security & compliance
Trust isn't a feature here. It's the architecture.
UCAPTM only works if both sides trust it. Consent is enforced in code, data is encrypted at the field level, and every action is logged for life.
security & compliance
UCAPTM only works if both sides trust it. Consent is enforced in code, data is encrypted at the field level, and every action is logged for life.
How we protect your data
ID numbers and sensitive fields are encrypted at rest with rotated keys. Data is protected at the field level, not just the database — and the consumer effectively holds the key.
No client reads anything without an explicit, scoped, time-bound grant from the consumer. Consent is enforced in code, not promised in a policy — and it aligns with POPIA.
Every approval, share and revoke lives in an append-only, timestamped audit log. If a grant is ever questioned, the full chain of consent is one query away.
Verified at the source
Supported identity documents are matched to a live selfie through Smile ID. Evidence grade and freshness remain document-specific.
Canonical income details and linked supporting evidence remain distinct, so consumers and recipients can see what is asserted and what is supported.
Documents are stored once, linked to relevant claims and disclosed only through an explicit consent grant.
That single principle is what makes UCAPTM safe to integrate, safe to use, and defensible to a regulator. Nothing happens without an explicit grant, and every grant can be pulled in one tap.
We'll walk the consent model, the encryption and the audit trail in detail — built for the questions your risk team will ask.