicemart and C2treds, and the Unified Lending Interface (ULI); India Stack systems and public registries including GSTN, MCA21 (MCA), Udyam, DGFT, ECGC, CERSAI, DigiLocker and the Account Aggregator ecosystem (Sahamati); and any loan-origination, loan-management or enterprise-resource-planning system (LOS / LMS / ERP) or their vendors (including, for example, Tally, SAP and Oracle). All such names, marks and logos are the property of their respective owners and are used for identification and interoperability only.
Any links from the AssureLocker website or services to third-party or official sources are provided for reference and convenience only; AssureLocker does not control, and is not responsible for, the content, availability, accuracy or policies of those external sites, and a link does not constitute endorsement by either party.
3. Eligibility and account registration
You may use AssureLocker only if you are legally able to form a binding contract and to use the relevant AssureLocker services. Some services are intended only for adults, authorized organizational representatives, regulated institutions, attesters, or regulators.
You must provide accurate, current, and complete information when creating or maintaining a AssureLocker account. You are responsible for protecting your credentials, recovery methods, devices, and any account sessions, exports, or backups associated with your AssureLocker account.
You must promptly update your information if it changes, and you must promptly notify AssureLocker through official channels if you suspect unauthorized account access, credential misuse, or compromise.
4. Acceptable use and prohibited conduct
You may use AssureLocker only for lawful, authorized, and intended purposes. You may not use AssureLocker to misrepresent identity, impersonate any person or organization, harvest data, abuse credential-sharing flows, evade security controls, reverse engineer restricted systems, attack or probe the platform, or interfere with any other user's use of AssureLocker.
You must not upload, submit, or share content or information that is false, infringing, unlawful, defamatory, malicious, deceptive, abusive, privacy-invasive, or otherwise harmful. You must not submit credentials, documents, or claims that you are not authorized to submit.
Institutions and entity users must not use AssureLocker to conduct unauthorized surveillance, bulk scraping, discriminatory profiling, spam, denial-of-service activity, or any use inconsistent with law, contract, regulated purpose limitations, or applicable consent and sharing restrictions.
5. Verification, evidence, and credentials
AssureLocker may provide verification, onboarding, KYC/KYB, attestation, re-verification, evidence-assembly, and credentialing workflows using documents, registry and authoritative-source checks (for example company, tax, trade, and charge registries), consented data imports, organizational records, biometric or liveness checks where applicable, and verification providers. Completion of a workflow does not guarantee that a credential, evidence pack, or signal will be issued, remain valid, or be accepted by any lender, counterparty, or relying party.
Credentials, evidence packs, Risk Signals, assurance badges, scores, tiers, DIDs, and tokenised or anchored outputs are subject to platform rules, source and provider quality, attester or reviewer assessment, policy controls, expiry, suspension, revocation, legal requirements, and operational dependencies. Every signal is presented with an evidence tier indicating the strength and source of the underlying evidence.
AssureLocker may refuse, pause, revoke, or restrict issuance, access, or use where data is incomplete, suspicious, inconsistent, expired, legally restricted, operationally unsafe, or otherwise not acceptable under AssureLocker's platform policies, customer obligations, or applicable law.
6A. Consented evidence sharing and lender visibility
Where AssureLocker lets a business maintain a finance-ready evidence profile and, with explicit consent, make selected verified evidence visible to participating lenders for independent review, that capability is a consent-based evidence-sharing channel only. AssureLocker verifies, structures, and distributes borrower-authorised evidence. It does not operate a marketplace; it does not match, rank, recommend, or compare borrowers or lenders; it does not determine eligibility, quote terms, or assure finance; and it does not collect success-based or loan-contingent fees.
Each participating lender reviews shared evidence independently and makes its own decisions under its own credit policy and regulatory obligations. Lender responses are neutral status indicators only and are not approvals, sanctions, eligibility determinations, or guarantees of finance. All outputs are signals and evidence for lender review — not a credit decision, recommendation, sanction advice, or eligibility determination.
7. Lender, anchor, entity, attester, and regulator services
Institutional and organizational services — including lender, financier, anchor-buyer, entity, attester, and regulator services — are available only to users authorized to act on behalf of the relevant organization. Organization administrators are responsible for role assignment, active organization context, webhook and API credential management, internal approval workflows, and compliance with law and AssureLocker platform rules.
AssureLocker may require additional verification, annual declarations, role-based approval, sandbox qualification, compliance reviews, or operational checks before enabling entity features, production API access, or credential-receipt workflows.
Entity and attester users are responsible for ensuring that their use of AssureLocker, including member management, consent settings, webhooks, API integrations, relay flows, and downstream use of verification outputs, complies with applicable law, sectoral obligations, and their own contractual and regulatory responsibilities.
