TatvaPay

Trust and security

Built for partners who will audit us

TatvaPay will work as a technology service provider to RBI-regulated partners, who audit their vendors. Every item below carries its status; none is live yet.
  • We never hold funds

    Money moves only inside licensed partners' escrow and settlement accounts. TatvaPay sends instructions.

    Next
  • Payment data stays in India

    The engine, database, ledger and logs are hosted in India, in line with RBI's 2018 storage directive.

    Next
  • No card numbers stored

    Cards are handled by partners as tokens; we keep references only.

    Next
  • Hash-chained audit trail

    Mandate, quote, approval, rail reference and settlement are linked in a tamper-evident chain, exportable per payment.

    Next
  • Humans approve money

    No AI employee or agent can move money outside a mandate a person authorised; above a threshold a person is always asked.

    Next
  • No training on customer data

    Customer and payment data is never used to train models, and card or account numbers are redacted before any model call.

    Next
  • CERT-In incident reporting and 180-day logs

    Six-hour incident clock and logs kept in India.

    Planned
  • DPDP notices, consent receipts and grievance officer

    Under the Digital Personal Data Protection Act and Rules.

    Planned
  • ISO 27001 and SOC 2

    Gap audit first, then certification, for partner due diligence.

    Planned

Nothing here is legal advice; every regulatory line is being confirmed with payments counsel.