How the platform is secured, and what happens if something goes wrong.
All traffic between your device and our systems travels over encrypted channels. Sensitive records are encrypted at rest, and identifiers such as PAN are tokenised or hashed rather than stored in the clear.
Internal access to identity and financial records is limited by role, granted on a need-to-know basis, reviewed periodically and logged. Administrative access requires multi-factor authentication.
Decision inputs, consent records and administrative actions are logged immutably so any application or account change can be reconstructed and audited.
Dependencies are monitored and patched on a defined cycle, and the platform is subject to periodic security testing. Findings are tracked to closure by severity.
Suspected incidents follow a documented response process covering containment, assessment, regulatory notification where required, and notification to affected customers. Report a suspected vulnerability to security@advancerupay.com.
Data is backed up on a defined schedule with tested restoration, so servicing and repayment can continue through an outage.
Traffic between your device and our systems is encrypted in transit. Sensitive identifiers are stored as one-way hashes rather than in readable form — a PAN, for example, is tokenised and the raw number is never retained. Bank account numbers are stored masked.
Access is role-limited and granted on the least-privilege principle: support staff see what they need to answer your question and no more, and access to underwriting inputs is restricted to the people making that decision. Access is logged, and the log is reviewed rather than merely retained.
We maintain an incident response process covering detection, containment, assessment and notification. Where an incident affects your data, we notify affected users and the relevant authority as required, and we say what happened rather than describing it vaguely.
Verification, payment and communication providers are assessed before integration and are contractually bound on data handling, retention and deletion. A provider cannot use what it processes for us for any purpose of its own.
Only repay through advancerupay.com or the AdvanceRupay app, and never share an OTP, UPI PIN or password with anyone — including anyone claiming to be from AdvanceRupay. We will never ask for those. Report the message to us with the number it came from.
No documentation, disbursal to your own bank account, and every charge disclosed in your Key Fact Statement before you accept.