generated: '2026-08-04' method: probed source: live probes of every KreditBee host plus the public site, sitemap and GitHub org note: >- Conformance is asserted only where a fetched document proves it. KreditBee publishes no OpenAPI, no AsyncAPI, no GraphQL surface, no developer portal, no API reference, no SDKs and no /.well-known document, so nearly every cross-cutting standard below is recorded as not-evidenced rather than as a failure. KreditBee is a regulated Indian lender and is subject to RBI Digital Lending Guidelines and the DPDP Act as a matter of law; that is a legal obligation, not a published certification, so no compliance claim is recorded here and no `Compliance` pointer is emitted. No SOC 2, ISO 27001, PCI DSS or equivalent attestation was found on any public KreditBee page. standards: - id: openapi conforms: false evidence: >- No OpenAPI or Swagger document found. Probed /openapi.json, /openapi.yaml, /swagger.json, /v1/openapi.json, /api-docs, /v2/api-docs, /docs and /redoc against www.kreditbee.in, kreditbee.in, api.kreditbee.in, dsa.kreditbee.in and www.krazybee.com. The web hosts return an HTML SPA shell (catch-all 200); api.kreditbee.in returns 403 ForbiddenException. - id: asyncapi conforms: false evidence: no event, streaming or webhook surface is published or documented - id: graphql conforms: false evidence: no /graphql endpoint found on any resolving KreditBee host - id: mcp conforms: false evidence: no hosted Model Context Protocol server advertised or discoverable - id: a2a conforms: false evidence: >- /.well-known/agent-card.json and /.well-known/agent.json return the SPA HTML shell on every web host and 403 on api.kreditbee.in — no AgentCard document exists - id: oauth2 conforms: false evidence: not evidenced — no authorization server metadata published on any host - id: oidc-discovery conforms: false evidence: >- /.well-known/openid-configuration returns text/html on every web host and 403 on api.kreditbee.in; no discovery document exists - id: rfc8414-authorization-server-metadata conforms: false evidence: /.well-known/oauth-authorization-server returns no JSON on any host - id: rfc9728-protected-resource-metadata conforms: false evidence: not evidenced - id: rfc9116-security-txt conforms: false evidence: >- /.well-known/security.txt returns the SPA HTML shell (200, text/html) on the web hosts and 403 on api.kreditbee.in — no RFC 9116 document is served - id: rfc8615-well-known-uris conforms: false evidence: no /.well-known document of any kind is served - id: rfc9457-problem-details conforms: false evidence: not evidenced — no public error contract is published - id: rfc8594-sunset-header conforms: false evidence: not evidenced — no versioning or deprecation policy is published - id: llmstxt conforms: false evidence: /llms.txt returns the SPA HTML shell on every host — not a published llms.txt - id: robots-txt conforms: true evidence: >- https://www.kreditbee.in/robots.txt returns 200 text/plain with 23 Disallow rules and a Sitemap directive - id: sitemaps-org conforms: true evidence: https://www.kreditbee.in/sitemap.xml returns a valid urlset with 741 entries - id: https-tls13 conforms: true evidence: every reachable KreditBee host negotiates TLSv1.3 - id: rfc6797-hsts conforms: true evidence: Strict-Transport-Security max-age=31536000 on www.kreditbee.in, api.kreditbee.in and www.krazybee.com - id: rfc6844-caa conforms: true evidence: kreditbee.in publishes CAA records naming six issuers note: krazybee.com publishes no CAA record - id: dnssec conforms: false evidence: no DNSKEY on kreditbee.in or krazybee.com - id: rfc7208-spf conforms: true evidence: both kreditbee.in and krazybee.com publish a v=spf1 record ending -all - id: rfc7489-dmarc conforms: true evidence: both domains publish DMARC at p=quarantine with rua and ruf reporting note: p=quarantine rather than p=reject regulatory: regime: India — Reserve Bank of India entities: - name: Finnovation Tech Solutions Private Limited role: platform operator (Lending Service Provider) identifier: CIN U74900KA2016PTC086953 source: https://www.kreditbee.in/ footer - name: KrazyBee Services Limited role: in-house RBI-registered NBFC (Systemically Important, Non-Deposit Taking) source: 'https://www.krazybee.com/ — page title: "KrazyBee Services Limited NBFC registered with RBI."' published_pages: - {page: https://www.kreditbee.in/security-center, title: 'KreditBee Security Centre - FACE & Code of Conduct'} - {page: https://www.kreditbee.in/grievance-redressal} - {page: https://www.kreditbee.in/responsible-lending} - {page: https://www.kreditbee.in/corporate-info} note: >- These pages are listed in the provider's own sitemap.xml, but every one of them is client-rendered — the origin returns the same 9,646-byte HTML shell it returns for a nonexistent path — so their contents could not be read by an unauthenticated, non-JavaScript fetch and nothing is asserted about what they say. compliance_program: published: false trust_center: null certifications: [] note: >- No trust.kreditbee.in or security.kreditbee.in (neither resolves), no bug bounty on HackerOne/Bugcrowd/Intigriti, no security.txt, and no named SOC 2 / ISO 27001 / PCI DSS certification found on any public page or in any public source. The company's /security-center page is a consumer fraud-awareness and FACE code-of-conduct page by its own title, not a security or compliance attestation surface. x-evidence: fetched: '2026-08-04' probes: - {url: 'https://www.kreditbee.in/robots.txt', http_status: 200, content_type: text/plain} - {url: 'https://www.kreditbee.in/sitemap.xml', http_status: 200, content_type: application/xml} - {url: 'https://www.kreditbee.in/openapi.json', http_status: 200, content_type: text/html, note: SPA shell} - {url: 'https://www.kreditbee.in/.well-known/security.txt', http_status: 200, content_type: text/html, note: SPA shell} - {url: 'https://www.kreditbee.in/.well-known/agent-card.json', http_status: 200, content_type: text/html, note: SPA shell} - {url: 'https://www.kreditbee.in/nonexistent-page-xyz123', http_status: 200, content_type: text/html, note: 'control — identical shell'} - {url: 'https://api.kreditbee.in/', http_status: 403, content_type: application/json} - {url: 'https://api.kreditbee.in/openapi.json', http_status: 403} - {url: 'https://api.github.com/orgs/krazybee/repos', http_status: 200, note: '9 public repos, all forks of third-party open source; no first-party API artifact'} - {url: 'https://kreditbee.statuspage.io', http_status: 200, note: 'redirects to atlassian.com marketing — no KreditBee status page exists'}