DEV Community

Manu Shukla
Manu Shukla

Posted on • Originally published at ecorpit.com

WealthTech app development in India: a 2026 guide to SEBI-ready broking and investment apps

WealthTech app development in India: a 2026 guide to SEBI-ready broking and investment apps

Summary. India had about 22.9 crore demat accounts by May 2026, roughly 18.38 crore at CDSL and 4.51 crore at NSDL, against nearly 13.1 crore unique registered investors on the NSE. That base did not just grow, it changed shape: the SEBI (Stock Brokers) Regulations, 2026 took effect on January 7, 2026 and repealed the 1992 rulebook, the retail algorithmic trading framework starts on April 1, 2026, and 91% of individual traders in equity derivatives lost money in FY24-25, with net losses widening 41% to ₹1.05 lakh crore. Building a broking or investment app in this market is now as much a compliance and data-engineering problem as a product one. This guide sets out the rules, a reference architecture, the market-data and cybersecurity work, and where the real cost sits.

Why India's WealthTech market is large and unforgiving

The scale is the easy part to state. CDSL reported about 18.38 crore active demat accounts by May 2026, after adding 2.72 crore accounts in FY26, and NSDL added 59.3 lakh gross accounts in the same year, its highest annual addition, taking it to 4.51 crore accounts across 315 depository participants and 57,065 service centres. Together that is close to 22.9 crore accounts, though the number of real people is smaller because one investor can hold several accounts.

Economics for the end user have collapsed to near zero. Zerodha, Groww, Angel One and Upstox all offer zero brokerage on equity delivery and a flat ₹20 per executed order on intraday, futures and options, so a new app cannot win on price alone. Groww is now the largest platform by active users. Zerodha still charges ₹300 a year for demat account maintenance, higher than several rivals, and keeps its lead on its Kite platform rather than on fees.

The unforgiving part is what happens to users after they trade. A SEBI study covering December 2024 to May 2025 found that 91% of individual traders in the equity derivatives segment lost money in FY24-25, the second straight year of that pattern, with the average per-person loss around ₹1.1 lakh. SEBI Chairman Tuhin Kanta Pandey, who took charge in March 2025, described a derivatives market skewed toward institutional players and said plainly, "It cannot be a one-way street." An app built for this market has to treat suitability, risk disclosure and cooling-off design as first-class product decisions, not afterthoughts.

Broker Equity delivery brokerage Notable detail
Zerodha Zero ₹300 annual demat AMC; Kite platform
Groww Zero Largest by active users; lifetime zero AMC
Angel One Zero Flat ₹20 per order on intraday and F&O
Upstox Zero Flat ₹20 per order on intraday and F&O
ICICI Direct Varies by plan AMC up to ₹700 a year on some plans

The 2026 regulatory reset every builder has to design for

The SEBI (Stock Brokers) Regulations, 2026 replaced a framework that had stood since 1992. For anyone shipping software into this space, several provisions change how the product and its back office have to work.

Registration now routes through a recognised stock exchange, and SEBI checks eligibility, infrastructure, experience, fit-and-proper status, NISM certification and minimum net worth. Applicants must show at least two years of experience dealing in securities, and the broker must have a designated director who stays in India for at least 182 days a year. Investor grievances have to be addressed within 21 calendar days, a compliance officer must monitor adherence and report material non-compliance to the exchange, and client funds and securities have to be segregated from the broker's own accounts. Record-keeping is specific: a register of transactions (the Sauda Book), client and general ledgers, cash and bank books, a register of securities, and copies of every contract note issued.

The line that matters most for app teams: algorithmic tools and third-party trading apps have to be registered and approved by the exchanges, and brokers must map every trade to a client-specific code and avoid discretionary trades without client authorisation. In practice, the "move fast" defaults of consumer software do not survive contact with these rules. Order tagging, immutable audit trails and exchange approval have to be designed in from the first sprint.

