KYC · KYB · AML · Transaction monitoring

Verify faster.
Reduce risk.
Stay compliant.

One platform for digital onboarding with DigiLocker and CKYCR, company checks against MCA21 and GSTN, screening against the official sanctions lists, explainable risk scoring and transaction monitoring. Built for banks, NBFCs, fintechs, marketplaces and enterprises in India and beyond.

  • 6official sanctions lists, refreshed nightly
  • 15 minencrypted backups, restore-tested daily
  • 3deployment models

Built for regulated and growing businesses

  • Banks & NBFCs
  • Fintech
  • Marketplaces
  • Enterprises
  • EdTech
  • HealthTech
  • Real estate
  • Government

The platform

Everything from the first selfie to the final STR

Five modules that share one customer record, one risk engine and one audit trail. Use them together or one at a time.

Individual KYC

Self-service links with one-time codes, DigiLocker e-Aadhaar and PAN, ID reading with checksum and MRZ checks, a camera liveness challenge and face match. Low-risk customers clear automatically.

AML screening

Official OFAC, UN, EU, UK and MHA (UAPA) lists refreshed every night, plus PEP and adverse-media providers. Matching handles spellings, transliterations and aliases, with every score explained.

Business KYB

MCA21 company status and directors, GSTN registration and PAN checks through API Setu, certificates read and matched, and beneficial owners traced through holding companies.

Transaction monitoring

Batch or API ingestion checked against threshold, structuring, velocity, geography and rolling-volume rules. Backtest a change, then a second reviewer approves it before it goes live.

Compliance management

Related alerts grouped per customer and worked in one go, SLAs, case workspaces, CDD/EDD, maker-checker approvals, monitoring suppressions and validated STR packages.

India-ready integrations

Verified at the source

Where a government record exists, Webyne checks it directly instead of trusting a photo.

DigiLocker

Customers share their e-Aadhaar and PAN with consent. Webyne checks the UIDAI signature and stores the Aadhaar number masked.

CKYCR · CERSAI

Search and download existing Central KYC records with the customer's consent. Requests are encrypted and signed both ways.

MCA21

Checks company and LLP status, registered name and incorporation date. Directors on record are reconciled with the ones you were told about.

GSTN

Checks that the GSTIN is active, matches its legal name, and that the PAN inside it belongs to the company.

Income Tax PAN

Confirms PAN validity, with name and date-of-birth matching where returned.

Official sanctions lists

OFAC SDN and Consolidated, UN, EU, UK and MHA UAPA lists, imported from the publishers every night with version history.

PEP & adverse media

Connect OpenSanctions or ComplyAdvantage. Their results are re-scored with the same explainable matcher.

Payments, e-mail & SMS

Razorpay for paying invoices online. SMTP, Twilio or MSG91 for codes and invitations, in your own wording and brand.

Government and provider integrations go live once the relevant authorisations and credentials are in place – your own, or Webyne's where permitted.

How it works

Four steps from sign-up to ongoing monitoring

Low-risk customers clear on their own. Everyone else reaches the right reviewer with the evidence already gathered.

  1. 01

    Onboard

    Send a secure link or onboard in branch. Customers verify their e-mail or mobile, give versioned consent, and share documents from DigiLocker or their camera.

  2. 02

    Verify

    Documents are read and checked, and a liveness challenge and face match confirm the person. Companies are checked against MCA21, GSTN and PAN, then directors and UBOs are reconciled.

  3. 03

    Screen and score

    Explainable list matches feed a versioned risk policy that returns reason codes and a decision route.

  4. 04

    Monitor

    Nightly re-screening alerts only on new hits, transaction rules raise alerts, related alerts are grouped, and periodic reviews stay on schedule.

Security and audit

Built to be inspected

Regulators and auditors ask why a customer was approved. Webyne keeps the answer: the inputs, the list versions, the policy version and who decided.

Tamper-evident audit trail

Every action is chained to the one before it with SHA-256, so any edit to history is detectable.

Maker-checker

High-risk approvals, STR filing and policy changes need a second, senior reviewer.

Encrypted by default

ID numbers and documents are encrypted at rest. Documents open only through short-lived signed links.

Fails safe

If a verification provider is down, the customer goes to manual review. Nobody is approved by default.

Privacy by design

Versioned consent, data-principal requests with deadlines, legal holds, and automatic erasure once the PMLA retention period ends. Aligned with the DPDP Act 2023.

SSO and two-step sign-in

Sign in with Microsoft Entra ID, Google, Okta or any OpenID Connect provider. Approvers and admins always need a second factor.

Scanned and private

Every upload is virus-scanned before it is stored. Documents and selfies are checked on Webyne's own servers, never sent to an outside AI service.

Recoverable to the minute

Encrypted backups every 15 minutes with point-in-time recovery and off-site copies. A full restore is rehearsed automatically every day.

Watched around the clock

Health checks, Prometheus metrics with alert rules, and audit-trail export to your SIEM (Splunk, Elastic or syslog).

