Security & Compliance

Your data is protected
at every step.

How Revvot handles your financial data, how the Account Aggregator framework works, and how we meet our regulatory obligations — explained transparently.

Account Aggregator Framework

Data shared through
a regulated pipeline.

The Account Aggregator (AA) framework is an RBI-regulated data-sharing architecture built by Sahamati. It enables consented, purpose-limited, auditable transfer of your financial data between regulated entities.

When you authorise AA consent on the Revvot platform, you are using the same regulated infrastructure as India's largest banks and NBFCs. Revvot acts as a Financial Information User (FIU) — one of the two regulated roles in the AA framework.

Your data is never transmitted in raw form to Revvot's servers. It flows through the AA network, encrypted end-to-end, and is accessible only for the specific purpose you consent to.

How AA data flows
Your Bank
Sahamati
AA Network
Revvot
End-to-end encrypted · Consent-gated · Audited · Revocable at any time
Your consent rights
Consent is one-time and purpose-limited to credit assessment
Revocable instantly via your banking app
Consent log is auditable and transparent
No secondary use of data without fresh consent
Regulatory Framework

Our compliance
obligations.

🏛️
Reserve Bank of India
RBI-regulated lending partners
All loan disbursements are executed by our bank and NBFC lending partners, each holding valid RBI registration. Revvot operates as a technology service provider and origination platform under applicable guidelines.
🔗
Sahamati / AA Network
FIU registration & AA compliance
Revvot is registered as a Financial Information User (FIU) with the Account Aggregator ecosystem. All AA data access is governed by the Master Directions for Account Aggregators issued by RBI.
🪪
KYC Compliance
Aadhaar & PAN eKYC
Identity verification is carried out via Aadhaar-based eKYC in compliance with UIDAI guidelines. PAN verification is performed via the Income Tax Department's API. No physical KYC documents are collected.
Data Security

How we protect
your information.

🔐
TLS 1.3 Encryption in Transit
All data transmitted between your device, the AA network, and Revvot's servers is encrypted using TLS 1.3 — the current industry standard.
💾
AES-256 Encryption at Rest
Personal and financial data stored in Revvot's systems is encrypted at rest using AES-256, with access controlled by role-based permissions and audit logs.
🧱
Role-Based Access Controls
Access to customer data within Revvot is restricted on a need-to-know basis. All access is logged, reviewed, and auditable.
🛡️
Minimal Data Retention
Raw AA financial data is not stored beyond the period required for credit assessment. Post-assessment, only the derived credit decision is retained, not the underlying bank statements.
🔍
Regular Security Audits
Revvot conducts periodic security assessments of its infrastructure and third-party integrations. Vulnerability disclosures can be reported to security@revvot.in.
📋
Vendor Due Diligence
All technology vendors and service providers with access to customer data are bound by data processing agreements. We conduct due diligence before onboarding any third-party integration.
For Lending Partners

What lenders and NBFCs
should know.

Data Revvot passes to lenders
AA-verified income and cash flow summary
CIBIL / Experian bureau report (consent-based)
Vehicle inspection and valuation report
eKYC-verified identity (Aadhaar + PAN)
Digitally executed loan agreement
Compliance documentation available
FIU registration with Sahamati AA ecosystem
Data processing agreement (DPA) template
Information security policy
Privacy policy and consent framework
Grievance redressal mechanism
Need compliance documentation?
Our partnerships team can share the full compliance pack for due diligence. Email lending@revvot.in or use the contact form.
Request Compliance Pack →
Incident Reporting & Disclosure

Our commitment to
transparency.

🚨
Security Incident Response
In the event of a data incident, Revvot will notify affected users and the relevant regulatory authorities within the timeframes required by applicable Indian law. We maintain an incident response plan reviewed annually.
🔎
Responsible Disclosure
Security researchers who identify vulnerabilities in the Revvot platform are encouraged to report them to security@revvot.in. We commit to acknowledge reports within 72 hours and to remediate valid findings in good faith.
📊
Data Protection Officer
Privacy and data protection concerns can be directed to our Data Protection Officer at privacy@revvot.in. We aim to respond to all data-related enquiries within 30 days.

Questions about security or compliance?

Our team is happy to discuss data handling, regulatory obligations, or partnership compliance requirements.

Contact Us →