30 years of secure digital infrastructure — India · UAE · Africa · Canada · USA
Biometrics · eKYC · Digital identity

Identity proven in seconds, not days.

H.A.R.T. is XS Infosol’s AI identity platform — multi-modal biometrics, liveness detection, Aadhaar-backed eKYC and document validation, delivered through an API your onboarding flow can call today.

  • UIDAI-aligned
  • Data-localisation ready
  • India · UAE · Africa
H.A.R.T. · Verification Session live
Face match · ResNet-10199.9%
Liveness · anti-spoofPass
Document OCR · PANParsed
Aadhaar eKYC · UIDAIVerified
1:N deduplicationRunning
4821 7734 0916Blockchain-anchored UID issued
Verified
00:11s
ledger: 0x7f3a…c41e · permissioned fabric · immutable audit entry written
0%
Verification accuracy
0–80%
Cost reduction vs manual KYC
0+
XS deployments worldwide
0
Countries in production
Trusted by
TATA Communications TATA Teleservices Airtel Fortis Hospital Hindustan Unilever DLF Limited Mother Dairy Hero MotoCorp AEGIS Mead Johnson Clariant
The identity problem

Fragmented identity records cost more than the fraud they enable

Wherever identity is captured on paper, re-keyed and stored in silos, four failures follow — and every one of them lands on the operator, not the fraudster.

01

Duplicate & ghost identities

Fragmented records let one person hold many personas across channels. Without deduplication at the point of enrolment, the duplicate is discovered only after the loss.

02

Expanded attack surface

Identity documents scattered across branch folders, shared drives and third-party agents turn every collection point into a potential mass PII breach.

03

Regulatory exposure

GDPR, the DPDP Act 2023, HIPAA and data-localisation mandates all carry penalties for records you cannot account for — and consent you cannot evidence.

04

Operational drag

Manual verification turns a two-minute journey into a two-day one. Abandonment during onboarding is a revenue loss that never appears in a fraud report.

Platform

Enrol, verify, issue, authenticate — in one identity fabric

H.A.R.T. covers the full identity lifecycle, from first biometric capture to re-KYC years later, on a permissioned blockchain that makes the record tamper-evident.

Multi-modal capture

ISO-compliant facial photo, ten-finger fingerprints, dual-eye iris, palm vein and voice samples, plus document OCR — captured through supported devices or a mobile SDK.

FaceFingerprintIrisVoice

Deduplication & verification

ResNet-101 deep learning performs 1:N deduplication against the enrolled population, with cross-validation against national and statutory sources.

1:N dedupeUIDAIGSTN

Liveness & anti-spoofing

AI liveness detection separates a live subject from a photograph, replayed video, mask or deepfake before the match is ever attempted.

Passive livenessPresentation attack

Document intelligence

OCR extraction and validation for PAN, Voter ID, passport, driving licence and utility documents, with automated CAF generation for telecom onboarding.

OCRAuto-CAFTamper checks

UID issuance on ledger

A twelve-digit unique identifier anchored to a permissioned Hyperledger Fabric network with Byzantine fault tolerance, optionally bound to a secure smart card.

HyperledgerSmart cardVirtual UID

Authentication & integration

Biometric, smart card, OTP or multi-factor authentication exposed through REST and SOAP APIs, iOS and Android SDKs, with role-based access and immutable audit trails.

REST / SOAPMobile SDKRBAC
Identity lifecycle

What happens between a face and a verified account

The same five stages whether the subject is a SIM buyer at a retail counter or a citizen enrolling for a welfare scheme.

01

Identify

Biometrics and documents are captured to ISO standards through a device, kiosk or mobile SDK.

02

Verify

Liveness is confirmed, documents are parsed and validated, and the subject is deduplicated 1:N against the population.

03

Issue

A unique identifier is generated and anchored to the ledger, with a virtual UID or QR credential for day-to-day use.

04

Authenticate

Later transactions are authenticated by biometric, card, OTP or MFA — without re-collecting the underlying PII.

05

Govern

Consent, retention windows and automated re-KYC keep the record compliant for its whole life, with every access logged.

Onboarding economics

The business case is the queue you no longer have

Manual KYC costs are mostly labour and rework: forms re-keyed, documents chased, applications rejected and resubmitted. Automating the verification step removes the queue, and the queue is where the cost sits.

  • Days to seconds. Verification completes inside the customer journey instead of after it, so abandonment falls with the wait.
  • 60–80% cost reduction against manual KYC processing, as reported across H.A.R.T. deployments.
  • Fraudulent activations eliminated at source. Deduplication happens at enrolment, not in a monthly exception report.
  • Paperless by default. No physical forms to store, ship, digitise or lose — and no branch archive to secure.
Manual KYC vs H.A.R.T.
2–5 days→Under a minute
Paper CAF, re-keyed→Auto-generated CAF
Visual document check→OCR + source validation
Duplicates found later→1:N dedupe at enrolment
Consent on paper→Logged, timestamped, auditable

Figures reflect outcomes reported across H.A.R.T. deployments; your baseline is measured during the assessment.

Privacy architecture

Designed so the safest place for identity data is the platform

Identity systems fail on governance more often than on matching accuracy. H.A.R.T. is built around minimisation, sovereignty and provability — because those are the properties a regulator actually tests.

