← Home

For citizens

Your identity. Your control.

If you bank, insure, or receive healthcare in India, your identity is anchored by government-issued credentials — and shared every day with institutions you trust. SEC@R puts you in charge of how that identity is used.SEC@R is the citizen-facing layer of Infinicue's trust platform. Download the mobile app, pair SEC@R-certified hardware, and decide — purpose by purpose — when your bank, insurer, or hospital may use your identity utility. Your Aadhaar, PAN, passport, and other credentials stay with you and the issuing authority; SEC@R never stores them.

Sectors

If you are a customer of

Banking

Secure logins, card transactions, internet banking, UPI, and loan journeys — without repeatedly sharing full KYC packs. You approve each trust request from your app.

Insurance

Claims and policy changes verified with your consent — not by emailing copies of ID documents across channels.

Healthcare

Hospital visits and health-record access gated by your device and explicit consent, reducing identity fraud and medical record misuse.

Banking

Banking services you control

SEC@R protects everyday banking touchpoints — not just identity documents. Each service wakes up only after your trusted device and consent approve the request.

Debit & credit cards

Card-not-present payments, new card activation, and limit changes — verified with your device and explicit consent before card data utilities activate.

Internet banking

Web logins and high-risk banking actions gated by hardware trust instead of OTP alone — your session stays dormant until you approve.

Online payments & UPI

UPI, net banking, and payment-gateway authorizations require real-time consent. Fraud Indicator Check flags unusual payees before money moves.

Mobile banking

App logins, fund transfers, and beneficiary additions verified on your phone with paired SEC@R hardware — not just a password.

Loan & credit applications

Personal, home, and business loan journeys activate identity utilities only for the lender and purpose you approve — no open-ended KYC sharing.

Account opening & KYC

New savings, salary, or NRI accounts verified with purpose-bound Aadhaar, PAN, and address utility — not full document uploads to every branch.

Identity issued by authorities

Your official credentials are issued by government bodies — not by your bank or hospital. SEC@R helps you share only what is needed, when it is needed, without handing over full document copies each time.

Aadhaar

UIDAI

National identity number issued by the Unique Identification Authority of India.

PAN

Income Tax Department

Permanent Account Number for tax and financial identity.

Passport

Passport Seva

International travel identity issued by the Ministry of External Affairs.

Driving licence

Regional Transport Offices

State-issued licence linked to your motor-vehicle identity.

Digital signatures

SEC@R BLE DSC Token — consent-gated digital signatures

Digital signature theft and misuse are rising — stolen USB tokens, unattended CA workstations, and remote signing without the holder's knowledge. SEC@R binds your DSC to your mobile so every signature needs your explicit consent.

The problem

A traditional DSC USB token signs whenever it is plugged in and the PIN is entered. If the token is stolen, cloned, or left with a Chartered Accountant, anyone with physical access can sign documents in your name — with no notification to you.

The SEC@R solution

The SEC@R BLE DSC Token adds a second trust layer: the token must be BLE-paired with the rightful owner's SEC@R mobile app. Before any document is signed, the owner receives a push notification with the reason, document summary, and requesting party — and must grant consent on their phone.

How fraud is prevented

Stolen token is useless alone

Without BLE proximity to the owner's paired mobile, the private key remains locked. A thief cannot sign remotely even with the USB token and PIN.

CA cannot sign without you

When your Chartered Accountant connects the token to sign returns or filings, your phone must be present and you must approve each request with the stated reason.

Real-time signing alerts

Every signing attempt triggers an instant notification — who is requesting, which document, and why. Deny suspicious requests in one tap.

Revoke instantly

Lost token or ended CA engagement? Unpair or quarantine the device from the SEC@R app. All pending and future signatures are blocked immediately.

Immutable audit trail

Each consent grant, denial, and signature event is cryptographically logged with timestamp, reason, and device attestation — admissible for compliance and dispute resolution.

No silent remote signing

Signing over RDP, shared desktops, or unattended machines fails unless the owner's mobile confirms proximity and consent in real time.

Consent-gated signing flow

  1. Pair token to your mobile

    Enroll the SEC@R BLE DSC Token in the mobile app. Only your phone can authorize signatures on this token.

  2. CA connects token to workstation

    Your Chartered Accountant plugs the USB token into their laptop to prepare a signing session — e.g. ITR filing or GST return.

  3. You receive a consent request

    Your phone shows who is asking, the document type, purpose, and hash summary. The token will not sign until you review and approve.

  4. Grant or deny permission

    Tap Approve to release the signature for that specific document, or Deny to block it. You can set time-bound consent for a batch of related filings.

  5. Signature executes with dual trust

    USB possession + BLE proximity + explicit consent must all pass. The signed document and audit record are available to you and your CA.

Business owners & directors

Keep DSC signing under your control even when a CA handles compliance — you see and approve every use.

Chartered Accountants

Prepare and submit filings efficiently while your client retains cryptographic control and receives transparent signing requests.

Company secretaries & compliance teams

Govern board resolutions, ROC filings, and contract signing with purpose-bound consent instead of shared token custody.

How SEC@R protects you

You approve every use

Institutions request a trust signal or data utility — you see who is asking, why, and for how long. Revoke access anytime from the app.

No document vault on our servers

SEC@R does not store Aadhaar, PAN, passport images, passwords, or account numbers. Only opaque IDs and cryptographic proofs flow through the platform.

Hardware-backed trust

FIDO2 keys, BLE DSC tokens, smart rings, wallets, and BLE card holders prove it is really you — not a stolen OTP, cloned SIM, or misused digital signature token.

DPDP-aligned rights

Access, correction, erasure, and consent withdrawal are built in. SEC@R operates as a Consent Manager for purpose-bound data utility sharing.

Your SEC@R toolkit

SEC@R mobile app

Available on iOS and Android through participating banks and partners. Manage devices, review consent requests, and see your trust activity in one place.

Request app access

SEC@R hardware

Purchase certified devices — smart ring, wallet, watch, USB security key, BLE DSC token, or BLE card holder — and enroll them in minutes from the app.

Shop hardware

Certified hardware

How it works

  1. Get the app

    Install SEC@R from your bank's portal or partner link. Sign in with the phone number your institution already knows.

  2. Buy & pair hardware

    Choose a SEC@R-certified device. Pair it over Bluetooth and complete a quick FIDO2 enrollment — your biometrics never leave your phone or key.

  3. Link identity utilities

    When your bank or insurer needs to verify Aadhaar, PAN, or passport, you authorize a one-time or time-bound utility — not a full document upload.

  4. Stay in control

    Review active consents, pause sharing, or withdraw permission. Every grant is logged and auditable under India's DPDP Act.

You stay the data principal

Under India's Digital Personal Data Protection Act, you have the right to know what is shared, withdraw consent, and demand correction or erasure. SEC@R is designed as your Consent Manager — not another database of your personal documents.

  • See every institution that requested your trust
  • Time-bound consent — not open-ended sharing
  • Revoke access in one tap
  • Cryptographic audit trail for every grant