Security & data protection
How we keep your data and your customers' money safe — from where data lives to how every transaction is authenticated.
Infrastructure & data residency
Where your data lives and what we never keep.
- The entire application and database run on Microsoft Azure, with a primary data centre in Central India (Pune) and a disaster-recovery site in South India (Chennai). These are two geographically separate regions, so services continue if one region fails.
- All data is stored and processed within India, in line with RBI's data-localisation requirements.
- Aadhaar numbers are never stored. Biometric data (fingerprints / PID blocks) is passed directly through for authentication and never retained.
- We retain no data that UIDAI, RBI or other applicable regulations prohibit us from storing.
Independent audit & compliance
External checks on our controls, every year.
- RBI-empanelled auditors independently audit our information-security controls every year against ISO/IEC 27001.
- The platform complies with RBI regulations for payment services and Business Correspondent operations, as well as KYC and AML/CFT norms.
API & access security
How calls to the platform are authenticated and protected.
- Every API request is signed with HMAC-SHA256 using a private key issued to your account. This authenticates the caller and detects any tampering with the request. See How Authentication Works.
- Credentials are designed to stay server-side. Our official SDKs (Node.js, Python, PHP, Go, Java) are backend-only and handle signing automatically, so keys are never exposed in client apps.
- Separate sandbox and production environments let you build and test without touching live data or money.
- All traffic is encrypted in transit over TLS 1.2+.
- IP whitelisting is available as an optional extra layer of security for production access.
Transaction security
Customer authentication and safeguards on every money movement.
- Money transfers (DMT): Senders complete a one-time biometric Aadhaar eKYC. Every transfer after that requires a fresh OTP sent to the sender's registered mobile. Transfers are capped at ₹5,000 per transaction, and sender-level monthly limits apply.
- AePS: Agents complete a one-time eKYC plus a biometric authentication each day before transacting. Customer withdrawals are authorised by fingerprint through UIDAI-certified RD-service devices, and withdrawals above ₹5,000 also need an SMS OTP.
- Bill payments (BBPS): Bill amounts are fetched live from the biller. Whenever a biller supports bill-fetch, the amount paid can never exceed the fetched bill amount.
- Each transaction carries a unique
client_ref_id(10–20 characters; 10 recommended). The Transaction Inquiry API lets you confirm the status of any pending or timed-out transaction before retrying. - Regulatory limits are enforced on the platform.
Audit trail & reconciliation
Records you can use for your own audits and reporting.
- Full transaction logs, reconciliation data and settlement reports are maintained for audit and reporting.
- Reconciliation and settlement reports are shared over email on request.
More questions? See the FAQ