Security & Compliance

Security is the product, not a feature

BNPRS builds payment infrastructure for issuing banks. Everything we ship is designed around one principle: the transaction is authenticated by who you are — verified by the issuer, protected end to end.

Certifications & recognitions

Compliance is table stakes in payments. These are the standards and recognitions our platform and company operate under.

PCI-DSS

Payment Card Industry Data Security Standard compliance for cardholder data processing, storage, and transmission.

PCI-PIN

PIN security requirements compliance for PIN-based transaction processing and key management.

ISO

ISO-aligned management systems for information security and quality across engineering and operations.

DPIIT Recognised

Recognised startup by the Department for Promotion of Industry and Internal Trade, Government of India.

Payments Council of India

Member of the representative body of the Indian digital payments industry.

IAMAI

Member of the Internet and Mobile Association of India.

IIT Hyderabad TRP

Research lab at the Technology Research Park, IIT Hyderabad campus.

Architecture principles

The design rules applied across every BNPRS product, from the AandhiPe SuperApp to card personalisation and the bRUID processing stack.

Zero-Trust architecture

No implicit trust between components. Every request is authenticated and authorized at every layer, from terminal to switch to issuer.

Issuer-controlled biometric validation

Biometric verification is anchored at the issuing bank — not the device. The cardholder is verified, not just the device holder.

Encryption everywhere

Sensitive data is encrypted in transit and at rest. Payment keys are generated, stored, and injected under hardware-backed key management.

Least-privilege operations

Production access is role-scoped and audited. Terminal fleets are managed remotely with full audit logging.

Data protection

Biometric and payment data are processed under strict purpose limitation: data collected for authentication is used for authentication. Sensitive data is never logged in plaintext, and access to production systems is role-scoped and audited.

For details on what data our website collects, see our Privacy Policy.

Responsible disclosure

If you believe you have found a security vulnerability in a BNPRS product or website, we want to hear from you. Write to info@bnprs.in with the details. We ask that you give us reasonable time to investigate and remediate before public disclosure, and we commit to acknowledging your report.