New: Hypersign is now eIDAS 2.0 ready verifiable credentials and EUDI Wallet compliance built in. See case studies →
For KYC & Identity Verification Providers

Hypersign Compass.

Compliance-ready identity infrastructure for growing regulatory and audit demands, powered by consent, verifiable credentials, encrypted identity vaults, and selective disclosure.

The Gap

Identity verification and data privacy compliance are not the same problem.

Document checks, liveness, and biometric matching answer one question: is this person who they claim to be? What happens to their data afterward (consent, minimal use, real deletion) is a different problem most engines were never built to solve.

  • Verification is a point-in-time decision; privacy compliance is ongoing
  • Data collected at onboarding usually outlives its real purpose
  • A stack can verify perfectly and still fail on how it handles the data
See the four building blocks →
Hypersign identity flow: the user's documents are minimized, verified, and shared with explicit consent to the organization as reusable trust signals, reducing PII exposure, lowering compliance risk and cost, and eliminating repeated verification.

What Compass Gives You

Four building blocks. One API.

4

Privacy Primitives: Consent, Credentials, Vault, Disclosure

0

Changes Required to Your Verification Engine

100%

Consent & Vault Access Events Logged

<2s

Webhook Response Time (p99)

The Difference

Same verification stack. A different privacy posture.

Without Compass

  • Consent captured as a single blanket checkbox, if at all
  • Full documents and biometrics handed to every relying party
  • Retention and deletion handled ad hoc, tool by tool
  • No portable proof your own clients can rely on later

With Compass

  • Purpose-based consent, captured and cryptographically signed at every check
  • Relying parties get a pass/fail claim through selective disclosure, never the raw document
  • Retention windows enforced automatically, with a signed erasure certificate
  • Every verified user carries a reusable, portable credential

Principle 1 · Consent

Capture consent once. Prove it forever.

Consent is captured per purpose (verification, AML, document storage), each accepted or declined independently, timestamped, and signed. The receipt is a PDF and a W3C Verifiable Credential: proof your client can hold, not a row only you can query.

  • Purpose-based, granular, and revocable, not a blanket "I agree"
  • Signed, portable consent receipts, not just an internal log entry
  • Downstream systems stop processing the moment a purpose is withdrawn
Consent Record
Purpose-scoped · Signed
● Active
Identity Verification✓ Consented
AML Screening✓ Consented
Marketing✗ Declined

Principle 2 · Verifiable Credentials

Turn a completed check into a reusable credential.

Most verification vendors stop at proofing identity. Compass adds a credential layer on top, so a completed check becomes a signed W3C Verifiable Credential. That's proof your clients, and their partners, can trust instantly instead of re-verifying from scratch.

  • W3C standard: interoperable with any compliant verifier, not locked to Compass
  • A portable proof your clients can present again, not just an internal record
  • Instant revocation the moment fraud or a withdrawal is detected
Hypersign reusable digital identity flow: a verified credential is stored in the user's digital identity wallet and reused instantly across banks, fintechs, lending platforms, and marketplaces, with consent oversight and audit reports available to regulators.

Principle 3 · Identity Vault

Store less. Isolate what you do store.

Every record is encrypted before it's written to disk, with per-customer keys, so even the vault operator can't read it. Personal and business data stay in separate vaults, and when a retention window closes, the record is purged or anonymized automatically with a signed erasure certificate.

  • AES-256 at rest with per-customer keys: trust-no-one by design
  • Dual vault architecture: individual and business data isolated
  • Access is consent-gated, checked on every record request
Vault Access
Consent-gated · Isolated
● Encrypted
Individual Vault✓ Isolated
Business Vault✓ Isolated
Retention Window Closed✓ Auto-purged

Principle 4 · Selective Disclosure

Share a yes or no. Not the underlying document.

Traditional verification hands a relying party the full document and biometric record, even for a single yes/no question. Selective disclosure (zero-knowledge proofs and BBS+ signatures) returns "over 18" or "KYC passed" without the document, DOB, or biometric ever leaving the vault. Minimization becomes structural, not a policy to enforce.

