From a filing cabinet to a checker
Landeed’s Vault stored property documents and did nothing else. The brief: one bet on what it should become, for an owner who cannot tell whether anything is wrong.
I did not start with the app.
That is an anxiety, not a feature gap. You cannot design for an anxiety by rearranging the screens that already exist.
So I went and found out what actually happens to people who own property in India, how long it stays hidden, and how much of it a document product can genuinely touch. Before starting I set one rule: every stage of every journey gets tagged either inside Landeed’s reach or outside it. A partition suit that takes four years in a district court is a real problem and it is not one a document vault can solve. Designing as though it were is how you end up with a product that promises everything and delivers a folder.
I ran three passes, each starting from a different place, because each one has a blind spot the others cover.
Pass one. Start from the disputes.
Land dispute data from 2021 to 2026, asking what a document vault could actually change.
Then the numbers that decided the direction of the whole project. Time to resolution.
| Forum | Average pendency |
|---|---|
| District courts, all civil | 3.18 years |
| High Courts, all civil | 5.47 years |
| Land acquisition, Bengaluru Rural | 8.1 years |
| Supreme Court, land disputes | around 20 years, origin to resolution |
Pass two. Start from Landeed’s own product pages.
The second pass reversed the method. I took six things Landeed already says it does, Monitoring and Compliance, Legal Opinion, LEX, Pulse, the stamp duty calculators and property tax payment, and worked backwards. If this capability exists, what problem does it imply, and what did that problem look like before Landeed existed?
Pass three. Start from Landeed’s own users.
Passes one and two share a blind spot. Both ask, in effect, what would this look like without Landeed. That question cannot surface a failure that only exists because Landeed exists. So the third pass read the reviews: 27.2 thousand ratings on the Play Store at 4.4 stars, 2.1 thousand on the App Store at 4.6 stars.
Reverse-engineer every problem the product could touch, then find out which ones are worth touching.
The three passes produced eleven journeys, each one showing how this gets handled today, without Landeed, and what the traditional process actually costs. Seeing that is what makes the gravity of each problem legible. To compare them I scored all eleven against the same six standards, one to four each, out of twenty-four.
Underneath the six numbers there is one question: can this be caught early enough that it never becomes a court case or a year of office visits? Two jobs fall out of that, and the product needs both.
The second job is where the leverage is, and the scoring is what proved it.
What was common among all five?
Five journeys separated at the top of the scoring. Before designing anything I had to know whether that was five problems or one.
Four of the five share the first pattern. K does not, because an active transaction forces it into view within days rather than years. So the bet addresses four, and K became a sequencing decision instead: build the fetch tracker first.
A container that is also a checker. It holds a property’s paperwork, verifies it against the government’s own registration and revenue records, tells the owner what is missing and what is wrong, fetches what they do not have, and keeps watching afterwards so a defect is caught in month one rather than year five.
- At intake. The moment a document enters the vault it is checked against government records. This catches a bad document going unquestioned. It addresses B, F and I.
- Ongoing. The same checks re-run on a schedule, plus a watch layer on external signals. This catches a clean document going bad later, without the owner touching anything. It addresses E.
One mechanism, four failure modes, because they share one root cause and not four unrelated ones.
- This does not undo a forgery, reverse an invalid transfer, or settle a fraud. That remains a lawyer's and a court's job. The promise is narrower: shrink a years-long blind spot to weeks.
- India runs presumptive titling, not conclusive titling. Registration records the transaction, not the title. No document set proves ownership is final.
- No number anywhere claims safety. Every number is a count of something the user can point at.
- Nothing here prevents fraud. It compresses the discovery window.
The rubric came before the shortlist, so I could not pick badly.