Deployment

Your infrastructure. Your compliance platform.

Run Webyne the way your regulator, auditors and security team need it.

SaaS on Webyne Cloud

Fast start with nothing to manage. Multi-tenant and isolated by design.

Live in days

Dedicated private cloud

Your own database, storage, network and encryption keys, operated by Webyne.

Single tenant

On-premises

Deploy inside your own data centre or private cloud with full control of residency and access.

Your data centre

API-first

Integrate in days, not quarters

Add KYC, KYB, screening and monitoring to your website, app, ERP, CRM or LOS/LMS through REST APIs and signed webhooks. Idempotent writes, clear errors and OpenAPI documentation come as standard.

  • REST API
  • OAuth 2.0 client credentials
  • API keys
  • Signed webhooks
  • Zero-downtime key rotation
  • OpenAPI docs
  • Idempotency keys
  • SIEM export
  • Prometheus metrics

Your brand, end to end

Applicants see your logo, colours, support contacts and your own wording in every e-mail and SMS. Your team works in the same branded workspace.

Read the API reference
screening.sh
# Screen a person against sanctions, PEP and adverse media
TOKEN=$(curl -s -u "$CLIENT_ID:$CLIENT_SECRET" -d grant_type=client_credentials \
  https://comply.webyne.com/api/v1/oauth/token | jq -r .access_token)
curl -X POST https://comply.webyne.com/api/v1/screenings \
  -H "Authorization: Bearer $TOKEN" \
  -d '{"name":"Alexei Petrov","dob":"1985-03-14","nationality":"RU"}'

# 201 Created
{
  "status": "potential_match",
  "matches": [{
    "source": "OFAC SDN (official)",
    "list_version": "2026-09-30",
    "score": 98.0,
    "features": { "jaro_winkler": 0.97, "dob": "match" }
  }]
}

Pricing (introductory)

Plans that grow with your volumes

Monthly prices, excluding GST.

Starter

For small businesses

₹24,999/month + GST

  • Up to 1,000 verifications a month
  • Basic screening
  • Standard support
Choose Starter
Most popular

Professional

For growing businesses

₹49,999/month + GST

  • Up to 5,000 verifications a month
  • Advanced screening
  • Transaction monitoring
  • API access
  • Priority support
Choose Professional

Enterprise

For large organisations

₹99,999/month + GST

  • Custom volume
  • Full feature access
  • Custom risk policies
  • Dedicated support
  • SLA available
Choose Enterprise

Every plan includes official sanctions lists, your own branding, SSO and two-step sign-in, the full audit trail, and monthly GST invoices with usage detail that you can pay online.

Verification, government-database, biometric, AML/watchlist and other third-party provider charges may be billed separately based on actual usage.

FAQ

Questions, answered

Something else on your mind? Write to sales@webyne.com.

How long does it take to go live?

SaaS customers can start in the sandbox right away and go live once their compliance policy and provider contracts are in place. Dedicated and on-premises deployments are planned with your infrastructure team.

Can we use our existing KYC or screening providers?

Yes. Webyne connects document, biometric, registry and screening vendors through adapters, so you can bring your own contracts or switch providers without changing workflows.

Do you work with DigiLocker, CKYCR, MCA and GSTN?

Yes. Customers can share their e-Aadhaar and PAN from DigiLocker. Your team can search and download CKYC records. Companies are checked against MCA21 and GSTN, and PANs with the Income Tax Department, through API Setu. Each integration is switched on with the required authorisation: CKYCR needs your CERSAI FI code, for example.

Can our customers see our brand instead of Webyne's?

Yes. Your logo, colours, support contacts and e-mail footer appear on the verification pages and in every message. You can edit the wording of invitations, one-time codes and confirmations yourself.

Can we sign in with our company accounts?

Yes. Single sign-on works with Microsoft Entra ID, Google Workspace, Okta and other OpenID Connect providers. You can require it for your whole team, and people with approval rights always need a second factor.

Does AI make compliance decisions?

No. Automation can help with matching and triage, but legally required decisions rest on your configured policy and human review. High-risk approvals use maker-checker controls.

Where is our data stored?

On Webyne Cloud by default, or in your own dedicated cloud or data centre. Identifiers and documents are encrypted, and documents and selfies are checked on Webyne's own servers rather than sent to outside AI services. Backups are encrypted, kept off-site and restore-tested every day. Every access is role-based and audited.

Can we file STRs from the platform?

Webyne prepares a validated STR/SAR package from the case narrative, linked alerts and transactions. After MLRO approval you map it to your FIU's filing format and submit it.

Book a demo

Compliance built for what's next

Tell us about your customers, volumes and timelines. We'll set up a demo around your use case.

  • Walkthrough of KYC, KYB, screening and monitoring
  • Sandbox access for your developers
  • Pricing for your expected volumes

Prefer email? sales@webyne.com

We use these details only to contact you about Webyne Compliance Cloud.