Built for the way ambitious Indian businesses move moneyExplore business banking
SECURITY ARCHITECTURE

Security belongs inside
every transaction path.

Experia360 is engineered to minimize sensitive-data exposure and make high-risk operations explicit, tenant-scoped, reviewable and fail-closed.

Start a controlled workspace
CONTROLLEDBY DESIGN
ENCRYPTSCOPEEVIDENCE
APPLICATION CONTROLS

Layered controls.
Clear responsibility.

Application safeguards reduce risk, but deployment, operations and organizational governance remain essential.

01

No raw cardholder data

The application has no fields for PAN, CVV/CVC, track data, PIN or other sensitive authentication data.

02

Explicit tenant context

Protected operations require authenticated organization membership and organization-scoped permission checks.

03

Secrets stay secret

Bank credentials and sensitive identifiers are encrypted, hidden from serialization and excluded from audit payloads.

04

Independent decisions

Connection activation, payout approval and onboarding review use separate-user controls where required.

05

Traceable operations

Request IDs, audit events, status transitions and integrity hashes create evidence for operational review.

06

Financial integrity

Money uses integer paise; posted journals are balanced and corrected through explicit reversals.

PCI DSS SCOPE BOUNDARY

Reduce card-data scope.
Do not manufacture confidence.

Source code alone cannot make an organization PCI DSS compliant. Any future card capture must use hosted or tokenized components supplied by a PCI DSS validated provider.

  • No raw cardholder data model
  • Tokenized or hosted capture boundary required
  • Logs and analytics follow the same prohibition
SENSITIVE DATA HANDLING

Encrypted where needed.
Masked everywhere else.

DATA CLASSAPPLICATION TREATMENTDISPLAY
Bank credentialsEncrypted application field; never returned after configurationConfiguration metadata only
PAN / GSTIN / registrationEncrypted at rest with last-four metadata where requiredMasked
Settlement account numberEncrypted at restLast four digits
Onboarding documentsEncrypted private storage plus SHA-256 integrity recordAuthorized download only
API and webhook secretsHashed or encrypted according to verification needShown once at creation