Useful across institutions. Pooled across none.

Cross-member evidence can improve a decision without creating a central warehouse of customer identity records.

Four constraints come before the model.

We treat regulatory boundaries as architecture inputs. They are not a policy page added after a data pipeline is complete.

  • Aadhaar Act, section 29

    We design the matching layer without storing core biometric information or Aadhaar numbers. Institution-side tokens are the comparison keys.

  • CICRA data boundaries

    Credit information is used inside the purpose and membership controls that apply to the institution. It is not moved into a shared identity pool.

  • V-CIP storage in India

    Video customer identification recordings and derived session evidence remain on systems located in India.

  • DPDP Rules 2025

    The architecture assumes itemised purpose, deletion rights and the 18-month commencement tranche that takes effect on 13 May 2027.

The identifier changes before the boundary.

The system separates direct identifiers, institution-local evidence, consortium matches and model updates.

  1. Tokenise inside the institution

    Member edge

    Direct identifiers are normalised and keyed before a request crosses the member boundary. Praman Labs receives a stable token, not the source identifier.

  2. Evaluate local signals

    Local compute

    Signals that can be scored inside the institution stay there. The hosted response carries verdict evidence rather than a copy of the member's source record.

  3. Match overlap privately

    Consortium match

    Private set intersection reveals that two permitted token sets overlap without either party disclosing every item in its set.

  4. Aggregate model updates

    Training round

    Federated training moves bounded model updates. Customer records and raw feature rows do not enter a central training table.

Private set intersection, in plain language

Member A and Member B each hold a private list of tokenised identifiers. The protocol returns the overlap they are permitted to learn. Neither receives the other member's full list.

  1. Member APrivate token set
  2. ProtocolPermitted comparison
  3. Member BPrivate token set
  4. ResultOverlap only

Members exchange verdicts, not customer files.

A permitted response can state that a token is linked to a confirmed ring and provide the ring reference. It does not expose another institution's customer record.

Raw onboarding records remain under the member's access and retention controls.

Training rounds aggregate bounded updates and reject malformed or outlying submissions.

Reason codes preserve the evidence category without naming another member or customer.

Membership exit stops new matching and triggers deletion under the signed retention schedule.

Retention follows purpose and contract.

Each deployment records which signal class is retained, for how long and by whom. A member exit revokes access, removes hosted tokens under the agreed schedule and preserves only records a law or active dispute requires.

Review the boundary before sharing a row.

The backtest starts with a data map, lawful-purpose review and a mutual NDA. Tokenisation happens inside your environment.

Discuss the data map