SEBI 2026 requirement What it means in the app and back office Framework
Exchange-routed registration Onboarding tied to exchange membership and approvals Stock Brokers Regulations, 2026
Client-code mapping on every trade Order tagging and per-client audit trail in the OMS Stock Brokers Regulations, 2026
Approved algos and third-party apps Register API and algo products with the exchange Retail algo framework, April 1, 2026
Grievance redress within 21 days Ticketing with SLA timers and regulatory reporting Stock Brokers Regulations, 2026
Client fund and securities segregation Separate settlement accounts and reconciliation Stock Brokers Regulations, 2026

Retail algo trading: the April 1, 2026 framework

SEBI issued its guidelines on safer participation of retail investors in algorithmic trading on February 4, 2025, and after industry requests deferred the rollout to April 1, 2026 with a phased glide path. Brokers had to register retail algo products and API strategies, run at least one full mock trading session by January 3, 2026, and any broker that missed the milestones was barred from onboarding new clients for API-based algo trading from January 5, 2026.

Two design details drive engineering. First, there is an orders-per-second threshold: a user below 10 orders per second is treated as a regular API user, while anything above that is algorithmic trading that must be registered and routed through exchange-approved systems. Second, strategies sold to others carry their own bar. As Zerodha co-founder Nithin Kamath put it when the rules landed, "Marketplaces where people share algos for a fee can't publish strategies without exchange registration as well as an RA license." If your app exposes APIs, hosts a strategy marketplace, or lets users automate, you need OPS metering, per-strategy registration state, and clear separation between white-box and black-box algo handling.

A minimal control most teams miss is a server-side rate governor that both protects the exchange gateway and produces the evidence a regulator will ask for:

# Illustrative OPS governor: classify and tag every order before it leaves the OMS
OPS_LIMIT = 10  # SEBI threshold: >10 orders/sec is algorithmic, not manual API use

def route_order(order, client, window):
    window.record(client.id)                      # sliding 1-second counter
    order.client_code = client.exchange_code       # mandatory client-code mapping
    order.channel = "algo" if window.rate(client.id) > OPS_LIMIT else "api"
    if order.channel == "algo" and not client.algo_registered:
        raise ComplianceError("unregistered algo strategy")  # block, log, alert
    audit_log.append(order)                         # immutable trail for the exchange
    return gateway.send(order)
Enter fullscreen mode Exit fullscreen mode

Cybersecurity: SEBI's CSCRF is not optional

The SEBI Cybersecurity and Cyber Resilience Framework (CSCRF) applies to stock brokers, depository participants, asset managers and KYC registration agencies. Implementation moved to August 31, 2025 for most regulated entities after two extensions in 2025. Qualified Stock Brokers face a half-yearly audit cadence, while brokers with fewer than 1,000 clients and less than ₹1,000 crore in annual trading volume are exempt. On May 5, 2026 SEBI issued an advisory nudging entities toward AI-assisted vulnerability detection, faster security operations centre onboarding, and software bill of materials upkeep.

For a WealthTech build, CSCRF turns into concrete work: vulnerability assessment and penetration testing before go-live and on a schedule, centralised logging feeding a security operations centre, an SBOM for every deployed service, documented incident response with regulator reporting timelines, and evidence you can hand an auditor. Retail algo platforms specifically must clear VAPT before running live strategies. Treat security as a delivery workstream with its own budget, not a pre-launch checkbox.

A reference architecture for a broking or investment app

The functional core of a broking app is an order management system that accepts orders, tags them to client codes, enforces risk and OPS limits, and forwards to the exchange through the broker's approved gateway. Around it sit a market-data pipeline, an onboarding and KYC flow, a payments layer, portfolio and reporting, and the compliance and audit plumbing the regulations demand.

