Skip to content
FinHubBy HabileLabs

Aadhaar Masking API

AI-powered detection and redaction of Aadhaar numbers across PDFs, images and scans — in real time at capture or in bulk across your legacy estate, aligned to UIDAI guidance and RBI KYC norms.

masking · POST /v1/documents/mask
aadhaar · front.pdfpage 1/1
nameRAVI KUMAR
dob14/08/1991
genderMALE
uid4821 7396 5510
detect · first 8 digits

Capabilities

Built to find what a manual review misses

Masking one document is easy. Masking millions — reliably, across formats, without slowing onboarding — is the actual job.

AI-Powered Detection

Models trained on hundreds of millions of real-world documents find Aadhaar numbers and QR codes wherever they appear on a page — rotated, cropped or photographed.

95%+ Accuracy

Consistent detection and masking accuracy across document types, so exceptions are the rare case your ops team reviews — not the daily norm.

Every Format You Hold

PDFs, images and scans are all handled by the same endpoint — no pre-sorting documents by type before masking.

Real-Time at Capture

Mask documents the moment they enter your systems — around 300ms per file — so an unmasked Aadhaar copy never reaches storage.

Bulk Across the Estate

Batch jobs scan and transform thousands of legacy files at a time — proven on multi-terabyte document estates.

API, SDK or On-Premises

Integrate via REST API, mask at capture with the mobile SDK, or deploy on-premises where data residency demands it.

Why It's Mandatory

Masking isn't a nice-to-have — it's the rulebook

Indian regulators expect Aadhaar copies you store to show only the last four digits. Holding the full number in the clear is a standing liability.

UIDAI guidance

UIDAI has directed that stored or shared Aadhaar copies be masked so only the last four digits remain visible — the first eight digits must be concealed.

RBI KYC Master Direction

Regulated entities must ensure Aadhaar numbers are redacted or blacked out in the KYC documents they retain — masking at capture keeps every stored copy compliant.

DPDP data minimisation

India's DPDP Act expects you to hold only the personal data you need. Masking the identifier you don't need shrinks both your risk surface and your compliance burden.

Regulatory positions evolve — confirm current requirements with your compliance counsel. FinHub keeps masking behaviour aligned to prevailing UIDAI and RBI guidance.

Use Cases

One engine, three ways to deploy it

The same detection models run in real time, in bulk and on-device — so new capture and legacy cleanup converge on one masked estate.

Loan & KYC Processing

Mask Aadhaar in application and KYC documents as they're captured, before they touch your LOS or document store.

  • Real-time masking inside onboarding and lending journeys
  • Works alongside OCR and verification in the same pipeline
  • Masked output lands in storage — never the raw copy

Legacy Estate Cleanup

Transform years of historical unmasked records in one automated, auditable bulk run.

  • Batch jobs across archives, DMS folders and object storage
  • Proven on 25+ TB estates and millions of documents
  • Progress and exception reporting for your compliance team

Mobile Capture

Mask images the moment field agents or customers photograph them in your app.

  • SDK masks on-device before upload
  • No unmasked Aadhaar image ever leaves the phone
  • Same accuracy models as the server-side API

Getting Started

From first call to a fully masked estate

Start with new capture, then work backwards through the archive — most institutions are fully masked within weeks, not quarters.

1

Pick your deployment

Real-time API for new capture, bulk jobs for legacy data, SDK for mobile — or all three against the same models.

2

Integrate the endpoint

One REST call in, masked document out. Most teams are processing files in under a day.

3

Run the backlog

Point a bulk job at your legacy estate and watch masked files replace unmasked ones, with a report per batch.

4

Stay compliant by default

Every new document is masked at capture, with an audit record your compliance team can produce on inspection.

Proven at Scale

Production numbers, not benchmark claims

The same engine runs today inside housing finance companies, NBFCs and small finance banks across India.

Masking Engine Overview

Live

250M+

Documents Masked

95%+

Detection Accuracy

~300ms

Avg. Processing Time

FAQ

Aadhaar Masking API — FAQs

Common questions about masking Aadhaar documents at scale.

The first eight digits of the 12-digit Aadhaar number are concealed, leaving only the last four visible (for example, XXXX XXXX 5510). That's enough to reference a record without exposing the full identifier, and it's the form UIDAI expects for stored or shared copies.

Explore More

Masking works best inside a full KYC pipeline

Mask your estate before the audit asks

Talk to our team about a pilot — real-time masking on new capture, plus a scoped bulk run on your archive.