8. Fees, billing, and payments
Certain AssureLocker services may be subject to fees, subscriptions, usage-based charges, attestation charges, renewal charges, or other pricing terms. Pricing is linked to evidence generation, verification, access, and reporting — for example subscription, per-pack, or per-verification charges. AssureLocker does not charge success fees, fees calculated as a percentage of any loan or facility, or fees contingent on a lender's approval, sanction, or disbursement. If fees apply, AssureLocker will generally present pricing or billing context through the website, application, contract, invoice, or institution-facing materials.
You authorize AssureLocker and its payment providers to charge the payment method you designate for the applicable fees, taxes, renewals, adjustments, and other amounts due. Failure to pay may result in suspension, revocation, delayed issuance, restricted access, or inability to use certain platform features.
Except where required by law or expressly stated otherwise, fees are non-refundable once the relevant service has been delivered, reserved, or consumed.
9. Intellectual property and platform rights
AssureLocker and its licensors retain all rights, title, and interest in the website, applications, software, branding, content, interfaces, documentation, models, workflows, and other platform materials, except for rights expressly granted to you under these terms.
Subject to these terms, AssureLocker grants you a limited, non-exclusive, non-transferable, revocable right to access and use the service for its intended purposes. You may not copy, distribute, modify, create derivative works from, scrape, reverse engineer, or otherwise exploit AssureLocker except as expressly permitted by law or written agreement.
You retain rights in content or data you lawfully submit, to the extent you have those rights. You grant AssureLocker the rights reasonably necessary to host, process, secure, transmit, verify, transform, and store that content for the operation of the service and related support, security, compliance, and legal purposes.
10. Suspension, restriction, and termination
AssureLocker may suspend, restrict, refuse, or terminate access to any account, organization, credential, DID, integration, or workflow where necessary for security, fraud prevention, policy enforcement, legal compliance, non-payment, provider failure, regulatory direction, or platform integrity.
You may stop using AssureLocker at any time. Account deletion, erasure, or termination does not necessarily cause immediate deletion of all associated data, especially where AssureLocker is required or permitted to retain data for legal, security, billing, audit, or compliance purposes.
11. Disclaimers
AssureLocker is provided on an as available and as configured basis, subject to applicable law. To the fullest extent permitted by law, AssureLocker disclaims warranties of merchantability, fitness for a particular purpose, non-infringement, uninterrupted availability, or that every credential, integration, provider connection, or verification outcome will be error-free, always available, or accepted by every relying party.
AssureLocker does not guarantee the conduct, decisions, compliance posture, or downstream use of data by independent institutions, attesters, verifiers, regulators, counterparties, or third-party service providers.
12. Limitation of liability
To the maximum extent permitted by applicable law, AssureLocker and its affiliates, licensors, service providers, officers, employees, and agents will not be liable for indirect, incidental, consequential, special, exemplary, or punitive damages, or for loss of profits, revenue, goodwill, business, data, opportunities, or reputation arising from or related to your use of AssureLocker.
To the maximum extent permitted by law, AssureLocker's aggregate liability for claims arising out of or related to the services will not exceed the amount you paid to AssureLocker for the specific service giving rise to the claim during the twelve months preceding the event giving rise to liability, or one hundred Indian rupees if no such payment was made.
Because AssureLocker provides risk scoring and evidence corroboration only, the ultimate credit underwriting decision and all liability for verifying a borrower, counterparty, transaction, or document rest entirely with the funding lender or regulated institution. AssureLocker is not liable for any lending, credit, disbursement, recovery, factoring, or compliance outcome, or for any decision a lender or other party makes in reliance on signals, scores, or evidence.
Nothing in these terms excludes liability that cannot be excluded by law.
13. Indemnity
You agree to defend, indemnify, and hold harmless AssureLocker and its affiliates, officers, employees, licensors, and service providers from and against claims, liabilities, losses, damages, costs, and expenses arising from your misuse of AssureLocker, your violation of these terms, your unlawful or unauthorized use of data or credentials, or your infringement of any third-party rights.
14. Governing law and disputes
These terms are governed by the laws of India, unless a mandatory law or written enterprise agreement requires otherwise. Subject to applicable law and mandatory dispute-resolution rights, courts of competent jurisdiction in India will have exclusive jurisdiction over disputes arising out of or relating to AssureLocker and these terms.
Where AssureLocker provides grievance or internal dispute-resolution channels, you agree to first use those channels in good faith before escalating a dispute, except where urgent legal relief is necessary.
15. Changes to these terms
AssureLocker may modify these Terms of Service from time to time. Updated terms become effective when posted or when otherwise communicated, unless a later effective date is stated. Your continued use of AssureLocker after the effective date of revised terms constitutes acceptance of the updated terms.
Contact and grievances
For questions about these legal terms, privacy requests, or grievance redressal, please use AssureLocker's official support, grievance, or compliance channels made available on the website or inside the AssureLockerapplication. If you are an authenticated holder, the in-app grievance workflow is the fastest path for product-specific issues and rights-related requests.
Legal and privacy contact: [email protected]