Market data is where latency and cost decisions concentrate. Live quotes, depth and order-book updates arrive as high-frequency streams that a mobile client cannot consume directly at scale, so a server-side ticker service normalises exchange feeds, fans them out over WebSockets, and throttles per device. Onboarding leans on Aadhaar-based e-KYC, KYC registration agencies and central KYC records so a user can open an account in minutes rather than days. Payments use UPI and net banking for funding, with settlement accounts kept separate from operating accounts to satisfy segregation rules. Teams building the money-movement and data-fetch paths should study our notes on fintech payments app development and on Account Aggregator integration for financial data, since a modern investment app usually pulls holdings and bank data through the Account Aggregator network.

Architecture layer Purpose Key considerations
Order management system Accept, validate, tag and route orders Client-code mapping, OPS limits, immutable audit trail
Market-data service Normalise and fan out live quotes and depth WebSocket fan-out, per-device throttling, failover
Onboarding and KYC Open accounts and verify identity Aadhaar e-KYC, KRA and CKYC, DPDP consent capture
Payments and settlement Fund accounts and settle trades UPI and net banking, segregated settlement accounts
Compliance and reporting Meet SEBI and exchange obligations Contract notes, grievance SLAs, CSCRF logging

For the client itself, most Indian WealthTech teams ship a single cross-platform codebase to reach both Android and iOS without doubling the team, which is why our Flutter app development practice sees steady demand from fintech founders who need real-time UI on a tight budget.

Data protection: DPDP by design

An investment app holds some of the most sensitive data a person owns: identity documents, bank details, holdings and trading behaviour. The Digital Personal Data Protection Act, 2023 (DPDP) requires clear consent, purpose limitation, honouring data-principal rights such as correction and erasure, and breach notification. The cleanest approach is to capture granular consent at onboarding, minimise what you store, encrypt data in transit and at rest, and keep an auditable record of every consent and its withdrawal. Our DPDP engineering playbook for Indian startups walks through the data model and consent architecture in detail. DPDP obligations sit alongside, not instead of, the SEBI record-keeping rules, so the same trade event often has to be both retained for the exchange and governed for the data principal.

What a compliant build actually costs

The honest answer is that in Indian WealthTech the market-data, compliance and reliability work usually costs more than the app UI. A price-comparison screen is a week of work; a market-data pipeline that stays correct under load, an OMS with client-code tagging and OPS metering, CSCRF-grade logging and VAPT, and DPDP-compliant consent are where months go. Cost drivers that move the estimate most are the number of exchanges and segments supported, whether you run your own gateway or ride a partner broker's rails, the depth of real-time data, and the audit and security cadence you commit to. Founders comparing vendors should read our broader guide to fintech app development in India before locking a scope, because scoping the compliance surface early is what keeps a build from stalling at the audit stage.

India-specific considerations

Everything above is India-specific by construction, but three points deserve their own line. First, the regulatory calendar is live: the Stock Brokers Regulations took effect on January 7, 2026 and the retail algo framework on April 1, 2026, so a plan written in 2024 is already out of date. Second, suitability is now a design constraint, not a marketing line, given the SEBI finding that 91% of derivatives traders lost money in FY24-25. Third, the market rewards trust over novelty. SEBI Chairman Tuhin Kanta Pandey has pushed for better quality and balance in the derivatives market, and an app that helps users invest rather than churn is aligned with where the regulator is heading.

FAQ

How many demat accounts and investors does India have in 2026?

By May 2026 India had about 22.9 crore demat accounts, roughly 18.38 crore at CDSL and 4.51 crore at NSDL, against nearly 13.1 crore unique registered investors on the NSE. Accounts exceed people because one investor can hold several accounts across depositories and brokers.

What changed with the SEBI (Stock Brokers) Regulations, 2026?

The regulations took effect on January 7, 2026 and repealed the 1992 rulebook. Registration now routes through a recognised exchange, applicants need at least two years of securities experience and NISM certification, grievances must be resolved within 21 days, and client funds must be segregated from the broker's own accounts.

