The problem with how this works today
Business lending, vendor onboarding and KYC all run on the same pattern: a requester asks for documents, you email a folder, and the exchange leaves no usable trace.
Three consequences, all of them ordinary rather than dramatic:
- You cannot answer “who has my documents?” Not which organisation, which people, and whether they still hold them.
- There is nothing to revoke. A declined loan application does not return your bank statements.
- Nobody can prove what was shared. If a figure is later disputed, neither side can show which version was sent.
What consent-based sharing means
Instead of sending files, the holder of the documents grants consent for a named requester to receive a specific set, for a stated purpose, for a defined period.
The shape of it:
- The requester asks for what it needs. Specific document types and a purpose, not “send your financials”.
- You see the request and decide. What is being asked for, by whom, why, and for how long, before anything moves.
- You grant or decline. Granting releases only the documents in that request.
- The requester receives them through an authenticated integration rather than an email attachment.
- You can revoke. The consent ends, and so does further access.
- Both sides hold a record of what was consented to, when, and what was released.
Recurring requests, handled once
Lenders routinely need the same documents monthly. Updated bank statements for a working-capital facility, refreshed GST returns for a revolving line.
Re-consenting every month is friction that pushes everyone back to email. A periodic consent covers a defined recurrence for a defined period: you agree once that this requester may receive this document type on this cadence, and you can still revoke at any point. That is the difference between a control that is used and one that is bypassed.
How the requester side is built
The integration is built on published standards rather than a bespoke scheme, which matters because it is what a bank’s security review will ask about:
- DPoP (RFC 9449). Tokens are bound to the requester’s key, so an intercepted token cannot be replayed by someone else.
- PKCE on the authorisation exchange, so the consent flow cannot be hijacked mid-redirect.
- Signed artefacts and manifests, the requester can verify that what it received is what was consented to and has not been altered.
- Webhooks so the requester learns of a grant or a revocation rather than polling.
- A sandbox to integrate against before touching real documents.
A full-page redirect path exists alongside the popup flow, because bank mobile apps render in webviews where popups do not survive.
Who this is for
- Businesses applying for credit. Share with several lenders without losing track of who holds what, and revoke when an application closes.
- Banks and NBFCs. Receive documents with a verifiable consent record attached, rather than attachments whose provenance rests on an email thread.
- Any requester running document KYC. Onboarding a vendor, verifying a counterparty, periodic refresh.
What this is and is not
It is a consent and delivery layer for documents, with a record on both sides and revocation that takes effect.
It is not a credit decision, a verification of the contents of your documents, or an assertion about your creditworthiness. A lender still underwrites; this changes how the documents reach them and what both parties can prove afterwards.
And it does not undo copying. A requester that has received a document holds a copy. Revocation stops further access; it does not retrieve what was already delivered. What you gain is knowing exactly what was delivered and when, the same honest limit as any document sharing.
Where the data sits
Hosting and object storage are located in India (Mumbai), with TLS in transit. Every sub-processor, its location and what reaches it, is published in the Privacy Policy rather than supplied on request. Technical measures are on security; how the platform maps to the DPDP Act is on DPDP compliance.
This page describes product capability. It is not legal advice and makes no claim about regulatory registration or licensing status. Your own obligations as a business sharing documents, or as a regulated entity receiving them, depend on your facts. Take advice on your own situation.
XDrop AI is a data room for Indian fundraising, with an AI that answers investor questions and cannot read what you have not shared.
Start free