Identity
PAN, Aadhaar offline KYC, voter ID, driving licence and passport — plus face match, liveness and OCR for whatever still arrives as an image.
IdentifyScoreSecure
One API layer for identity, income and fraud intelligence. iScoreIt turns every applicant, merchant and payout account into a decision your team can defend — in under a second.
Signals evaluated
iScore
0
Low risk
Policy outcome — Approve, no step-up
Built for banks, NBFCs, fintechs and marketplaces
40+
Verification APIs
<500ms
Median response
99.9%
Platform uptime
1 key
UAT and live, one console
Who it's for
Surrogate and bureau signals give you an income estimate, an ability-to-pay view and a fraud read before the applicant ever uploads a payslip.
Application received
PAN, mobile, consent captured
Identity & bank verified
Name match + reverse penny drop
Income estimated
Surrogate model, no upload
Decision returned
Approve, limit ₹1.87L
KYB, beneficial ownership and payout-account screening run in the same call, so a seller goes live the same day without opening a hole in settlement.
Merchant signs up
GSTIN + PAN submitted
Entity graph built
3 directors, 1 linked entity
Payout account screened
Not seen on collection pages
Live with monitoring on
Re-scored every 24 hours
Every check, every model version and every override is stored against the case. Replay any decision from six months ago exactly as it was made.
Case opened
Ref DEC-88214 · 14 Mar
Screening run
Sanctions, PEP, adverse media
Analyst disposition
False positive, note attached
Replay available
Policy v14 · model v3.2
API catalogue
PAN, Aadhaar offline KYC, voter ID, driving licence and passport — plus face match, liveness and OCR for whatever still arrives as an image.
GSTIN, CIN and MCA filings, Udyam, shop & establishment licences, director networks and beneficial ownership — resolved into one entity graph.
Penny drop, reverse penny drop over UPI, UPI ID validation, IFSC resolution and bank statement analysis with salary and obligation tagging.
Device fingerprinting, email existence and digital footprint, mobile vintage and porting history, IP and geo risk — the quiet signals fraud can't fake cheaply.
A monthly income estimate built from surrogate and bureau signals. No payslip, no statement upload, no drop-off in the middle of your journey.
MuleNet continuously discovers illegal betting and gambling deposit pages, captures the collection UPI IDs, account numbers and QR codes shown on them, and screens your accounts against that evidence repository.
Sanctions, PEP and adverse media screening with tunable thresholds, ongoing rescreening, and dispositions stored against the case for audit.
swipe to explore
Developers
Send an applicant, name a policy, get a scored decision back with every underlying signal attached. No orchestration code, no vendor-by-vendor error handling, no reconciliation job.
iScoreIt Labs
Our team publishes what the data shows — how mule chains are actually structured, which signals hold up under pressure, and where verification quietly fails.
Mule networks
Thin-file credit
Customer
“We were running six vendors and reconciling them by hand. iScoreIt collapsed that into one call and one policy — and the review queue dropped by more than half in the first month.”
This doesn't have to end here
Bring us your riskiest cohort. We'll run it through the platform and show you what your current stack is missing.
Products
Pulse decides, Verify onboards, MuleNet protects. They share one identity graph, one policy layer and one audit trail — so a signal captured at onboarding is still working for you at payout six months later.
// Decide
Rules and models live in one policy layer. Risk writes the policy, engineering keeps shipping features, and every change is versioned the moment it is saved.
Visual policy builder no deploy
Thresholds, waterfalls and step-up logic edited in the console with maker–checker approval.
Shadow & champion–challenger safe rollout
Run a new policy silently against live traffic and compare outcomes before you cut over.
Decision replay audit
Reopen any decision with its exact inputs, policy version and model version intact.
Cost-aware waterfalls spend control
Order your checks so the cheap disqualifying signals run first and the expensive ones only run when they can still change the answer.
// Onboard
Drop-in hosted flows for individuals and businesses, with friction added only where the risk actually sits — not applied uniformly to everyone who walks in.
Hosted or headless your call
Use our journey with your branding, or call the same checks directly from your own app.
Risk-based step-up less drop-off
Selfie and liveness are requested when the signals demand it, not from everybody by default.
UAT and live in one console one key set
Switch environments from a toggle. Same payloads, same webhooks, seeded sandbox identities.
Re-KYC and periodic review stays current
Schedule re-verification by risk band so your book doesn't quietly go stale.