When does SEBI's retail algo trading framework start?

SEBI issued the guidelines on February 4, 2025 and the framework rolled out on April 1, 2026 after a phased glide path. Brokers had to register API and algo products and run a mock session by January 3, 2026, or face a bar on onboarding new algo clients from January 5, 2026.

What is the orders-per-second rule for trading APIs?

SEBI set a threshold of 10 orders per second. A user staying below 10 orders per second is treated as a regular API user, while anything above is algorithmic trading that must be registered and routed through exchange-approved systems. Apps offering automation need per-user OPS metering and clear registration state.

Does my broking app need to meet SEBI's CSCRF cybersecurity rules?

Most regulated entities had to implement CSCRF by August 31, 2025. Qualified Stock Brokers face half-yearly audits, though brokers with fewer than 1,000 clients and under ₹1,000 crore in annual trading volume are exempt. Expect VAPT before go-live, centralised logging, an SBOM, and documented incident response with regulator reporting.

How does DPDP affect an investment app?

The Digital Personal Data Protection Act, 2023 requires clear consent, purpose limitation, data-principal rights such as correction and erasure, and breach notification. Because investment apps hold identity, bank and holdings data, capture granular consent at onboarding, minimise storage, encrypt data, and keep an auditable record of every consent and withdrawal.

Why is suitability design so important for Indian trading apps?

A SEBI study covering December 2024 to May 2025 found 91% of individual derivatives traders lost money in FY24-25, with net losses widening 41% to ₹1.05 lakh crore and an average loss near ₹1.1 lakh. Building risk disclosure, suitability checks and cooling-off flows protects users and aligns with the regulator.

What costs the most when building a WealthTech app?

The market-data pipeline, order management system with client-code tagging and OPS metering, CSCRF-grade security, and DPDP consent architecture cost more than the user interface. Estimates move most with the number of exchanges and segments supported, whether you run your own gateway, and the security and audit cadence you commit to.

How eCorpIT can help

eCorpIT is a Gurugram-based technology organisation, founded in 2021, appraised at CMMI Level 5 and MSME certified, with senior-led, multi-disciplinary teams and partnerships with AWS, Microsoft and Google. We design broking and investment apps aligned with SEBI (Stock Brokers) Regulations, 2026, the retail algo framework, CSCRF and DPDP requirements, covering the order management system, real-time market-data pipeline, KYC onboarding, payments and the audit plumbing that has to clear an exchange review. If you are scoping a SEBI-ready WealthTech build, talk to our team and we will map the compliance surface before you write a line of code.

References

  1. SEBI (Stock Brokers) Regulations, 2026 explained — SCC Online
  2. SEBI (Stock Brokers) Regulations, 2026: key changes — King Stubb & Kasiva
  3. SEBI extends timeline for the retail algo trading framework and sets a glide path — Upstox News
  4. Nithin Kamath on SEBI's algo rules for retail traders — Business Today
  5. SEBI CSCRF: a complete guide for regulated entities — Security Brigade
  6. FAQs on the Cybersecurity and Cyber Resilience Framework — SEBI
  7. Net losses of individual F&O traders widened in FY25: SEBI study — Business Standard
  8. 91% of retail traders lost money in derivatives in FY24-25 — Moneylife
  9. India's derivatives market and retail investors — CFA Institute
  10. NSDL adds 59 lakh demat accounts in FY26, highest-ever annual expansion — Outlook Money
  11. CDSL investor and demat account update — CDSL
  12. Shri Tuhin Kanta Pandey takes charge as Chairman, SEBI — SEBI
  13. SEBI plans to improve tenure and maturity of equity derivatives: Tuhin Pandey — Business Standard
  14. Best demat accounts in India: brokerage and AMC comparison — Pocketful
  15. SEBI chief on deeper issues in the derivatives market (March 2025 interview), Business Today

Last updated: July 26, 2026.

Top comments (0)