Security & Trust
Trust infrastructure has to earn its own trust first. Here's how consent, access, and explainability are built into OpenCredit from the ground up.
How We Handle Trust
Four principles that shape every part of the platform.
Consent Before Anything
UPI, GST, and Account Aggregator data is gated behind explicit, purpose-bound consent and never pulled before that consent exists.
- Explicit, purpose-bound consent
- No data access before consent
- Consent scope tied to a specific use
Scoped Document Access
Every document a lender reviews is granted as scoped, time-bound, revocable, view-only in-app access — never downloaded, never "sent."
- Time-bound access grants
- Revocable at any time
- View-only, never downloadable
- Full audit trail behind every grant
Explainability as a Safeguard
Confidence scores are never a black box. Lenders see the factors behind every score, and borrowers see exactly which criteria were and weren't met.
- Component-level score breakdown
- No opaque machine-only decisions
- Transparent, auditable criteria
Regulatory Alignment
OpenCredit is built with the RBI's Digital Lending Directions and India's DPDP Act in mind from day one.
- Designed around Digital Lending Directions
- Privacy-by-design under the DPDP Act
- We are not a lender — a technology and matching layer
Where We Are Today
OpenCredit is an early-stage platform. We won't claim certifications (PCI DSS, ISO 27001, SOC 2, or similar) until they've actually been completed and independently verified. What you see above reflects how the platform is architected today — not a compliance badge.
Staying Safe on OpenCredit
Review Every Consent Request
Only approve data-sharing consent for the specific purpose stated — you can revoke it at any time.
Check Document Access Grants
Confirm any document access you grant a lender is time-bound and scoped to what they actually need to see.
Verify the Lender
OpenCredit only routes you to cooperative banks, NBFCs, and merchant/scheduled banks — always confirm who you're dealing with.
Beware of Phishing
We will never ask for your password, OTP, or Account Aggregator credentials over email or phone.