₹250 crore
Useful across institutions. Pooled across none.
Cross-member evidence can improve a decision without creating a central warehouse of customer identity records.
Four constraints come before the model.
We treat regulatory boundaries as architecture inputs. They are not a policy page added after a data pipeline is complete.
Aadhaar Act, section 29
We design the matching layer without storing core biometric information or Aadhaar numbers. Institution-side tokens are the comparison keys.
CICRA data boundaries
Credit information is used inside the purpose and membership controls that apply to the institution. It is not moved into a shared identity pool.
V-CIP storage in India
Video customer identification recordings and derived session evidence remain on systems located in India.
DPDP Rules 2025
The architecture assumes itemised purpose, deletion rights and the 18-month commencement tranche that takes effect on 13 May 2027.
Systems in India
Required location for V-CIP data and recordings
RBI KYC Master Direction, 2026The identifier changes before the boundary.
The system separates direct identifiers, institution-local evidence, consortium matches and model updates.
Tokenise inside the institution
Member edge
Direct identifiers are normalised and keyed before a request crosses the member boundary. Praman Labs receives a stable token, not the source identifier.
Evaluate local signals
Local compute
Signals that can be scored inside the institution stay there. The hosted response carries verdict evidence rather than a copy of the member's source record.
Match overlap privately
Consortium match
Private set intersection reveals that two permitted token sets overlap without either party disclosing every item in its set.
Aggregate model updates
Training round
Federated training moves bounded model updates. Customer records and raw feature rows do not enter a central training table.
Private set intersection, in plain language
Member A and Member B each hold a private list of tokenised identifiers. The protocol returns the overlap they are permitted to learn. Neither receives the other member's full list.
- Member APrivate token set
- ProtocolPermitted comparison
- Member BPrivate token set
- ResultOverlap only
Members exchange verdicts, not customer files.
A permitted response can state that a token is linked to a confirmed ring and provide the ring reference. It does not expose another institution's customer record.
Raw onboarding records remain under the member's access and retention controls.
Training rounds aggregate bounded updates and reject malformed or outlying submissions.
Reason codes preserve the evidence category without naming another member or customer.
Membership exit stops new matching and triggers deletion under the signed retention schedule.
Retention follows purpose and contract.
Each deployment records which signal class is retained, for how long and by whom. A member exit revokes access, removes hosted tokens under the agreed schedule and preserves only records a law or active dispute requires.
Review the boundary before sharing a row.
The backtest starts with a data map, lawful-purpose review and a mutual NDA. Tokenisation happens inside your environment.
Discuss the data map