Security posture
Security you can verify, not just trust.
AssureLocker handles consent-backed identity and risk-signal workflows for regulated lenders. Here is exactly how we secure it, what we hold, and where each data source stands.
Certifications
Independent certification is in progress — SOC 2 Type I and ISO/IEC 27001:2022, with independent VAPT and certification readiness underway (dry-runs complete; independent VAPT scheduled within 90 days of first pilot commencement). We state status honestly: nothing here is described as “certified” until the report is in hand. Production deployment profiles support private connectivity, controlled egress and autoscaling for batch and real-time flows, subject to lender environment and deployment model.
Encryption & post-quantum
TLS in transit and encryption at rest. Long-lived issuer-signed artefacts (SD-JWTs, receipts, OID4VP requests) are signed with ML-DSA-65 (NIST FIPS 204); key encapsulation uses ML-KEM-768 — so records stay verifiable beyond the classical-crypto horizon.
Data minimisation
We compute and persist aggregates, not raw sensitive payloads. Account-Aggregator bank data is reduced to derived metrics immediately and the raw FI payload is discarded — designed to support lender/FIU obligations under the AA framework and our minimum-retention principle.
Tamper-evident registry
Membership, credential and consent events are SHA-256 hashed and recorded in an immutable registry — an immutable, independently verifiable provenance trail. Only the hash is written to the registry; raw PII never leaves our store.
Consent & audit
Every share is consent-gated and produces an append-only audit record you can export — who shared what, with whom, under which consent, and when.
India data residency
Production keeps customer data hosted and processed within India, on infrastructure in an Indian data centre — supporting RBI data-localisation expectations and the DPDP Act, so regulated lenders keep customer data onshore.
DPDP posture
Built for India's DPDP Act: per-entity Data Protection Officer fields, a scroll-to-accept Data Processing Agreement, purpose-limited collection, and consent artefacts on every data flow.
Sandbox vs production
Sandbox requests are tagged end-to-end (env claim on the token), webhooks to your endpoint are suppressed in sandbox, and no billable external calls are made. You validate fully before you go live.
Security controls — in detail
Stated as it actually is today. In place means implemented; in progress and on the roadmap are honest about what we’re still building — no control is claimed before it’s real.
Access control
In placeRole-based access across every portal, DID-based entity membership with least-privilege roles (OrgAdmin / SysAdmin / Manager / Technician / Operator / Integrator), maker-checker approval for privileged configuration changes in production, and strict per-tenant data isolation.
Monitoring & audit logging
In placeAppend-only, tamper-evident audit logs for identity, consent and admin actions; request-context tracing and metrics instrumentation; machine-readable step-up / denial codes. Continuous 24×7 SIEM monitoring is on the roadmap as we scale.
Application security
In placeAllow-listed request validation (unknown fields rejected), SSRF-guarded and mTLS-capable outbound calls, HMAC-verified webhooks that fail closed, and signed-cookie gates on sensitive surfaces. Independent VAPT is scheduled as part of the certification readiness programme.
Network & transport
In placeTLS 1.2+ everywhere and mutual TLS on connector pulls. A reverse proxy fronts the API with per-route rate limits and gates the raw API-docs surface; egress is controlled. IP-allowlisting on privileged surfaces is being rolled out.
Infrastructure & resilience
In placeIndia-hosted, containerised services with autoscaling profiles for batch and real-time flows over dual, high-throughput links. A documented, drill-tested business-continuity / disaster-recovery runbook is on the roadmap.
Data privacy & breach notification
In placeDPDP-aligned by design — DPO fields, a signed Data Processing Agreement, purpose limitation and consent artefacts on every flow, plus data minimisation and India residency. We commit to timely breach notification to affected customers and regulators as the DPDP Act requires.
Subprocessors
On requestWe maintain a current register of subprocessors (identity / verification, messaging, object storage and AI-support providers) and share it with customers under NDA on request.
Audit rights & evidence
In placeEvery consent-gated share produces an exportable, append-only audit record — who shared what, with whom, under which consent, and when. Customers may request control evidence under agreement; independent SOC 2 / ISO 27001 reports are in progress.
Endpoint & corporate security
On the roadmapFormal device hardening, endpoint detection & response (EDR) and security-awareness training are being established as the team scales, tracked alongside the ISO 27001 programme.
Independent verification
AssureLocker-issued credentials can be checked against public issuer keys, status endpoints and registry anchors without trusting a screenshot or a private email. Open the public verification register →
Responsible disclosure
Found a vulnerability? Email [email protected] with steps to reproduce. Please give us reasonable time to remediate before public disclosure; we will acknowledge within 3 business days. We do not pursue good-faith researchers who follow this policy.