Security at Rimor

Collect less. Protect everything. Keep it in India.

We handle applicant data on behalf of lenders, so we treat it as theirs. We collect only what a risk decision needs, protect it at every step, keep it in India and delete it on schedule.

Data stays in India

Lending data is collected, processed and stored in India, and nowhere else.

Encrypted end to end

Protected in transit and at rest, with keys held apart from the data they protect.

Collect only what's needed

Nothing without the applicant's consent, and only what a risk decision needs.

Controlled access

Least-privilege access for our team, with every access logged and reviewable.

Deleted on schedule

Kept only for the period agreed with each lender, then deleted, backups included.

Watched and accountable

Monitored around the clock, with logs kept in India and incidents reported as Indian rules require.

Never collected
  • SMS
  • Call logs
  • Contacts
  • Photos and files
  • Location
  • Phone numbers
  • Anything an applicant types
Regulations we design for

The rules behind the design.

These shape how Rimor is built. They are not a certification; lenders should confirm their own obligations with counsel.

RBI Digital Lending Directions
Borrower data stored in India; no processing abroad.
DPDP Act and Rules
Rimor acts as a data processor for the lender. Consent first, minimal collection, deletion on schedule.
CERT-In directions, 2022
Logs kept in India; incidents reported within six hours.
Google Play personal loan policy
No access to SMS, call logs, contacts, photos or installed apps. No invasive permissions.

Security documentation

Detailed security documentation is available to lenders on request, under NDA.

Request documentation

Found a security issue?

Tell us before anyone else. Reports go straight to the founders.

Report an issue