Fintech APIs & Platform for KYC, Verification & Transactions in India | Eko Platform ServicesSecurity & Data Protection | Eko Platform Services API
Eko Platform Services Logo

Security & data protection

How we keep your data and your customers' money safe — from where data lives to how every transaction is authenticated.

Infrastructure & data residency

Where your data lives and what we never keep.

  • The entire application and database run on Microsoft Azure, with a primary data centre in Central India (Pune) and a disaster-recovery site in South India (Chennai). These are two geographically separate regions, so services continue if one region fails.
  • All data is stored and processed within India, in line with RBI's data-localisation requirements.
  • Aadhaar numbers are never stored. Biometric data (fingerprints / PID blocks) is passed directly through for authentication and never retained.
  • We retain no data that UIDAI, RBI or other applicable regulations prohibit us from storing.

Independent audit & compliance

External checks on our controls, every year.

  • RBI-empanelled auditors independently audit our information-security controls every year against ISO/IEC 27001.
  • The platform complies with RBI regulations for payment services and Business Correspondent operations, as well as KYC and AML/CFT norms.

API & access security

How calls to the platform are authenticated and protected.

  • Every API request is signed with HMAC-SHA256 using a private key issued to your account. This authenticates the caller and detects any tampering with the request. See How Authentication Works.
  • Credentials are designed to stay server-side. Our official SDKs (Node.js, Python, PHP, Go, Java) are backend-only and handle signing automatically, so keys are never exposed in client apps.
  • Separate sandbox and production environments let you build and test without touching live data or money.
  • All traffic is encrypted in transit over TLS 1.2+.
  • IP whitelisting is available as an optional extra layer of security for production access.

Transaction security

Customer authentication and safeguards on every money movement.

  • Money transfers (DMT): Senders complete a one-time biometric Aadhaar eKYC. Every transfer after that requires a fresh OTP sent to the sender's registered mobile. Transfers are capped at ₹5,000 per transaction, and sender-level monthly limits apply.
  • AePS: Agents complete a one-time eKYC plus a biometric authentication each day before transacting. Customer withdrawals are authorised by fingerprint through UIDAI-certified RD-service devices, and withdrawals above ₹5,000 also need an SMS OTP.
  • Bill payments (BBPS): Bill amounts are fetched live from the biller. Whenever a biller supports bill-fetch, the amount paid can never exceed the fetched bill amount.
  • Each transaction carries a unique client_ref_id (10–20 characters; 10 recommended). The Transaction Inquiry API lets you confirm the status of any pending or timed-out transaction before retrying.
  • Regulatory limits are enforced on the platform.

Audit trail & reconciliation

Records you can use for your own audits and reporting.

  • Full transaction logs, reconciliation data and settlement reports are maintained for audit and reporting.
  • Reconciliation and settlement reports are shared over email on request.

More questions? See the FAQ