Device integrity
Is this a real, untampered phone?
- Root
- Hooking
- Emulator
- Debugger
- App cloning
- Screen overlay
- Remote access
- Mock location
Rimor reads the other half: the phone, its integrity, and the behaviour of whoever filled the form. Every score comes with the evidence behind it.
Is this a real, untampered phone?
Have we seen this phone before?
Did a person fill this in?
Never collected: SMS, call logs, contacts, photos, location, phone number, IMEI, installed apps, or the characters anyone types.
Every signal, explained// when the applicant starts
Forensics.start(context, applicantRef, consent)
Forensics.attach(this)
// when they submit
uploader.send(Forensics.snapshot(), consent, leadId)
Forensics.endSession()Your lending policy stays. Our work earns its place.
The SDK goes into a staging build, with consent copy in your journey.
Every application is scored in silence. Applicants and decisions don't change.
Scores are joined to outcomes such as DPD 30, through hashed application IDs.
Fraud caught at your review budget, good customers flagged by mistake, and what didn't work.
Borrower data, backups and server logs stay in India.
AES-256-GCM on every upload, keys outside the database.
Your application ID is kept only as a keyed hash.
No consent receipt, no upload. The server refuses it too.
Typing is measured. What anyone types is never read.
Raw data is deleted after 180 days by default.
Fill it the way you normally would, then let a bot have a go. This runs only in your browser, and it never reads what you type.
Our first lending partner has the SDK and is integrating it for a shadow pilot. Here is what runs today and what follows.
One SDK, no change to your decisions, and a straight answer on whether it helps.