Every industry answers to someone — a regulator, a statute, a standard. Here is who, for each one we build for, and what we design for across all of them. It is written for the compliance officer who has to make the case internally, and it never claims a certification we do not hold.
Pick an industry. This is the landscape an engagement there typically has to respect — not legal advice, and not a list of things we are certified against. Which rules bind a build depends on the client’s licence and what the software does; their counsel decides, and we build to the answer.
Broking, distribution and depository operations — where the firm started, and where it ships products today.
Flagship · products shipping
| Industry | Who typically sets the rules | Speaks to |
|---|---|---|
| 01Capital markets & wealth |
| NSE · BSE · MCX · NCDEX · MSEI · NSDL · CDSL · CKYC · UPI · NEFT · RTGS · IMPS |
| 02Banking & lending |
| Account Aggregator · UPI · NACH · e-mandate · CKYC · Credit bureaus · Core banking systems |
| 03Insurance |
| Insurance repositories · TPA & hospital networks · Payment gateways · e-KYC · CKYC · Regulatory returns |
| 04Healthcare |
| ABDM · ABHA · HL7 FHIR · DICOM imaging · TPA & insurer portals · e-prescription |
| 05Manufacturing |
| PLCs & IoT gateways · OPC UA · MQTT · SAP · Tally · ERPs · GST e-invoicing · e-way bills · Barcode · RFID |
| 06Retail & e-commerce |
| ONDC · UPI & payment gateways · Marketplaces · Shipping aggregators · GST invoicing · WhatsApp Business |
| 07Logistics & supply chain |
| GPS & telematics · e-way bills · FASTag · ULIP · Carrier & courier APIs |
| 08Education |
| UPI & fee gateways · DigiLocker · APAAR · ABC IDs · Video conferencing · SMS · WhatsApp |
| 09Real estate & construction |
| RERA disclosures · Payment gateways · e-stamping · e-sign · Accounting systems |
| 10Agriculture |
| eNAM · AgriStack · Weather & satellite data · UPI · DBT · IoT field sensors |
| 11Hospitality & travel |
| OTAs & channel managers · Payment gateways · GST invoicing · WhatsApp Business · Food delivery platforms |
| 12Government & public sector |
| DigiLocker · API Setu · Aadhaar e-sign · UPI & payment gateways · GIGW guidelines |
01 · Flagship
Where the firm started, and the only industry we ship products for today.
We build software for SEBI-registered intermediaries. The regulatory obligations remain the intermediary's; our job is to make meeting them a property of the software. Controls are designed against SEBI's Cybersecurity and Cyber Resilience Framework — designed against, not assessed.
Member-side controls are owned by the broker. Venue connectivity certification is granted by each exchange after its own conformance testing; we are building to those specifications and have not completed certification on any venue yet.
Vault Backoffice carries DP operations against the same client master as the broking book. Depository integration for the wider platform is in progress; pledge and corporate-action flows are being built to the byelaws that apply to a DP.
Investra MFD is built for AMFI-registered distributors. Registration and the distributor's code of conduct stay theirs; the software is designed around how a registered practice actually has to work.
Bank-rail surfaces — UPI, NEFT, RTGS, IMPS — are designed to the RBI directions that apply to a tenant's use of them: IT governance, and payment aggregation where the use case brings it in.
AML rules, transaction monitoring, suspicious-transaction reporting workflows and record retention for the period the rules require — delivered through the compliance layer and provable from the audit trail.
The capital markets platform is pre-production. These describe its design; none of it has been assessed by a regulator or an auditor, and none of it is claimed as running.
Every industry
India’s Digital Personal Data Protection Act, 2023 reaches every industry on this page. Its obligations are being brought into force in phases; we design to the whole Act now rather than retrofit each part as it commences. This is what we design for — there is no certificate for it, and it does not replace your own counsel.
The Act asksConsent that is free, specific, informed and unambiguous, given after a clear notice — and as easy to withdraw as it was to give.
We designConsent stored as a record: who agreed, to what, for which purpose, and when. Withdrawal sits one step away, in the same place consent was given.
The Act asksPersonal data used for the purpose it was given for, and no more of it than that purpose needs.
We designEvery personal field carries its purpose in the schema. A field with no purpose is not collected.
The Act asksData erased once its purpose is served, unless a law requires it kept.
We designRetention rules held as configuration and run as scheduled jobs — not a request someone has to remember to make.
The Act asksReasonable security safeguards, and intimation of a breach to the Data Protection Board and to each person affected.
We designThe practices on the trust page, and an audit trail that lets a breach be scoped quickly. CERT-In's six-hour reporting runs alongside.
The Act asksAccess to a summary of their data, correction, erasure, grievance redressal and nomination.
We designBuilt as screens and workflows with an owner and a clock, not as an email address.
The Act asksVerifiable parental consent for anyone under eighteen, and no tracking or targeted advertising aimed at children.
We designAge and guardian flows designed in wherever children may be users — schools, learning apps, family accounts.
The Act asksA data fiduciary may use a processor only under a valid contract.
We designWhen we build or run a system for you, you are the fiduciary and we are your processor, under a written agreement. We act on your instructions.
Security safeguards are set out layer by layer on the trust page, alongside what we hold and what we do not yet.
The calendar our own systems are held to. Where an item needs a production system to act on, it says so.
For any engagement, in any industry. Documents go out under NDA.
Write to compliance@nexoratechnologiesnagpur.com with your compliance lead copied, and we will set you up.
Bring the forms, the registers and the workarounds. We will tell you plainly what we would build first, and what we would leave alone.
Or write to hello@nexoratechnologiesnagpur.com