Skip to content
TatvaPay

Trust and security

Built for the people who will audit us

TatvaPay will work as a technology service provider to RBI-regulated payment aggregators and a forex partner, who audit their vendors. Here is what is built, what is not, and who holds which licence.

Nothing is live yet. Next means it works in our sandbox or is being built now; Planned means a later wave.

Licences

Who holds which licence

  • TatvaPay

    A technology service provider to regulated entities. Holds no RBI licence, never holds customers' funds, never stores card numbers.

    Company being incorporated

  • Licensed payment aggregators

    Collect and settle rupee payments (UPI, cards, netbanking, AutoPay) under their own RBI authorisation. First planned integration: Razorpay.

    Agreement not signed yet

  • An AD Category-II partner

    Carries out every forex leg: currency for travel, forex cards and LRS remittances, under its own licence for foreign exchange.

    Agreement not signed yet

We do not call any company our partner until an agreement is signed, and we will publish names when it is.

Money

Receipts, approvals and rules

  • We never hold funds

    Money moves only inside licensed payment aggregators' and the forex partner's accounts. TatvaPay sends instructions.

    Next
  • No AI moves money

    No AI employee or agent can move money, approve a merchant, book a forex deal or file with a regulator. Merchant agents' payment retries always wait for a named person, at any amount.

    Next
  • A person approves above ₹2,000

    Whatever a mandate allows, a bigger payment waits for its owner. The threshold is a default the agent cannot change.

    Next
  • Mandates with written consent

    An agent pays only inside a mandate its owner authorised, with versioned consent wording recorded at the moment of authorisation. Revoke it in one tap.

    Next
  • Rules decide, AI explains

    Risk decisions come from versioned deterministic rules; every decision records the rule version.

    Next
  • Receipts that verify

    Mandate, quote, approval, bank reference and settlement are linked in a hash-chained receipt, signed with Ed25519 keys published for anyone to check.

    Next

Data

Payment data, India and privacy

  • No card numbers, ever

    We never take or store card numbers, CVVs, PINs or OTPs. Agent protocols that offer a card are refused.

    Next
  • No PAN or Aadhaar at rest

    A PAN is kept only as a salted one-way hash plus a masked form. Aadhaar is never collected.

    Next
  • Identity numbers hidden from AI models

    Card, Aadhaar, PAN and account numbers are replaced before a customer's words reach a model. No customer data trains models.

    Next
  • Consent centre and your own data

    See and revoke every agent and mandate; download a copy of the personal data we hold about you.

    Next
  • CERT-In incident clock

    Every incident starts a six-hour clock. An AI assistant prepares the report; a named person decides and files.

    Next
  • Payment data hosted only in India

    The engine, database, documents, backups and logs on an India-region server. Not yet created.

    Planned
  • 180-day logs in India

    Application logs kept for at least 180 days within India, as CERT-In's 2022 directions ask.

    Planned
  • Backups and tested recovery

    Encrypted backups in India and quarterly restore tests.

    Planned
  • Multi-factor sign-in

    A second factor for staff, partner officers and workspace admins.

    Planned
  • Grievance officer and DPDP notices

    A named grievance officer and final notices under the Digital Personal Data Protection Act and Rules.

    Planned
  • Independent assurance

    Penetration test by a CERT-In empanelled auditor, ISO 27001 gap audit, SOC 2 Type I then Type II, PCI DSS scope-out.

    Planned
  • Real sanctions and PEP screening

    Today the sandbox uses a placeholder screener; the payment aggregator's officers screen and decide.

    Planned

Compliance pack

Where our controls stand

Our controls register lists every security and compliance control with an honest status, checked by a test in our code. As of 1 October 2026, before launch:
  • In code (enforced and tested in the sandbox)56
  • Documented (policy written, not yet operating)14
  • To do31

“In code” means the code enforces it in the sandbox, not that it operates in production: no production environment exists yet. Nobody outside the team has tested these controls.

For payment and forex providers

The pack (security policies, the controls register, data map, vendor list, incident runbook and answers to a standard vendor questionnaire) is available on request. Write to hello@tatvapay.com.

Report a vulnerability

Write to hello@tatvapay.com with the subject “Security”. Please do not access data that is not yours or degrade the service. The same contact is at /.well-known/security.txt.

Nothing here is legal advice; every regulatory line is being confirmed with payments counsel.