It stopped being optional five years ago.
Instruments as published by RBI, NPCI, PCI SSC, CERT-In and MeitY. Dates are compliance dates, not issue dates.
Seven requirements. Seven dates. And no single product on the market covers them all.
Five of them are already behind you. The two ahead are the two that move money and liability onto your books.
Whatever you are, something already binds you.
| Sector | What Binds You | Products Required | What It Looks Like For You | The Published Number | From |
|---|---|---|---|---|---|
| Banking & PSOs | RBI DPSC 2021 · Auth Directions 2025 · NPCI UPI MASF | RASP · Fingerprint · Identity · API · Behaviour · Risk Score · Graph · Evidence · Compliance | Customer talked through an approval on their own phone | ₹805 cr in eight months. 6.66% recovered | 1 Apr 2026 / liability 1 Jan 2027 |
| Fintech & Neobanking | NPCI UPI MASF · RBI PSO Directions 2024 | RASP · Fingerprint · Identity · API · Behaviour · Risk Score · Graph · Evidence · Compliance | Account takeover from a second handset after a SIM swap | Mobile fraud sessions +67% YoY. iOS +86% | 19 May 2025 |
| NBFC & Digital Lending | RBI Digital Lending Directions 2025 · DLA directory | RASP · Fingerprint · Identity · API · Behaviour · Risk Score · Compliance | Repackaged loan apps, and device farms at onboarding | RBI now publishes a directory of genuine apps | 1 Jul 2025 |
| Trading & Broking | SEBI CSCRF — Cyber Resilience Framework | RASP · Fingerprint · Identity · API · Behaviour · Evidence · Compliance | Unauthorised order placement from a hijacked session | Binding on all regulated entities | 31 Aug 2025 |
| E-Commerce & Marketplaces | PCI DSS v4.0.1 · E-Commerce Rules 2020 | RASP · Fingerprint · Identity · API · Behaviour · Evidence · Compliance | Promo, refund and multi-account abuse from emulators | Text-message scams +146% | 31 Mar 2025 |
| Media & OTT | IT Rules 2021 · licensor content obligations | RASP · Fingerprint · Identity · API · Behaviour · Evidence · Compliance | Credential sharing, rooted-device capture, stream ripping | ₹22,400 cr a year lost to piracy | In force |
| E-Governance Apps | Aadhaar Act & UIDAI · MeitY · localisation | RASP · Fingerprint · Identity · API · Behaviour · Evidence · Compliance | Cloned fingerprints where there is no liveness check | AePS = 11% of online financial scams, I4C 2023 | In force |
| Startups & D2C | DPDP Rules 2025 · CERT-In Directions 2022 | RASP · Fingerprint · Identity · API · Evidence · Compliance | Personal data taken from the device before it reaches you | Up to ₹250 cr for a safeguards failure | 12 May 2027 |
MoS Finance Dec 2025 · Ministry of Finance, Rajya Sabha Jul 2026 · BioCatch Jul 2026 · PIB Jul 2025 · SEBI · EY–IAMAI Oct 2024, whole M&E sector · I4C 2023 · DPDP Act 2023, Sch. 1
Eight industries. Eight vocabularies. One mechanism underneath all of them.
Five of these eight need all nine layers, and none needs fewer than six. Not one of them is a broken phone — every one is a working phone that lied.
We solve one clause of DPDP. Not the Act.
We are a Data Processor to you. Rule 6 requires a contract mandating equivalent safeguards — ours is ready to sign.
₹250 crore for a security-safeguards failure. ₹200 crore for failing to report the breach.
Both need the same thing — telemetry the attacker could not have written.
