01 Compliance · Is Any of This Still Optional?
NonaShield

It stopped being optional five years ago.

RBI, NPCI & DPDP compliance for mobile apps — seven requirements, seven deadlines, five already passed.

Today
Transaction monitoringRBI DPSC
18 Feb 2021
Jun 2022
CERT-In180-day log retention
Request integrityPCI DSS v4.0.1
31 Mar 2025
19 May 2025
NPCI UPI MASFApp + device integrity
A dynamic proven factorRBI Auth Directions
1 Apr 2026
1 Jan 2027
RBI liability shiftBurden of proof shifts
Endpoint safeguardsDPDP Rule 6
12 May 2027

Instruments as published by RBI, NPCI, PCI SSC, CERT-In and MeitY. Dates are compliance dates, not issue dates.

Seven requirements. Seven dates. And no single product on the market covers them all.

Five of them are already behind you. The two ahead are the two that move money and liability onto your books.

02 Your Sector · What Binds You, and What It Costs
NonaShield

Whatever you are, something already binds you.

The instrument changes by sector. What it asks of the mobile app barely changes at all.

SectorWhat Binds YouProducts RequiredWhat It Looks Like For YouThe Published NumberFrom
Banking & PSOsRBI DPSC 2021 · Auth Directions 2025 · NPCI UPI MASFRASP · Fingerprint · Identity · API · Behaviour · Risk Score · Graph · Evidence · ComplianceCustomer talked through an approval on their own phone₹805 cr in eight months. 6.66% recovered1 Apr 2026 / liability 1 Jan 2027
Fintech & NeobankingNPCI UPI MASF · RBI PSO Directions 2024RASP · Fingerprint · Identity · API · Behaviour · Risk Score · Graph · Evidence · ComplianceAccount takeover from a second handset after a SIM swapMobile fraud sessions +67% YoY. iOS +86%19 May 2025
NBFC & Digital LendingRBI Digital Lending Directions 2025 · DLA directoryRASP · Fingerprint · Identity · API · Behaviour · Risk Score · ComplianceRepackaged loan apps, and device farms at onboardingRBI now publishes a directory of genuine apps1 Jul 2025
Trading & BrokingSEBI CSCRF — Cyber Resilience FrameworkRASP · Fingerprint · Identity · API · Behaviour · Evidence · ComplianceUnauthorised order placement from a hijacked sessionBinding on all regulated entities31 Aug 2025
E-Commerce & MarketplacesPCI DSS v4.0.1 · E-Commerce Rules 2020RASP · Fingerprint · Identity · API · Behaviour · Evidence · CompliancePromo, refund and multi-account abuse from emulatorsText-message scams +146%31 Mar 2025
Media & OTTIT Rules 2021 · licensor content obligationsRASP · Fingerprint · Identity · API · Behaviour · Evidence · ComplianceCredential sharing, rooted-device capture, stream ripping₹22,400 cr a year lost to piracyIn force
E-Governance AppsAadhaar Act & UIDAI · MeitY · localisationRASP · Fingerprint · Identity · API · Behaviour · Evidence · ComplianceCloned fingerprints where there is no liveness checkAePS = 11% of online financial scams, I4C 2023In force
Startups & D2CDPDP Rules 2025 · CERT-In Directions 2022RASP · Fingerprint · Identity · API · Evidence · CompliancePersonal data taken from the device before it reaches youUp to ₹250 cr for a safeguards failure12 May 2027

MoS Finance Dec 2025 · Ministry of Finance, Rajya Sabha Jul 2026 · BioCatch Jul 2026 · PIB Jul 2025 · SEBI · EY–IAMAI Oct 2024, whole M&E sector · I4C 2023 · DPDP Act 2023, Sch. 1

Eight industries. Eight vocabularies. One mechanism underneath all of them.

Five of these eight need all nine layers, and none needs fewer than six. Not one of them is a broken phone — every one is a working phone that lied.

03 DPDP · Where Our Scope Starts and Stops
NonaShield

We solve one clause of DPDP. Not the Act.

It happens to be the clause with ₹250 crore attached.

What We Cover

§8(5) and Rule 6 — Reasonable Security Safeguards

✓
Access control rooted in hardwareA key in the secure element, not a claim the app makes about itself.
✓
Encryption, plus proof of originPinning and a signed payload — integrity as well as confidentiality.
✓
Access and processing logs, one yearRule 6 asks 365 days; CERT-In asks 180. One setting satisfies both.
✓
The breach class servers cannot seeOverlay, screen capture, keylogging, clipboard, cloned apps — personal data taken before it ever reaches you.
What We Do Not Cover

Your Privacy Programme Stays Yours

—Consent capture, notice and consent-manager registration
—Data principal rights — access, correction, erasure
—Purpose limitation and retention across your other systems
—Cross-border transfer governance
—Grievance redressal and Board correspondence

We are a Data Processor to you. Rule 6 requires a contract mandating equivalent safeguards — ours is ready to sign.

₹250 crore for a security-safeguards failure. ₹200 crore for failing to report the breach.

Both need the same thing — telemetry the attacker could not have written.