Nothing in Indian consumer software does what this product needs to do, so I benchmarked apps that solve one piece of it well. The rubric came first, because otherwise the selection collapses into “apps a fifty-two-year-old already uses,” which is a comprehension argument rather than a structural one. Eight metrics, each tied to a part of the journey rather than to the persona’s demographics, with the comprehension floor demoted to a gate applied only where a person has to understand something unaided.
| Journey part | Reference | What it contributes |
|---|---|---|
| Onboarding | UPI bank linking | Narrow, search, confirm from a list, with a real dead-end escape |
| The shelf | DigiLocker | Issued versus uploaded as two visibly different things |
| Intake checks | Vanta | Per-check status, own clock, source and timestamp attached |
| The verdict | 1Password Watchtower | Named categories, no score, empty categories vanish |
| Fetch | Swiggy | Commitment before payment, a named step, refund plus a human |
| Watch | Aura | The heartbeat, and the resolution machinery after detection |
| Incident | Amex fraud alert | One intent question, one tap, the surface changes mode |
The reference I threw out is the useful one. My first shortlist had CRED owning onboarding: give it a phone number, it pulls your credit report, it hands back a list of your own cards to confirm. Exactly the shape Vault needs. It fails here for a precise reason. CRED works because India has one national key tying a person to their credit obligations, and property has no such key. ULPIN, the 14-digit Bhu-Aadhaar now adopted across 29 states and union territories, is generated from the parcel’s latitude and longitude. It identifies the land, not the owner. A good confirmation key and a useless discovery key.
Five parts. Each one is a flow, and each flow ends in a screen.
The brief asks you to finish one sentence for the main screen. The main screen is the portfolio home rather than any single property, because this person owns four things and opens the app carrying one question.
Two facts per property, never multiplied together. Completeness is a count of what is held against what is required, shown as a segmented bar rather than a pie, because a pie shows one number and a bar shows three facts and tells you what to do next. Health is what the checks found: clean, needs attention, problem found, or could not check. Four categorically different conditions, not points on a scale.
A property’s health is the worst status among its records, never the average. Nine clean records and one forged deed is not ninety percent fine, it is a stop signal. And “could not check” sits off the colour scale entirely, because it is the absence of information rather than a middle value between good and bad.
The shelf underneath is organised by what a document proves, not by what a state calls it. State is a renderer, not a schema. The instrument that conveyed title. The chain behind it. The public record naming you as holder, which is an RTC in Karnataka and a 7/12 in Maharashtra and a Patta in Tamil Nadu. Evidence the transfer entered the revenue system. Evidence of what is charged against it. Evidence of the boundary. Nine slots, whatever the state, whatever the language.
The governing rule is to ask only for what a person carries in their head. They know their PIN code and their own name. They do not know their survey number, their local body type, their land classification or their tenure, so none of those are ever asked for. Which raises the obvious objection: where does the survey number come from? I chased that down to real infrastructure.
There is no phone-number route and no Aadhaar route. Aadhaar seeding into land records is real, but it runs one direction only: it attaches your Aadhaar to a record somebody already located. No portal takes an Aadhaar number and returns your holdings. That is exactly why DigiLocker can do this for a driving licence and not for land.
Two things do work. Landeed already inverts the Bhoomi portal, which demands seven fields including the survey number, into a search by owner name. And Karnataka’s revenue department runs Dishaank, which uses GPS to place you inside a survey polygon across more than 30,000 digitised village maps. Zero documents, zero recall, zero typing.
The map route matters most for this persona because it matches how they actually hold the information. They do not know “Survey 142/2.” They know “the plot behind the Bidadi bus stand.” And the last step is not an OTP, because most of what Landeed pulls is public. It is a declaration of ownership, which is the thing that makes “you did not authorise this” mean something eight months later.
The brief asked for AI that earns its place. Landeed already has the right AI and it is not a chatbot. Terra is their own property intelligence layer, built over 773 million documents across 26 states and four union territories, returning ownership, encumbrances, liabilities and litigation, transaction history and document risk.
So Terra is the checker. It reads a torn, faded, Kannada-script 1987 deed and structures it. It runs six checks against the government records it has indexed. It names the defect in plain words. It does not give an opinion on title, does not certify a document as genuine, and does not decide whether you should buy. A machine checks everything and an advocate becomes the escalation for the minority of cases rather than the gate on all of them, which is what makes it viable to give the first call away free at the moment the user most doubts you.
This is the part that gets built first, because Journey K said so. Before anyone trusts a vault with a lifetime of land papers, it has to deliver the one document they just paid for.
Fetch is not one flow, it is three, and the user is told which one they are in before any money moves. Some records come back instantly from a state portal. A certified copy is a two to three day order placed with a sub-registrar. And some documents are not available online anywhere, in which case the honest answer is a person sent to an office, or an upload with the caveat stated.
