Protean SurakshAA
Applications

Protean SurakshAA

10K+Downloads
iOSPlatform
AndroidPlatform
RBICompliance

About Protean SurakshAA

Protean SurakshAA is India's RBI-licensed Account Aggregator (AA) mobile app developed by Protean Account Aggregator Ltd., a part of Protean eGov Technologies Ltd.

It empowers individuals and businesses to securely control and consent to sharing their financial data — such as bank accounts, investments, insurance, and pensions — with authorised service providers only after explicit permission, without ever storing that data.

  • 🛡️ RBI-regulated consent-driven sharing
  • 🔐 End-to-end encrypted transmission
  • 📊 Link multiple financial accounts
  • 🤝 Share with lenders, insurers, wealth managers
  • 📱 iOS & Android

Vision: To give users full visibility and control over their own financial data — when it's requested, by whom, and for what purpose — while keeping their information private and secure.

How It Works

User Onboarding & Account Linking

Secure Registration

User registers with basic identity details (phone/email). Authentication and secure session management keeps user access protected throughout the lifecycle.

Firebase AuthOTP VerificationSecure session tokens

Financial Account Linking

Users link their financial accounts (bank accounts, mutual funds, pensions) via bank-level authentication (OTP/secure login). A unique AA handle is created — a digital identity representing the user's consent profile.

AA Handle generationBank-level OTP authFlutter UI

Consent-Driven Data Sharing

The Trust Layer — FIP → AA → FIU

Protean SurakshAA acts as a secure broker: Financial Information Providers (FIPs) hold source data; Financial Information Users (FIUs) request access for services like loans; the AA orchestrates transfer only after explicit user consent — never reading or storing the data.

Account Aggregator protocolRBI AA frameworkConsent Artefact

Consent Flow

FIU sends a data request → AA notifies the user → user approves or rejects → upon approval, AA fetches encrypted data from FIP → encrypted data is securely transmitted to FIU. At no point does the AA store or read this data — it simply acts as a pipe.

Encrypted data relayConsent ledger loggingPush notifications (FCM)

Security & Compliance

End-to-End Encryption & RBI Compliance

Data is encrypted both in transit and at the endpoints — only authorised recipients can decrypt it. The entire ecosystem operates under RBI's regulatory framework with strict compliance to financial data norms.

TLS encryptionRBI AA regulationDigital signature validation

Consent Ledger & No Persistent Storage

Every consent decision (grant/revoke) is logged in a secure, auditable ledger. Unlike traditional finance apps, SurakshAA never stores user financial data centrally — it fetches and passes encrypted data only upon consent.

Immutable consent ledgerZero persistent financial data storageAudit trail

Ecosystem Architecture

Component Overview

User's Financial Accounts (FIP) → Protean SurakshAA (AA, secure broker) → Service Provider (FIU). User links accounts, FIU requests data, user gives consent, AA fetches encrypted data from FIP and forwards to FIU. At every step, the user is in control.

Flutter (iOS & Android)FirebaseRBI AA APIsEncrypted data relay

Technologies

Flutter
Dart
iOS
Android
Firebase
RBI AA Protocol
Encryption
FCM

Project Screenshots

Protean SurakshAA screenshot 1