Every requirement, mapped to a shipped control.
| The Requirement | What Satisfies It in NonaShield | The Instrument | Status |
|---|---|---|---|
| App integrity (RASP) | Phone health — root, tamper, hook, overlay, debugger | NPCI UPI MASF | Control Mapped |
| Device binding | Device recognition across sessions and accounts | NPCI UPI MASF · RBI DPSC | Control Mapped |
| Authentication factors | Hardware identity — a dynamic factor unique to the transaction | RBI Auth Directions 2025 | Control Mapped |
| Request & channel integrity | API layer — pinning, proxy detection, signed payload | NPCI UPI API OC-215A · PCI DSS v4.0.1 | Control Mapped |
| Transaction monitoring | Behaviour + risk engine + graph analysis | RBI DPSC 2021 | Control Mapped |
| Risk-based authentication | Risk score on device, location, behaviour and history | RBI Auth Directions 2025 | Control Mapped |
| Endpoint data protection | Overlay, capture, keylog and clone blocking at the device | DPDP §8(5) / Rule 6 | Control Mapped |
| Log retention & proof | Cryptographic evidence — signed, retained one year, exportable | CERT-In 2022 · DPDP Rule 6 · RBI Fraud Compensation | Control Mapped |
Twelve controls, 166 threat IDs, mapped live — ask us for the current coverage report.
Four vendors and a compliance project — or one SDK and a signed record.
That is the whole pitch. One SDK, one integration, and an answer you can prove.
A rule engine that can't explain itself isn't evidence.
| Report | What It Actually Shows | What It's Used For |
|---|---|---|
| 1. Device Health Report | Whether the phone was rooted, jailbroken, an emulator, or running hacking tools at the time. | Proves an account takeover was automated, not the real customer acting on their own device. |
| 2. Hardware Proof Report | Whether the signing key actually belongs to the customer's real, enrolled device. | Proves a transaction request didn't come from the genuine device — non-repudiable proof, not a guess. |
| 3. Behaviour & Bot Report | Whether a real person was doing this, or a script, bot, or remote-control app (like AnyDesk or TeamViewer) was active. | Proves unauthorised remote access or a scripted mule network, not ordinary customer behaviour. |
| 4. Early Warning Log | Exactly when risk jumped, how fast, and what the system did about it — down to the second. | Shows an alert was raised and acted on in time, not after the fact. |
| 5. Investigation Worksheet | The full step-by-step story of what happened on the device, in order, with the evidence attached. | Becomes the technical backbone of the bank's official report to regulators. |
| 6. Rule & Config Audit Trail | A record of every fraud-rule change, who made it, and when — impossible to edit after the fact. | Used in regulator inspections to prove nobody quietly weakened the fraud controls. |
Each report is generated from the same signed evidence record — nothing is written after the fact.
Six reports. One source of truth behind all of them.
Not six separate systems bolted together — six views of the same signed record.
Four rulebooks. One evidence trail satisfies all of them.
Banks must report suspicious activity to India's financial intelligence unit within 7 days of suspecting it.
NonaShield's part: supplies the technical proof behind that report — why the account looked suspicious, in evidence a regulator can check.
Banks must run an early-warning system, flag risky accounts, and report frauds on time.
NonaShield's part: generates the early-warning alert log and the reasoning behind each flag, ready for the bank's fraud committee.
Apps must check the device is genuine, block remote-access tools, and catch fake overlay screens.
NonaShield's part: proves those checks actually ran on that transaction, not just that a policy exists on paper.
Banks must keep tamper-proof records and be able to investigate an incident properly.
NonaShield's part: every record is signed at the moment it's created, so it can't be quietly edited later.
Detection is instant. The paperwork isn't.
Required in real time under RBI's digital payment security rules.
Required under India's anti-money-laundering rules.
NonaShield sits at the first step — on the phone, at the moment the transaction happens. It hands the bank's fraud and compliance teams real signals (is this a bot, is this device tampered with, is a remote-access tool active) that become the first piece of evidence in everything that follows: the bank's own internal case file, and — where needed — what gets filed with regulators or the police.
The bank still writes the report. NonaShield gives it something true to write.
Twelve controls, mapped to the instrument, for your sector.