A live V-CIP session between your official and your customer — and a record that carries how every fact came to be known. Identity is read from signed payloads and verified, never guessed from a photograph.
flows run with no UIDAI licence
carries its own provenance
runs with the network interface disabled
A tick tells you a check passed. It does not tell you whether the field was proven by a signature the issuing authority put there, or merely found to be well-formed. Those are different facts, and only one of them survives being questioned. A well-formed identifier belonging to nobody passes a format check every time.
When an auditor asks, three years later, how a particular customer came to be identified, the record has to answer on its own. Ours carries the provenance of every field, the journey it followed, the stages that journey required — and, by name, the stages it deliberately did not.
Your official opens the session and admits the customer, who joins from a single-use link and signs in to nothing.
Captured against a one-time code, read aloud on the call.
Signed payload decoded, signature checked against a named anchor.
Live capture and face match — value, scale and threshold together.
An active challenge the customer performs on camera.
Drawn at random, asked on the call, judged by the official.
Recording sealed with a SHA-256 chain; evidence pack exported.
“Online KYC” is not one flow. Some run in the product, some run on a licence you already hold and no vendor can hold for you, and some are delivered with a specialist. The table says which, per flow, so a deployment can be planned rather than discovered.
| Flow | How it is delivered | What it is |
|---|---|---|
| V-CIP (video-based customer identification) | Included | A live video session between your official and your customer: consent against a one-time code, identity payload, live photograph and face match, liveness challenge, randomised question, and a retained recording with a hash chain. Runs end to end and produces the verification record. Your trained official, operating from your premises under your audit, is what makes a deployment compliant — the product carries the process and the evidence. |
| Offline Aadhaar — Secure QR | Included | The signed QR on an eAadhaar printout or PVC card. Decoded, decompressed, and the RSA signature checked against a named anchor before any field is read. Needs no UIDAI licence, which is why it is the primary identity path here. A signed field cannot be misread the way an extracted one can. Verified against the issuing authority's key in your own deployment. |
| Offline Aadhaar — paperless e-KYC XML | Included | The share-code protected archive your customer downloads from UIDAI, holding an XML document signed by the issuer. The share code gates access; the signature gates extraction. Also licence-free, and the second of the two routes that let you read Aadhaar data without holding an AUA/KUA agreement. |
| Digital KYC — officer captured | Included | The PMLA-defined flow: your officer captures a live photograph of the customer, geo-tagged and timestamped, with the officer's own identity on the record. Photograph, coordinates and attribution are captured and carried. Coordinates are recorded as the browser reported them; enforcing a boundary is a deployment decision we wire to your rules rather than assume. |
| Passport (machine-readable zone) | Included | A TD3 zone validated in full against its own check digits, so a misread fails loudly instead of becoming a permanent customer record. The zone is entered rather than read optically, which is the deliberate choice: check digits make a typing error visible, where an optical misread would be silent. |
| Indian identifier validation (PAN, GSTIN, CIN, LLPIN, DIN) | Included | Format and checksum validation, including the Aadhaar Verhoeff check digit, with every result carrying what it proves. Structural validity, reported as structural validity. Confirming an identifier against its registry is the row below, and the record never lets one be read as the other. |
| Re-KYC / periodic updation | Included | Risk-based re-verification — two, eight or ten years by customer risk category — run over the same V-CIP journey. The verification runs today. Scheduling and campaign management are driven from your own customer master, which is where the risk category and the due date already live. |
| Aadhaar OTP e-KYC | Your licence | An OTP to the Aadhaar-registered mobile; UIDAI returns demographics and photograph. Runs through your AUA/KUA licence — the credential is yours and could not be ours. Worth knowing before it is chosen as the default: for banks it yields limited KYC, with balance and annual-credit ceilings and conversion within a year, which is why the two offline routes above are the primary path here. |
| Aadhaar biometric e-KYC | Your licence | Fingerprint or iris capture on a UIDAI-registered device. Your AUA/KUA licence and your certified capture hardware. Yields full KYC where OTP e-KYC does not. |
| DigiLocker issued documents | Your licence | Issuer-signed documents fetched with the customer's consent, satisfying the officially-valid-document requirement. Your DigiLocker partner agreement. The trust model is the one this product is built on — an issuer signs, we verify, fields are read only if the signature holds — so the verification side needs no new machinery. |
| CKYC / CERSAI registry | Your licence | Search and download an existing KYC record by CKYC identifier, and upload newly created records. Your CERSAI registration, which every regulated entity holds and no vendor can hold on your behalf. We integrate to it and put the download on the record with its provenance. |
| PAN verification against the registry | Your licence | Confirming a PAN and its name match against a permitted channel, and PAN–Aadhaar linkage status. Your agreement with the permitted channel. The identifier's checksum is validated here today; the registry confirmation is carried onto the record as a separate, stronger state. |
| Presentation-attack and deepfake detection | Partner | Detecting a replayed video, a mask or a synthesised face, beyond the active challenge the journey already runs. Delivered with a specialist engine, integrated behind an interface so it can be replaced, and reported with its version and its threshold on its own scale. On-premises capable engines exist and licensing one for your estate is part of the deployment conversation. |
| AML / CFT screening | Partner | Sanctions and PEP screening, adverse media, and ongoing monitoring. Screening is a licensed-data business rather than a software one, and most regulated entities already run a system for it. We call yours at the right point in the journey and carry the result onto the record with its provenance — rather than asking you to buy a second one. |
| KYB / legal-entity onboarding | Roadmap | Company, LLP and partnership onboarding: registry data, beneficial-ownership identification, and KYC of the authorised signatory. The signatory's KYC runs on the V-CIP journey today, and CIN, LLPIN, DIN and GSTIN are validated. The entity flow around them, and beneficial ownership in particular, is committed work rather than a shipped feature. |
Every limit named on a row is also carried on the verification record itself, and the full scope statement is published in one place for your evaluation team.
Offline Aadhaar — the Secure QR and the paperless XML — is verified against a named anchor before a single field is read. Extraction can misread a character and write it permanently into a customer record. A signature check either holds or it does not.
Three states, kept permanently apart: cryptographically verified, structurally valid, and not looked for. They are never collapsed into a tick, and no route in this application can set an absence to a passing outcome.
Deploy on-premises or in your own India-region cloud. Any relay is named in advance for that deployment, and every session's record states which media path that session actually took.
This deployment has a relay configured: media may be carried through kyc.contetial.com, named in advance and reachable by both parties. Every session's record states which path it actually took.
A V-CIP deployment is not one vendor's product. Your AUA/KUA licence, your CERSAI registration, your DigiLocker agreement and your screening system are assets you already hold, and a vendor who offered to hold them for you would be describing something that cannot exist. We integrate to them and put the result on the record with its provenance.
Where the capability is a data or research business rather than a software one — sanctions screening, deepfake detection — we deliver it with a specialist, behind an interface, reported with its version and its threshold on its own scale. You are not asked to buy a second system you already run.
And every limit the product has is written down: on the record, inside the evidence pack, and on one published page your evaluation team can read before they meet us. A record read three years from now states its own limits without needing us to still exist.
Read the scope statementCases on this instance: 1