Underneath all of it, one pricing rule: sell the work, never the verdict. Reading a document, running every machine check, the status, and the evidence pack are always free. Fetching, certifying, a written legal opinion and monitoring are paid. A payment never changes a status, only new evidence does. And nobody is ever charged more because the news was bad, since that is the moment they most need to act and most doubt you.
Seven signals can tell you a property is in trouble, and the only ordering that matters is how much warning each one gives.
| Signal | Source | Lead time |
|---|---|---|
| Your property listed for sale by someone else | Listing portals | Weeks to months |
| Someone running records diligence on your property | Landeed's own search telemetry | Days to weeks |
| An e-stamp certificate issued naming your property | SHCIL and state portals | Days to weeks |
| A new charge filed against your property | CERSAI | 0 to 30 days |
| A new registration | State EC and Index II | Already happened |
| A mutation you did not file | State revenue records | Already happened |
| A court case or auction notice | eCourts, IBAPI, bank portals | Years late |
The first two are the only signals that give an owner room to act, and neither exists in any Indian product today. CERSAI is the strongest single source, national rather than state-by-state and publicly searchable at around ten rupees, catching equitable mortgages that leave no registered deed and are therefore structurally invisible to an encumbrance certificate. And the discipline that makes the rest credible is saying out loud what is not detectable: the forged identity, the fake power of attorney and the cash negotiation leave no online trace at all.
Signals spanning months of runway to years too late cannot share one feed without the urgent one getting lost, so there are two modes. Watch is calm by design. Incident is not a notification, it is the whole property screen changing. The bridge between them is a single tap on a single question, and it is the most important interaction in the product, because the system can read the listing and read the land record but only the owner knows whether they agreed to it.
Detection without a remedy solves half the journey. Across every failure mode I studied, the frustration was not ignorance, it was knowing and being unable to act. So the evidence pack is generated the moment anything is found, before the user opens the app.
A single Property Health Score out of 100.
One number per property, a ring gauge, green above 80. It is what most fintech products would ship and it demos beautifully.
That is why health is four named states, completeness is a separate count, and the two are never multiplied.
Three designed failure states, not one.
- A fetch that fails. Refund first, named reason, real alternatives.
- A check that cannot run. The could-not-check state, off the colour scale, present on the portfolio, the verdict and the live check screen.
- A document that cannot be read. Intake branches to retake, upload a better copy, or send it to a person.
| Edge | How the design answers it |
|---|---|
| Zero documents | The empty shelf appears in onboarding before any input, so a new user sees the destination rather than a blank screen |
| Forty documents | The shelf caps at nine by design, because it is organised by what a document proves, not by how many files exist |
| Returning after six months | The heartbeat and the weekly digest. The portfolio answers the question in one line before they scroll |
- Does listing-to-property matching reach useful precision on real portal data
- Does search telemetry survive a privacy review under DPDP
- Does name-based record search work across enough of the 24 states to carry onboarding, or is Karnataka unusually well served
- What the false-positive rate on Watch alerts actually is, and whether the authorisation question survives alert fatigue
- A name search finds land recorded against a name, it cannot prove the searcher is that person. Enrolment should need a second signal before alerts start
Where AI helped.
I used Claude throughout, and the honest answer about where it helped is not that it made the screens.
It compressed the research. The most valuable part of this project was the part that has nothing to do with the app: eleven journeys reconstructed from court data, real fraud cases, state digitisation programmes, judgments, Landeed’s own product pages and its own app store reviews. Reading and cross-checking that much material, then holding all of it in view long enough to notice that four of the top five journeys share one root cause, would have taken weeks on my own. It took days.
It was also the fastest way to check myself. When I assumed Landeed’s existing monitoring already covered an individual owner, checking that against their own pages took minutes and changed the argument. The judgment calls stayed mine: cutting the partition dispute out of Journey A, throwing out two journeys that were not vault-shaped, replacing the wrong benchmark app, and deciding that K belonged in the sequencing rather than the bet. Where it helped least was taste. Every line of copy on these screens was rewritten by hand until it sounded like one voice.















