Security & Trust

Trust infrastructure has to earn its own trust first. Here's how consent, access, and explainability are built into OpenCredit from the ground up.

How We Handle Trust

Four principles that shape every part of the platform.

Consent Before Anything

UPI, GST, and Account Aggregator data is gated behind explicit, purpose-bound consent and never pulled before that consent exists.

  • Explicit, purpose-bound consent
  • No data access before consent
  • Consent scope tied to a specific use

Scoped Document Access

Every document a lender reviews is granted as scoped, time-bound, revocable, view-only in-app access — never downloaded, never "sent."

  • Time-bound access grants
  • Revocable at any time
  • View-only, never downloadable
  • Full audit trail behind every grant

Explainability as a Safeguard

Confidence scores are never a black box. Lenders see the factors behind every score, and borrowers see exactly which criteria were and weren't met.

  • Component-level score breakdown
  • No opaque machine-only decisions
  • Transparent, auditable criteria

Regulatory Alignment

OpenCredit is built with the RBI's Digital Lending Directions and India's DPDP Act in mind from day one.

  • Designed around Digital Lending Directions
  • Privacy-by-design under the DPDP Act
  • We are not a lender — a technology and matching layer

Where We Are Today

OpenCredit is an early-stage platform. We won't claim certifications (PCI DSS, ISO 27001, SOC 2, or similar) until they've actually been completed and independently verified. What you see above reflects how the platform is architected today — not a compliance badge.

Staying Safe on OpenCredit

Review Every Consent Request

Only approve data-sharing consent for the specific purpose stated — you can revoke it at any time.

Check Document Access Grants

Confirm any document access you grant a lender is time-bound and scoped to what they actually need to see.

Verify the Lender

OpenCredit only routes you to cooperative banks, NBFCs, and merchant/scheduled banks — always confirm who you're dealing with.

Beware of Phishing

We will never ask for your password, OTP, or Account Aggregator credentials over email or phone.

Report a Security Issue

Found a vulnerability? Let us know directly.

We take responsible disclosure seriously. If you've found a security issue, email the founder directly and we'll respond as quickly as we can.