UCAP
Consumer? Get the walletBook a demo
Security & compliance

Trust isn't a feature here. It's the architecture.

UCAP only works if both sides trust it. Consent is enforced in code, data is encrypted at the field level, and every action is logged for life.

Envelope-encrypted PII

ID numbers and sensitive fields are encrypted at rest with rotated keys. Data is protected at the field level, not just the database — and the consumer effectively holds the key.

Consent-first by design

No partner reads anything without an explicit, scoped, time-bound grant from the consumer. Consent is enforced in code, not promised in a policy — and it aligns with POPIA.

Tamper-evident audit

Every approval, share and revoke lives in an append-only, timestamped audit log. If a grant is ever questioned, the full chain of consent is one query away.

Verified at the source

Where the data comes from.

Identity

Verified through Home Affairs via the VerifyID gateway. Direct DHA integration is on the roadmap as UCAP scales.

Income

Sourced through Open Banking feeds, so figures are live and bank-verified — not self-declared or scraped.

Address & documents

Collected once from trusted issuers and reused with consent — never re-uploaded, never stale.

The consumer owns their data. You borrow it, with permission, for as long as they allow.

That single principle is what makes UCAP safe to integrate, safe to use, and defensible to a regulator. Nothing happens without an explicit grant, and every grant can be pulled in one tap.

Bring your compliance team to the call.

We'll walk the consent model, the encryption and the audit trail in detail — built for the questions your risk team will ask.

Book a demo