// Protect
Illegal betting and gambling sites have to show a collection account to get paid. MuleNet finds those pages continuously and turns what is printed on them into a screenable, evidence-backed list.
Continuous discovery always on
Crawlers surface new deposit pages and mirrors as they appear, not once a quarter.
Screenshot-backed evidence defensible
Every UPI ID, account number and QR code is stored with the page and timestamp it came from.
Linkage scoring beyond exact match
Accounts one or two hops from a known collection account get scored too, not just the ones on the list.
Payout-time screening before the money moves
Screen a beneficiary at payout, not just at onboarding, so an account that turns bad is caught.
This doesn't have to end here
Tell us which decision hurts most right now and we'll show you the shortest path to fixing it.
API catalogue
Every iScoreIt API shares the same authentication, the same error grammar, the same idempotency rules and the same webhook signature scheme. Learn one, and you have learned all of them.
Modules
PAN, Aadhaar offline KYC, voter ID, driving licence and passport — plus face match, liveness and OCR for whatever still arrives as an image.
GSTIN, CIN and MCA filings, Udyam, shop & establishment licences, director networks and beneficial ownership — resolved into one entity graph.
Penny drop, reverse penny drop over UPI, UPI ID validation, IFSC resolution and bank statement analysis with salary and obligation tagging.
Device fingerprinting, email existence and digital footprint, mobile vintage and porting history, IP and geo risk — the quiet signals fraud can't fake cheaply.
A monthly income estimate built from surrogate and bureau signals. No payslip, no statement upload, no drop-off in the middle of your journey.
MuleNet continuously discovers illegal betting and gambling deposit pages, captures the collection UPI IDs, account numbers and QR codes shown on them, and screens your accounts against that evidence repository.
Sanctions, PEP and adverse media screening with tunable thresholds, ongoing rescreening, and dispositions stored against the case for audit.
Endpoint reference
Endpoint paths shown for orientation. Full request and response schemas, error codes and rate limits live in the developer documentation.
| API | Endpoint | What it returns |
|---|---|---|
| PAN verification | POST /v1/identity/pan | Validates a PAN and returns name, status and Aadhaar-seeding flag. |
| Aadhaar offline KYC | POST /v1/identity/aadhaar/offline | OTP or XML-based offline KYC with masked storage. |
| Driving licence | POST /v1/identity/dl | Licence validity, holder name, date of issue and vehicle classes. |
| Voter ID / Passport | POST /v1/identity/voter | Electoral roll and passport file-number checks. |
| Face match & liveness | POST /v1/identity/face | Passive liveness plus 1:1 match against the document photo. |
| Document OCR | POST /v1/ocr/extract | Structured extraction with tamper and template checks. |
| GSTIN verification | POST /v1/business/gstin | Registration status, trade name, filing history and address. |
| MCA / CIN lookup | POST /v1/business/cin | Company master data, directors, charges and filing status. |
| Udyam / MSME | POST /v1/business/udyam | Udyam registration details and enterprise classification. |
| Director network | POST /v1/business/network | DIN-based graph of linked entities and shared directors. |
| Penny drop | POST /v1/bank/penny-drop | Credits a token amount and returns the registered account holder name. |
| Reverse penny drop | POST /v1/bank/reverse-penny-drop | UPI-collect based account ownership proof with no debit to you. |
| UPI ID verification | POST /v1/bank/vpa | Validates a VPA and returns the registered payee name. |
| IFSC lookup | GET /v1/bank/ifsc/{code} | Bank, branch, address and supported payment rails. |
| Bank statement analysis | POST /v1/bank/statement | Salary detection, obligations, bounces, and a tamper score. |
| Device intelligence | POST /v1/signals/device | Fingerprint, emulator and root detection, account linkage count. |
| Email intelligence | POST /v1/signals/email | Existence, domain risk, digital age, footprint depth and a recommendation. |
| Mobile intelligence | POST /v1/signals/mobile | Connection vintage, recent porting, SIM swap indicators and operator. |
| IP & geo risk | POST /v1/signals/ip | Proxy, VPN and hosting detection with geo-distance from declared address. |
| Estimated income | POST /v1/income/estimate | Document-less monthly income estimate with confidence and driver weights. |
| Employment check | POST /v1/income/employment | Employer confirmation and tenure from surrogate sources. |
| MuleNet screen | POST /v1/mulenet/screen | Screens a VPA or account against the collection-account evidence repository. |
| MuleNet linkage | POST /v1/mulenet/linkage | Returns hop distance and connected accounts for a beneficiary. |
| AML screening | POST /v1/aml/screen | Sanctions, PEP and adverse media with tunable match thresholds. |
| Ongoing monitoring | POST /v1/aml/monitor | Registers a subject for continuous rescreening with webhook alerts. |
| Decision | POST /v1/decision | Runs a named policy across any combination of the above and returns a scored outcome. |
Sandbox
The sandbox returns the same response shape as live, with seeded identities that deterministically produce clean, borderline and rejected outcomes. Flip one header to go live.