See the full DPDP Rule 6 breakdown →

04 Compliance · What It Closes on Day One
NonaShield

Every requirement, mapped to a shipped control.

Control-mapped on day one — not a roadmap, and not a claim of compliance.

The RequirementWhat Satisfies It in NonaShieldThe InstrumentStatus
App integrity (RASP)Phone health — root, tamper, hook, overlay, debuggerNPCI UPI MASFControl Mapped
Device bindingDevice recognition across sessions and accountsNPCI UPI MASF · RBI DPSCControl Mapped
Authentication factorsHardware identity — a dynamic factor unique to the transactionRBI Auth Directions 2025Control Mapped
Request & channel integrityAPI layer — pinning, proxy detection, signed payloadNPCI UPI API OC-215A · PCI DSS v4.0.1Control Mapped
Transaction monitoringBehaviour + risk engine + graph analysisRBI DPSC 2021Control Mapped
Risk-based authenticationRisk score on device, location, behaviour and historyRBI Auth Directions 2025Control Mapped
Endpoint data protectionOverlay, capture, keylog and clone blocking at the deviceDPDP §8(5) / Rule 6Control Mapped
Log retention & proofCryptographic evidence — signed, retained one year, exportableCERT-In 2022 · DPDP Rule 6 · RBI Fraud CompensationControl Mapped

Twelve controls, 166 threat IDs, mapped live — ask us for the current coverage report.

Four vendors and a compliance project — or one SDK and a signed record.

That is the whole pitch. One SDK, one integration, and an answer you can prove.

05 When Something Goes Wrong, What Do You Actually Have?
NonaShield

A rule engine that can't explain itself isn't evidence.

Six Reports, Ready When You Need Them.

ReportWhat It Actually ShowsWhat It's Used For
1. Device Health ReportWhether the phone was rooted, jailbroken, an emulator, or running hacking tools at the time.Proves an account takeover was automated, not the real customer acting on their own device.
2. Hardware Proof ReportWhether the signing key actually belongs to the customer's real, enrolled device.Proves a transaction request didn't come from the genuine device — non-repudiable proof, not a guess.
3. Behaviour & Bot ReportWhether a real person was doing this, or a script, bot, or remote-control app (like AnyDesk or TeamViewer) was active.Proves unauthorised remote access or a scripted mule network, not ordinary customer behaviour.
4. Early Warning LogExactly when risk jumped, how fast, and what the system did about it — down to the second.Shows an alert was raised and acted on in time, not after the fact.
5. Investigation WorksheetThe full step-by-step story of what happened on the device, in order, with the evidence attached.Becomes the technical backbone of the bank's official report to regulators.
6. Rule & Config Audit TrailA record of every fraud-rule change, who made it, and when — impossible to edit after the fact.Used in regulator inspections to prove nobody quietly weakened the fraud controls.

Each report is generated from the same signed evidence record — nothing is written after the fact.

Six reports. One source of truth behind all of them.

Not six separate systems bolted together — six views of the same signed record.

06 Which Rules These Reports Actually Satisfy
NonaShield

Four rulebooks. One evidence trail satisfies all of them.

Real Rules, in Plain English.

India's Anti-Money-Laundering Law (PMLA, 2002)

Banks must report suspicious activity to India's financial intelligence unit within 7 days of suspecting it.

NonaShield's part: supplies the technical proof behind that report — why the account looked suspicious, in evidence a regulator can check.

RBI's Fraud Risk Rules (2024)

Banks must run an early-warning system, flag risky accounts, and report frauds on time.

NonaShield's part: generates the early-warning alert log and the reasoning behind each flag, ready for the bank's fraud committee.

RBI's Digital Payment Security Rules (MD-DPSC)

Apps must check the device is genuine, block remote-access tools, and catch fake overlay screens.

NonaShield's part: proves those checks actually ran on that transaction, not just that a policy exists on paper.

RBI's Cybersecurity Rules for Banks

Banks must keep tamper-proof records and be able to investigate an incident properly.

NonaShield's part: every record is signed at the moment it's created, so it can't be quietly edited later.

07 From the Phone to the Regulator
NonaShield

Detection is instant. The paperwork isn't.

Two Speeds, One Evidence Trail.

Happens Instantly

On the Device, Right Then

  • Checking if the device is tampered with, cloned, or running an emulator
  • Spotting a remote-access tool or bot behaviour while it's happening
  • Recording every fraud-rule change the moment it's made

Required in real time under RBI's digital payment security rules.

Happens Afterward

The Investigation & Filing

  • Writing up what happened, in order, as a case file
  • Getting sign-off from the person responsible for compliance
  • Filing the final report within 7 working days of suspecting fraud

Required under India's anti-money-laundering rules.

NonaShield sits at the first step — on the phone, at the moment the transaction happens. It hands the bank's fraud and compliance teams real signals (is this a bot, is this device tampered with, is a remote-access tool active) that become the first piece of evidence in everything that follows: the bank's own internal case file, and — where needed — what gets filed with regulators or the police.

The bank still writes the report. NonaShield gives it something true to write.

Ask Us for the Coverage Report.

Twelve controls, mapped to the instrument, for your sector.