Security posture

Security you can verify, not just trust.

AssureLocker handles consent-backed identity and risk-signal workflows for regulated lenders. Here is exactly how we secure it, what we hold, and where each data source stands.

Certifications

Independent certification is in progress — SOC 2 Type I and ISO/IEC 27001:2022, with independent VAPT and certification readiness underway (dry-runs complete; independent VAPT scheduled within 90 days of first pilot commencement). We state status honestly: nothing here is described as “certified” until the report is in hand. Production deployment profiles support private connectivity, controlled egress and autoscaling for batch and real-time flows, subject to lender environment and deployment model.

Encryption & post-quantum

TLS in transit and encryption at rest. Long-lived issuer-signed artefacts (SD-JWTs, receipts, OID4VP requests) are signed with ML-DSA-65 (NIST FIPS 204); key encapsulation uses ML-KEM-768 — so records stay verifiable beyond the classical-crypto horizon.

Data minimisation

We compute and persist aggregates, not raw sensitive payloads. Account-Aggregator bank data is reduced to derived metrics immediately and the raw FI payload is discarded — designed to support lender/FIU obligations under the AA framework and our minimum-retention principle.

Tamper-evident registry

Membership, credential and consent events are SHA-256 hashed and recorded in an immutable registry — an immutable, independently verifiable provenance trail. Only the hash is written to the registry; raw PII never leaves our store.

Consent & audit

Every share is consent-gated and produces an append-only audit record you can export — who shared what, with whom, under which consent, and when.

India data residency

Production keeps customer data hosted and processed within India, on infrastructure in an Indian data centre — supporting RBI data-localisation expectations and the DPDP Act, so regulated lenders keep customer data onshore.

DPDP posture

Built for India's DPDP Act: per-entity Data Protection Officer fields, a scroll-to-accept Data Processing Agreement, purpose-limited collection, and consent artefacts on every data flow.

Sandbox vs production

Sandbox requests are tagged end-to-end (env claim on the token), webhooks to your endpoint are suppressed in sandbox, and no billable external calls are made. You validate fully before you go live.

Security controls — in detail

Stated as it actually is today. In place means implemented; in progress and on the roadmap are honest about what we’re still building — no control is claimed before it’s real.

Access control

In place

Role-based access across every portal, DID-based entity membership with least-privilege roles (OrgAdmin / SysAdmin / Manager / Technician / Operator / Integrator), maker-checker approval for privileged configuration changes in production, and strict per-tenant data isolation.

Monitoring & audit logging

In place

Append-only, tamper-evident audit logs for identity, consent and admin actions; request-context tracing and metrics instrumentation; machine-readable step-up / denial codes. Continuous 24×7 SIEM monitoring is on the roadmap as we scale.

Application security

In place

Allow-listed request validation (unknown fields rejected), SSRF-guarded and mTLS-capable outbound calls, HMAC-verified webhooks that fail closed, and signed-cookie gates on sensitive surfaces. Independent VAPT is scheduled as part of the certification readiness programme.

Network & transport

In place

TLS 1.2+ everywhere and mutual TLS on connector pulls. A reverse proxy fronts the API with per-route rate limits and gates the raw API-docs surface; egress is controlled. IP-allowlisting on privileged surfaces is being rolled out.

Infrastructure & resilience

In place

India-hosted, containerised services with autoscaling profiles for batch and real-time flows over dual, high-throughput links. A documented, drill-tested business-continuity / disaster-recovery runbook is on the roadmap.

Data privacy & breach notification

In place

DPDP-aligned by design — DPO fields, a signed Data Processing Agreement, purpose limitation and consent artefacts on every flow, plus data minimisation and India residency. We commit to timely breach notification to affected customers and regulators as the DPDP Act requires.

Subprocessors

On request

We maintain a current register of subprocessors (identity / verification, messaging, object storage and AI-support providers) and share it with customers under NDA on request.

Audit rights & evidence

In place

Every consent-gated share produces an exportable, append-only audit record — who shared what, with whom, under which consent, and when. Customers may request control evidence under agreement; independent SOC 2 / ISO 27001 reports are in progress.

Endpoint & corporate security

On the roadmap

Formal device hardening, endpoint detection & response (EDR) and security-awareness training are being established as the team scales, tracked alongside the ISO 27001 programme.

Independent verification

AssureLocker-issued credentials can be checked against public issuer keys, status endpoints and registry anchors without trusting a screenshot or a private email. Open the public verification register →

Responsible disclosure

Found a vulnerability? Email [email protected] with steps to reproduce. Please give us reasonable time to remediate before public disclosure; we will acknowledge within 3 business days. We do not pursue good-faith researchers who follow this policy.

AssureLocker
Right Vectors India
3rd floor, Innov8, SKCL Tech Square,
SIDCO Industrial Estate, Guindy,
Chennai, TN 600032

AssureLocker is a verification & orchestration platform — not a lender. It supplies verified evidence and risk signals checked against authoritative sources (GSTN, MCA21, EPFO, CERSAI, Account Aggregator) and orchestrates the assessment room. It does not lend, hold or move funds, operate escrow, set advance rates, or make the credit decision — the lender's system of record makes that decision and disburses. Right Vectors India, the provider of AssureLocker, operates strictly as a Technology Service Provider. Every signal is labelled by evidence tier — registry-verified, lender-side, issuer-confirmed, document-signed or self-declared (missing where unresolved); some integrations are in sandbox, lender-side or pilot, and records are written to an immutable registry (hashes only — never raw PII). Signals and figures are point-in-time and consent-bound; confidential to the named parties.

Explainable, evidence-tiered signals — auditable on request. Our algorithmic-accountability approach →

© 2026 Right Vectors India. All rights reserved. · Site version: al-20260721-155225-34ff216c8

Aligned with India Stack. Made in India.