Real questions Indian fintech & financial services business owners ask us during scoping calls. Detailed answers, no fluff.
What does RBI's Digital Lending Guidelines 2022 mean for fintech apps?+
The 2022 guidelines (and subsequent updates) tightened the rules sharply: only Regulated Entities (banks/NBFCs) can disburse and collect funds, the Lending Service Provider (LSP) i.e. the app cannot hold customer money in its own pool account, all fees must be transparently disclosed in a standard Key Fact Statement (KFS), and there must be a clear cooling-off period and grievance redressal flow. We design fintech apps with these rules built in: clean money-flow diagrams, automated KFS generation, audit-ready consent capture, and integration with the RE's accounts. We also help fintechs document their RBI-compliant operating model so they can confidently onboard partner NBFCs and banks.
How do you handle KYC for fintech apps in India?+
We support the full RBI-approved KYC stack: Aadhaar OKYC (instant, OTP-based, low friction for retail), DigiLocker for document fetch with consent, V-CIP (Video CIP) for cases requiring assisted KYC, and PAN, Aadhaar XML, and Voter ID verification through licensed KUAs. The flow is risk-based — low-ticket transactions use OKYC, higher-ticket use V-CIP with AI-based liveness and face-match. We also integrate offline KYC via DigiLocker downloads for users in low-connectivity areas. The full KYC pipeline typically completes in under 3 minutes for a low-friction flow and 8-10 minutes for full V-CIP with manual review.
Can you integrate with Account Aggregator (AA) framework?+
Yes. We integrate with the Sahamati AA ecosystem to pull consented financial data (bank statements, GST returns, MF holdings) for use cases like credit underwriting, wealth management, and SME loans. The AA flow is fully consent-driven: the user sees exactly which FIU (Financial Information User) is requesting which data, the duration, and the purpose. For lenders, AA-based bank statement analysis dramatically reduces fraud (no PDF tampering possible) and speeds up decisioning. We've integrated with most major AAs including Onemoney, Finvu, CAMSFinServ, and NESL. AA-enabled underwriting can compress credit decisioning to under 5 minutes for clean customer profiles.
How do you ensure data security and DPDP Act compliance for fintech?+
Fintech is the most-attacked vertical in India by a wide margin, so our baseline is well above generic best practice. We use AES-256 encryption at rest, TLS 1.3 in transit, AWS KMS with key rotation, AWS CloudHSM for high-sensitivity keys, and field-level encryption for PII and financial data. All data sits in AWS Mumbai region for RBI data-localisation compliance. Access uses MFA, role-based controls, and audit logs that go to a tamper-resistant store. Annual VAPT (Vulnerability Assessment & Penetration Testing) is built into the SDLC, and we maintain a documented incident-response runbook aligned with both DPDP Act and CERT-In's 6-hour breach reporting requirement.
Can you build payment and reconciliation systems for SMB and enterprise?+
Yes — payments and reconciliation is one of our deepest specialisations. We integrate with the major PA-PGs (Razorpay, Cashfree, PhonePe, Paytm), and directly with bank APIs (HDFC, ICICI, Axis) for high-volume corporate flows. Reconciliation is the harder problem: matching incoming UPI/NEFT/IMPS receipts against expected invoices, handling part-payments, identifying mis-mapped transactions, and auto-generating ledger entries. Our recon engines typically achieve 95-98% straight-through processing, with the remaining cases routed to a reviewer queue. For enterprises, we add bank-statement OCR and AI-based matching to handle legacy bank flows that don't have clean APIs.
How long does it take to build an MVP fintech product in India?+
A focused MVP (e.g. consumer onboarding + KYC + a single product flow like personal loan or invoice discounting) typically takes 4-6 months. Add another 2-3 months for collections, accounting, and compliance reporting modules. The longest pole is usually integrations: bureau, banks, AA, KYC providers, and PA-PGs each take 4-12 weeks of integration and UAT. We typically run discovery + compliance design in the first 4 weeks, kick off engineering in parallel, and target a closed-pilot launch by month 4-5. Going from closed pilot to public launch usually requires another 8-12 weeks for security audit, RBI documentation, and load testing.