security & compliance

Trust isn't a feature here. It's the architecture.

UCAPTM only works if both sides trust it. Consent is enforced in code, data is encrypted at the field level, and every action is logged for life.

How we protect your data

Envelope-encrypted PII

ID numbers and sensitive fields are encrypted at rest with rotated keys. Data is protected at the field level, not just the database — and the consumer effectively holds the key.

Consent-first by design

No client reads anything without an explicit, scoped, time-bound grant from the consumer. Consent is enforced in code, not promised in a policy — and it aligns with POPIA.

Tamper-evident audit

Every approval, share and revoke lives in an append-only, timestamped audit log. If a grant is ever questioned, the full chain of consent is one query away.

Verified at the source

Identity

Supported identity documents are matched to a live selfie through Smile ID. Evidence grade and freshness remain document-specific.

Income

Canonical income details and linked supporting evidence remain distinct, so consumers and recipients can see what is asserted and what is supported.

Address & documents

Documents are stored once, linked to relevant claims and disclosed only through an explicit consent grant.

The consumer owns their data. You borrow it, with permission, for as long as they allow.

That single principle is what makes UCAPTM safe to integrate, safe to use, and defensible to a regulator. Nothing happens without an explicit grant, and every grant can be pulled in one tap.