UCAP only works if both sides trust it. Consent is enforced in code, data is encrypted at the field level, and every action is logged for life.
ID numbers and sensitive fields are encrypted at rest with rotated keys. Data is protected at the field level, not just the database — and the consumer effectively holds the key.
No partner reads anything without an explicit, scoped, time-bound grant from the consumer. Consent is enforced in code, not promised in a policy — and it aligns with POPIA.
Every approval, share and revoke lives in an append-only, timestamped audit log. If a grant is ever questioned, the full chain of consent is one query away.
Verified through Home Affairs via the VerifyID gateway. Direct DHA integration is on the roadmap as UCAP scales.
Sourced through Open Banking feeds, so figures are live and bank-verified — not self-declared or scraped.
Collected once from trusted issuers and reused with consent — never re-uploaded, never stale.
That single principle is what makes UCAP safe to integrate, safe to use, and defensible to a regulator. Nothing happens without an explicit grant, and every grant can be pulled in one tap.
We'll walk the consent model, the encryption and the audit trail in detail — built for the questions your risk team will ask.
Book a demo