Compliance is a feature, not a constraint.
We built Kapiital products to operate inside the Indian regulatory environment, comfortably. RBI DLG, the SRO regime, data localisation, scale-based regulation — these are protections for the borrower and the system.
Where we stand on every framework that matters.
RBI Digital Lending Guidelines
Disclosures, consent capture, audit trail. Compliant with the September 2022 framework and subsequent updates.
SRO regime under FACE
Pre-built disclosures and reporting for Self-Regulatory Organisation obligations.
Data localisation
Customer data hosted in India. AWS Mumbai (ap-south-1).
Scale-based regulation
Pre-built reports for Base, Middle, Upper, and Top Layer NBFCs.
NBFC-MFI compliance
Qualifying asset ratio reporting, household indebtedness checks.
Section 8 lenders
Companies Act overlay built in.
SOC 2 Type 2
In process for 2026.
ISO 27001
In process for 2026.
Architecture, not assertions.
Detailed security documentation is shared with customers on request, under NDA.
Network isolation
VPC isolation. WAF in front of all customer-facing endpoints.
Encryption
In transit (TLS 1.2+). At rest (AES-256). Per-customer keys on single-tenant and enterprise plans.
Pen testing
Quarterly third-party penetration testing. Reports shared on request under NDA.
Dependency hygiene
Continuous dependency scanning. Critical CVEs patched within 48 hours.
Incident response
Documented runbook. 24-hour customer notification on confirmed breach.
Disaster recovery
Daily backups to a separate region. Point-in-time recovery for 30 days. Annual DR test.
India-resident, by default. Stored in AWS Mumbai. Never used to train shared models.
Email compliance@kapiital.com
We reply within one working day.