Seeded test identities deterministic
Named fixtures for a clean approve, a device-linked step-up, a mule hit and a sanctions match — so your QA suite can assert on outcomes.
Signed webhooks in UAT same secret flow
Webhook signatures work identically in sandbox, so you test verification once.
Rate limits mirrored no surprises
Sandbox enforces the same per-second ceilings you will hit on the day you launch.
This doesn't have to end here
Sandbox keys are issued the same day. No procurement cycle needed to find out whether this fits.
Solutions
A lender is asking “can they repay?” A marketplace is asking “is this the same person as last week?” A payments company is asking “where is this money going?” The signals overlap; the policy does not.
// Lending & NBFCs
Most rejections in personal and small-ticket lending are not credit calls — they are missing-data calls. iScoreIt fills the gap with surrogate income, verified banking and a fraud read, so the policy can act on evidence instead of absence.
Personal loans · Two-wheeler · Consumer durables · Business loans · Gold loans
// Fintech & payments
A payment business lives and dies on who it lets in. KYB, ownership resolution and payout-account screening run together, and MuleNet keeps checking after the merchant is live.
PA/PG · Neobanks · Wallets · Lending-as-a-service · Payout platforms
// Marketplaces & gaming
High-volume consumer platforms need verification that clears the honest majority in seconds and concentrates human review on the small slice that actually warrants it.
E-commerce · Real-money gaming · Gig platforms · Rental · Classifieds
// Insurance
Verification at proposal stage is cheaper than investigation at claim stage. The same identity and banking checks that clean up onboarding also give the claims team a baseline to compare against.
Life · Health · Motor · Micro-insurance · Distribution platforms
// Telecom & enterprise
Distribution networks, retailer onboarding and subscriber activation all need the same primitives — just with throughput and audit requirements that most verification stacks were not built for.
Telecom · Utilities · Logistics · BPO · Large enterprise procurement
This doesn't have to end here
Send us the decision you are trying to make. We'll map it to signals and show you the policy that gets there.
Trust & security
Verification platforms get asked hard questions by security teams, compliance teams and regulators — usually all three, usually at once. Here are the answers, written down.
Controls
ISO 27001
Information security management across the platform.
SOC 2 Type II
Controls tested over a period, not a point-in-time snapshot.
DPDP-aligned
Consent captured, stored and retrievable per data principal request.
Data residency in India
Processing and storage stay inside the country.
Encryption everywhere
TLS 1.3 in transit, AES-256 at rest, keys rotated on schedule.
Role-based access
Scoped keys, IP allowlists and full admin audit logs.
Least-data retention
Configurable retention windows with hard deletion, per endpoint.
Segregated environments
Sandbox and live are fully separate — no shared stores or keys.
Certification statuses shown here are placeholders in this build. Replace each one with your actual certificate, scope and audit date before publishing — and remove any you have not yet been awarded.
Reliability
A verification API that fails closed can stop your business. One that fails open can cost you a lot more. iScoreIt does neither by default — it tells your policy exactly which signal is missing and lets you decide.
Questions we get asked
All processing and storage for Indian customers happens inside India. Retention windows are configurable per endpoint, and you can request hard deletion of any record through the console or the API.
No. Data submitted through the APIs is used to answer that request and to serve your own audit trail. It is not pooled into shared training sets. Aggregate fraud intelligence such as MuleNet is built from publicly published collection pages, not from customer submissions.
Every call that touches a personal identifier expects a consent artefact reference. That reference is stored against the decision so you can produce it later — for a regulator, an auditor, or the data principal themselves.
Responses carry a structured status per signal rather than failing the whole call. Your policy decides whether a missing signal means step-up, manual review, or proceed — so an upstream outage does not silently change your approval rate.