  • Zero-knowledge proofs. A relying party can be told that an attribute holds without receiving the underlying document or biometric.
  • Virtual and time-bounded credentials. Day-to-day authentication uses a virtual UID or expiring QR rather than the permanent identifier.
  • Data sovereignty by deployment. The platform runs in-country, on your infrastructure, to satisfy localisation mandates.
  • Immutable audit trail. Every enrolment, access and change is written to a permissioned ledger — provable, not merely logged.
Governance posture
Least-privilege access
Role-based control over who may enrol, view, match or export — enforced per record, not per screen.
Consent & retention
Purpose-bound consent captured at enrolment, with configurable retention and automated re-KYC scheduling.
Regulatory alignment
Built against UIDAI guidelines, RBI and TRAI requirements, GDPR, the DPDP Act 2023 and HIPAA where applicable.
Deployment sovereignty
In-country, on-premise or sovereign-cloud deployment with local government database integration in India, the UAE and Africa.
Where it runs

Wherever a person has to be proven to be who they claim

Telecom & SIM activation

Subscriber verification at the point of sale with auto-generated CAF, deduplication against existing connections and regulator-ready records.

Banking, NBFC & insurance

Account opening, loan origination and policy issuance with instant approval rules and a defensible KYC audit trail.

E-governance & welfare

Beneficiary enrolment, subsidy disbursement and voter registration where duplicate identities directly divert public money.

Healthcare

Patient identity resolution across facilities, so records merge correctly and treatment history follows the person, not the file.

Workforce access & attendance

Biometric access control and attendance for large or distributed workforces, including contractor and visitor management.

Border & public services

National-scale authentication for immigration, transport and citizen service delivery on a microservices architecture built to carry it.

Technical profile

National-scale architecture, integrated with two API calls

H.A.R.T. runs as containerised microservices on Docker and Kubernetes so it can be sized from a single-branch pilot to a population-scale programme — while the integration surface your developers see stays a simple REST API.

  • Low-code integration — REST APIs plus iOS and Android SDKs; most onboarding flows integrate in days, not quarters.
  • Configurable risk rules — an instant-approval engine you tune, so low-risk cases clear automatically and edge cases route to review.
  • Platform-native — hands off directly to SmartGuard for network onboarding and B.O.S.S. for subscriber activation.
Biometric modalitiesISO-compliant facial image, ten-finger fingerprint, dual-eye iris, palm vein, voice sample
MatchingResNet-101 CNN for 1:1 verification and 1:N deduplication; configurable thresholds per use case
Document sourcesAadhaar / UIDAI (CIDR-native), PAN, Voter ID, passport, driving licence; Passport Seva, Sarathi, GSTN cross-validation
LedgerPermissioned Hyperledger Fabric with Byzantine fault tolerance; immutable enrolment and access records
Credentials12-digit UID, virtual UID, time-bounded QR, high-security smart card
AuthenticationBiometric, smart card, OTP, MFA, API-based; RBAC with least-privilege enforcement
IntegrationREST SOAP iOS & Android SDKs, webhook callbacks, batch enrolment
DeploymentDocker / Kubernetes microservices; on-premise, sovereign cloud or air-gapped; in-country data residency
ComplianceUIDAI guidelines, RBI and TRAI requirements, GDPR, DPDP Act 2023, HIPAA, data-localisation mandates
Why XS Infosol

Identity is only useful when it connects to something

Verification into activation

Most eKYC vendors return a verdict and stop. H.A.R.T. hands the verified identity straight to SmartGuard for network access and B.O.S.S. for service activation — one journey, not three integrations.

Deployed where you operate

Live across India, the UAE and Africa with local government database integration and in-country deployment — not a single cloud region serving every market.

Thirty years of critical systems

XS Infosol has been building infrastructure that carriers and governments depend on since 1995. H.A.R.T. inherits that operational discipline, not a start-up roadmap.

Questions

Before you talk to sales

Wherever your regulator requires it to be. H.A.R.T. is deployed on your infrastructure — on-premise, in a sovereign cloud, or air-gapped — so identity data stays inside the jurisdiction. XS Infosol does not operate a central repository of your subjects’ biometrics.

The integration surface is a REST API plus iOS and Android SDKs, so a standard onboarding flow — capture, verify, return a decision — is typically working in a development environment within days. Longer timelines are usually driven by your own approval processes and connections to national databases, not by the platform.

Yes. Aadhaar eKYC is one verification source among several. In the UAE and African deployments, H.A.R.T. integrates with the relevant local government identity databases and document types, while the biometric capture, liveness, deduplication and ledger layers remain the same.

Liveness detection runs before matching and is designed to identify presentation attacks — printed photographs, replayed video, masks and synthetic media. Multi-modal capture raises the bar further, since an attacker must defeat several independent modalities in the same session. Thresholds are configurable so you can tune the balance between friction and assurance per use case.

Re-KYC is scheduled automatically against the retention and refresh rules you configure. Subjects due for revalidation are surfaced as a work queue, and the ledger records what was re-verified, when and by whom — which is normally the evidence a regulator asks for first.

Yes, and it is the recommended path. Assessments typically start with one branch, one retail channel or one district, measuring accuracy, throughput and drop-off against your current baseline before any commitment to a wider programme.

Next step

Measure H.A.R.T. against your current onboarding.

Request a platform assessment. We will benchmark verification accuracy, throughput and drop-off on a live pilot population, alongside the process you run today.

Pilot on one channel first In-country deployment Compliance review included