AI agents Architecture Pricing Compliance Compare Book a demo
Compliance

Compliance is a feature,
not a constraint.

We built SquareNow to operate inside Indian regulation, comfortably. RBI DLG, SRO under FACE, scale-based regulation, NBFC-MFI rules, Section 8 — pre-built into the product, not bolted on.

The eight pillars

Eight regulatory frames.
One platform.

01

RBI DLG

Disclosures, consent capture and audit trail compliant with the Sept 2022 Digital Lending Guidelines and subsequent updates.

02

SRO under FACE

Pre-built disclosures and reporting for Self-Regulatory Organisation obligations.

03

Scale-based regulation

Pre-built reports for Base, Middle, Upper and Top Layer NBFCs.

04

NBFC-MFI

Qualifying-asset ratio reporting, household indebtedness checks, JLG / group lending workflows.

05

Section 8 lenders

Companies Act overlay built in. Compliance with the not-for-profit lending framework.

06

Data localisation

Customer data hosted in AWS Mumbai (ap-south-1). Tenant-isolated, encrypted at rest.

07

SOC 2 Type 2

In process for 2026. Detailed security pack shared on request under NDA.

08

ISO 27001

In process for 2026. Quarterly third-party pen-testing reports available on request.

RBI DLG checklist

The Digital Lending Guidelines,
line by line.

Every DLG obligation, mapped to where it sits in the SquareNow workflow. None of these are configurable away — they ship enabled.

01

Lending service provider transparency

Every borrower-facing screen surfaces the lender of record (not the platform), regulated identifier and grievance contact — both at application and post-disbursement.

02

Key Fact Statement (KFS)

Standardised KFS auto-generated per loan offer. Includes APR, processing fees, prepayment terms, default rate. Bilingual rendering (English + local language).

03

Consent capture, granular

Per-data-category, per-purpose, time-stamped, geo-tagged, IP-logged. Withdrawable from the borrower portal at any time with full data-deletion workflow.

04

Disbursement only to verified accounts

No third-party disbursement. Pre-flight checks against bureau name, PAN-linked account and penny-drop verification. Audit log of every disbursement and the verifications that preceded it.

05

Cooling-off period

Borrower can return the disbursed amount within the cooling-off window with only proportionate APR cost — wired into the workflow as a non-defaulting return path.

06

No automatic credit-limit increase

Limit increases require explicit borrower consent. No silent upsell, no auto-enrolment.

07

Grievance escalation

Three-level grievance routing — partner, lender, RBI Sachet — surfaced on every borrower-facing surface. SLA on first response and resolution.

08

No deceptive nudges

No dark-pattern UI for product upsell or fee collection. Periodic UI audit attests to this.

SRO under FACE

Self-regulation,
operationalised.

FACE membership is straightforward; ongoing reporting is where most NBFCs run into operational drag. SquareNow handles the recurring submissions.

01

Member onboarding pack

KYC of the legal entity, beneficial-ownership disclosure, code-of-conduct attestation. Pre-formatted submission to FACE.

02

Operational data submission

Monthly operational disclosures on disbursement, repayment, NPA, customer-grievance counts. Generated from production data; reviewer signs off.

03

Code-of-conduct attestations

Quarterly code-of-conduct, anti-coercive-collection and fair-practice attestations — pre-templated and routed through the right authority on your side.

04

Complaint resolution metrics

Time-to-first-response, time-to-resolution and complaint-by-product reporting. Outliers surfaced before they cross SRO thresholds.

05

Reporting calendar

A pre-loaded calendar of every recurring SRO submission. The compliance officer sees what is due next without checking the FACE portal.

Audit trail mechanics

How "tamper-evident" is enforced.

01

Every state change is an event

Application created, document uploaded, KYC passed, underwriting decisioned, disbursement triggered, repayment received, collection action taken — each is an immutable event with actor, timestamp and reasoning.

02

Hash-chained, tamper-evident

Each event includes a cryptographic hash of the previous event. Any retroactive modification breaks the chain — detectable on the next audit.

03

Inspection mode for regulators

A read-only inspection role exposes the full event log, document repository and report archive to an external auditor without writing access to operational systems.

04

Document version history

Borrower documents, signed agreements, KYC artefacts — all versioned. The latest is current; previous versions are retrievable for the retention period.

05

Retention by document class

Configurable retention per document class — KYC, agreements, statements, communications — aligned with statutory minimums and data-minimisation defaults.

Business continuity

What we can hold ourselves to.

BCP / DR posture — the numbers your auditor and risk team will ask for first.

4 hrs
RTO — recovery time objective (production tier)
15 min
RPO — recovery point objective (production tier)
Daily
cross-region backup snapshot (ap-south-1 → ap-southeast-1)
Quarterly
documented DR drill with restore + cutover benchmarks
99.9%
platform availability SLA on multi-tenant tier
99.95%
platform availability SLA on single-tenant tier
Specific compliance question?

Email compliance@squarenow.co.in

We reply within one working day. Security pack shared under NDA on request.