  • Verifier gets a pass/fail claim, never the raw document
  • Zero-knowledge proofs and BBS+ signatures, not a redaction step bolted on after the fact
  • The same mechanism works for age, KYC status, or any other single claim
/api/v1/presentation/generate
Claim Requestedkyc_passed
Disclosed✓ true
Document, DOB, Biometric✗ Not disclosed

Mapped to the Law

DPDP and GDPR clauses, mapped to Compass.

DPDP Act 2023 (India)

DPDP §5, §6(1)Consent must be free, specific, informed, and revocable
Consent API
DPDP §6(1)Data collected must be limited to what's necessary for the purpose
Selective Disclosure
DPDP §8(7)–(8)Data held only as long as the purpose requires, then deleted
Identity Vault
DPDP §11–13Data principals get enforceable access, correction, and erasure rights
Verifiable Credentials

GDPR (EU)

GDPR Art. 6(1)(a), 7Consent must be freely given, specific, and as easy to withdraw as to give
Consent API
GDPR Art. 5(1)(c)Data collected must be adequate, relevant, and limited to what's necessary
Selective Disclosure
GDPR Art. 17Data subjects have a right to erasure, enforceable on request
Identity Vault
GDPR Art. 30Controllers must maintain a record of processing activities
Verifiable Credentials

Every Feature, One Place

The full Compass feature set.

Purpose-Based Consent

Verification, AML, storage, marketing: each captured and revoked independently.

Signed Consent Receipts

Issued as a PDF and a W3C Verifiable Credential, not just a database row.

Jurisdiction Presets

DPDP, GDPR, and eIDAS 2.0 as configurable presets on one engine.

Reusable Verifiable Credentials

A completed check becomes a portable, W3C-standard credential.

Instant Revocation

Credentials revoked the moment fraud or a withdrawal is detected.

Encrypted Identity Vault

AES-256 at rest with per-customer keys, so even Compass can't read it.

Dual Vault Architecture

Individual and business data isolated by design.

Automated Retention & Erasure

Windows close automatically with a signed erasure certificate.

Selective Disclosure

Share a pass/fail claim through zero-knowledge proofs, never the document.

Consent-Gated Access

Vault access checked against live consent on every request.

Signed Webhooks

HMAC-SHA256 signed, session-scoped, no long-lived credentials.

Audit Trail

Every consent and access event logged and producible on demand.

For Your Customers

Less data liability for the businesses you sell to.

What Compass changes for you also changes for your customers. They receive a claim, not raw documents, so it's a smaller breach surface on their side and one less compliance gap for their own vendor review to flag.

  • They get a pass/fail claim through selective disclosure, never the raw document
  • Their users inherit a reusable credential instead of re-verifying every time
  • A signed audit trail they can hand their own regulators or auditors
  • Your compliance posture clears their vendor security review instead of stalling it
What Your Customer Receives
Per verified user
Pass/Fail Claim✓ Received
Raw Document✗ Not received
Reusable Credential✓ Received
Signed Audit Trail✓ Received

Where Compass Fits

Not a consent platform. Not a replacement for your engine.

A general-purpose CMP covers your whole business: cookies, marketing, partner data-sharing. Compass covers one moment, the identity check itself: consent, credentialing, and minimization built in as an API layer beside your engine, not inside it. Your verification stack stays yours.

Built to align with:DPDP Act 2023 (India)GDPR (EU)eIDAS 2.0 / EUDI WalletSOC 2 · ISO 27001

FAQ

Everything about Hypersign Compass

Your verification engine.
Compass underneath it.

Talk to our compliance team about adding consent, credentials, a vault, and selective disclosure alongside the KYC stack you already run.

From the Blog

Best Digio Alternatives for DPDP-Compliant Aadhaar KYC (2026)
Comparison

Best Digio Alternatives for DPDP-Compliant Aadhaar KYC (2026)

Digio's Aadhaar eSign and KYC line predates DPDP consent rules, sold separately via its CoTrust add-on. Compare 7 real Digio alternatives, including Hypersign.