Yes. For DigiLocker-based flows we operate as the technology and orchestration layer while you hold your own requester registration, which keeps the regulatory relationship where it belongs.
Decision records, policy versions and model versions are retained for the period you configure, with a default that comfortably covers standard audit cycles. Personal identifiers inside those records can be masked independently of the decision metadata.
This doesn't have to end here
We would rather answer it up front than three weeks into a procurement cycle.
iScoreIt Labs
We publish what the data shows — how mule chains are actually structured, which signals hold up under pressure, and where verification quietly fails. No vendor gloss.
Mule networks
We followed the collection accounts published on a cluster of betting sites for six weeks. The structure is more consistent — and more findable — than most fraud teams assume.
Read the studyThin-file credit
Not every surrogate earns its place in a model. We ranked the ones that survive contact with an out-of-time sample, and the ones that quietly stop working after a quarter.
Read the studyDevice intelligence
Linkage counts are one of the highest-signal, most-misused features in onboarding. A short guide to setting the threshold without rejecting half of a joint-family customer base.
Read the studyOnboarding
Uniform friction is the most expensive default in KYC. What changes when you request documents from twelve percent of applicants instead of everyone.
Read the studyPayments
A practical comparison of penny drop and reverse penny drop across cost, assurance, customer experience and the failure modes each one hides.
Read the studyCompliance
Storing the outcome is easy. Storing the reasoning — inputs, policy version, model version, overrides — is what turns an audit from a fire drill into a query.
Read the studyThese are placeholder titles and summaries for the build. Replace them with your published research before launch — thin or fabricated article pages will hurt your search rankings rather than help them.
This doesn't have to end here
We share underlying methodology and sample data with teams evaluating the platform.
About
iScoreIt is a risk intelligence platform for the teams who have to say yes or no to a stranger in under a second — and then explain that answer months later.
Why we exist
The gap between “this PAN is valid” and “approve this applicant for ₹1.87 lakh” is where most of the cost, most of the fraud and almost all of the manual work sits. iScoreIt is built to close it.
We come out of lending, not out of a generic API business — which is why the platform is opinionated about things like cost-aware waterfalls, decision replay and what happens when an upstream source goes down mid-journey.
The problem
Risk teams were stitching together a PAN provider, a bank verification provider, a bureau, a device SDK and two spreadsheets — then reconciling the answers by hand. The decision was never the hard part. Getting trustworthy inputs to it was.
The idea
A verification API tells you a field matched. That is not a decision. We wanted a layer that collects the signals, weighs them against a policy you control, and returns something you can act on and later defend.
The build
Same auth, same error grammar, same idempotency, same webhook signature — across identity, banking, business, device, income and AML. Learn one endpoint and you have learned all of them.
The differentiator
MuleNet came out of a simple observation: illegal collection operations have to publish an account to get paid. That published evidence, gathered continuously, is a fraud dataset nobody else was assembling systematically.
How we build
Evidence over assertion
Every score comes with the signals that produced it. If we cannot show you why, we do not ship it.
Fail loud, not open
A missing signal is reported as missing. Your policy decides what that means — we never quietly substitute a default.
The customer holds the relationship
Where a regulated registration belongs to you, it stays with you. We are the technology layer, not a middleman on your compliance.
Boring where it matters
Auth, idempotency, versioning and audit trails are unglamorous and non-negotiable. The interesting work sits on top of them.
40+
Verification APIs
<500ms
Median response
99.9%
Platform uptime
1 key
UAT and live, one console
This doesn't have to end here
The fastest way to evaluate us is a sandbox key and your own back-book sample.
Contact
Book a demo, request sandbox keys, or send a security questionnaire. Whichever it is, you will get a person who has worked in risk — not a form response.
Direct
Reaching out directly is usually faster than a form, and it lands with the same people.
Sales & demos
Developer support
Security & compliance
Before you ask
Same day in most cases. Sandbox keys do not require a signed contract — we would rather you test against real response shapes before anyone talks about commercials.
Yes. The most useful evaluation is a back-book sample scored against your current outcomes, so you can see where the platform would have decided differently and why.
Usage-based per check, with volume tiers and a platform component for the decision engine. Pricing is quoted against your actual mix of checks rather than a single blended rate.
Most customers do. A single high-value check — reverse penny drop, income estimation or MuleNet screening — is a common first integration, with the decision engine added later.
This doesn't have to end here
Sandbox keys the same day. No procurement cycle needed to find out whether this fits.