Best Jukshio Alternatives for Video KYC in India (2026)
Comparison

Best Jukshio Alternatives for Video KYC in India (2026)

Jukshio's privacy policy never mentions India's DPDP Act. See how six real Jukshio alternatives compare on video KYC coverage and DPDP-ready consent handling.

Socure & IDnow Alternatives for India Expansion (2026)
Comparison

Socure & IDnow Alternatives for India Expansion (2026)

Socure's fraud-risk scoring and IDnow's supervised video-ident are both strong in their home markets, but neither publishes a single India-specific claim. Here's where each actually fits, and the one alternative built for the DPDP, CKYC, and Aadhaar gap both leave open.

Best IDfy Alternatives for DPDP-Compliant KYC (2026)
Comparison

Best IDfy Alternatives for DPDP-Compliant KYC (2026)

IDfy's DPDP tool, Privy, is a separate product from its KYC API, not built into verification. See six real IDfy alternatives, including one that builds it in.

Best Sumsub Alternatives for DPDP-Compliant KYC (2026)
Comparison

Best Sumsub Alternatives for DPDP-Compliant KYC (2026)

Sumsub's AML, KYB, and Travel Rule tools sit behind a $299/month tier or a custom Enterprise quote, and nothing on its site addresses India's DPDP Act. Here's how seven real Sumsub alternatives compare, including the one built for DPDP-regulated fintechs and Web3 teams.

Best Trulioo Alternatives for India-Compliant KYC (2026)
Comparison

Best Trulioo Alternatives for India-Compliant KYC (2026)

Trulioo's own site claims 195 countries and 450+ data sources, but nothing on it, including its India KYC blog post, mentions CKYC or the DPDP Act. Here's how seven real Trulioo alternatives compare, including the one built for DPDP-regulated Indian fintechs.

DPDP Consent Manager vs. Consent Management Platform vs. KYC-Embedded Consent: What Your Fintech Actually Needs
Compliance

DPDP Consent Manager vs. Consent Management Platform vs. KYC-Embedded Consent: What Your Fintech Actually Needs

"Consent Manager" is a specific, registered role under the DPDP Act. A "consent management platform" is a software category most vendors selling into fintech actually belong to. Neither is the same as consent captured at the KYC moment. Here's the boundary between all three, and which one (or two) a fintech actually needs.

Your Account Aggregator License Meets DPDP for Financial Data Consent. It Was Never Built for KYC Consent.
Compliance

Your Account Aggregator License Meets DPDP for Financial Data Consent. It Was Never Built for KYC Consent.

RBI built the Account Aggregator framework to move financial data with consent and nothing else. It was never scoped to cover PAN, Aadhaar, or biometric KYC consent and that's exactly the part of onboarding still sitting with whichever KYC vendor an NBFC plugged in years ago. Here's the boundary, mapped point-to-point against DPDP.

cKYC Doesn't Mean "Verify Once" Anymore: The OTP and Stale-Data Problem Under DPDP
Compliance

cKYC Doesn't Mean "Verify Once" Anymore: The OTP and Stale-Data Problem Under DPDP

cKYC was built so a bank could pull a customer's verified identity once and skip re-KYC. Since April 2025, every pull needs a fresh OTP and the record sitting behind that OTP is often years out of date. How cKYC actually works, why DPDP just made reuse harder, and what fixes both problems at once.

DPDP Act Compliance for Fintech KYC: What Changes, and What Your Stack Needs to Handle It
Compliance

DPDP Act Compliance for Fintech KYC: What Changes, and What Your Stack Needs to Handle It

India's DPDP Act doesn't replace RBI's KYC Master Directions it runs alongside them, with a different legal basis, different retention logic, and its own penalties. Here's what that means for a fintech's KYC stack, mapped to the controls that actually satisfy it.

The PII Liability Hiding in Every Indian Event Company's Database and How to Stop Storing It
Guide

The PII Liability Hiding in Every Indian Event Company's Database and How to Stop Storing It

A ticketing platform running large venues doesn't just process payments it accumulates ID scans, face photos, and gig-worker documents by the thousand, every event. Under India's DPDP Act, every one of those records is a liability sitting in your database. Here's how to verify people without owning the data.