New: Hypersign is now eIDAS 2.0 ready verifiable credentials and EUDI Wallet compliance built in. See case studies →
For KYC & Identity Verification Providers

Hypersign Compass.

Compliance-ready identity infrastructure for growing regulatory and audit demands, powered by consent, verifiable credentials, encrypted identity vaults, and selective disclosure.

The Gap

Identity verification and data privacy compliance are not the same problem.

Identity verification is point-in-time. Data privacy compliance isn't. Consent, data retention, auditability, and secure data custody continue long after a verification decision.

  • Verification ends with a decision. Compliance continues.
  • Identity data creates obligations long after onboarding.
  • Your verification stack can be accurate and still leave compliance gaps.
See the four building blocks →
Hypersign identity flow: the user's documents are minimized, verified, and shared with explicit consent to the organization as reusable trust signals, reducing PII exposure, lowering compliance risk and cost, and eliminating repeated verification.

What Compass Gives You

Four building blocks. One API.

4

Privacy Primitives: Consent, Credentials, Vault, Disclosure

0

Changes Required to Your Verification Engine

100%

Consent & Vault Access Events Logged

<2s

Webhook Response Time (p99)

The Difference

Same verification stack. A different privacy posture.

Without Compass

  • Consent captured as a single blanket checkbox, if at all
  • Full documents and biometrics handed to every relying party
  • Retention and deletion handled ad hoc, tool by tool
  • No portable proof your own clients can rely on later

With Compass

  • Purpose-based consent, captured and cryptographically signed at every check
  • Relying parties get a pass/fail claim through selective disclosure, never the raw document
  • Retention windows enforced automatically, with a signed erasure certificate
  • Every verified user carries a reusable, portable credential

Principle 1 · Consent

Capture consent once. Prove it forever.

Consent is captured per purpose, timestamped, and signed. The receipt is a PDF and a W3C Verifiable Credential, proof your client can hold, not a row only you can query.

  • Purpose-based, granular, and revocable, not a blanket "I agree"
  • Signed, portable consent receipts, not just an internal log entry
  • Downstream systems stop processing the moment a purpose is withdrawn
Consent Record
Purpose-scoped · Signed
● Active
Identity Verification✓ Consented
AML Screening✓ Consented
Marketing✗ Declined

Principle 2 · Verifiable Credentials

Turn a completed check into a reusable credential.

Most verification vendors stop at proofing identity. Compass adds a credential layer on top: a completed check becomes a signed, reusable W3C Verifiable Credential.

  • W3C standard: interoperable with any compliant verifier, not locked to Compass
  • A portable proof your clients can present again, not just an internal record
  • Instant revocation the moment fraud or a withdrawal is detected
Hypersign reusable digital identity flow: a verified credential is stored in the user's digital identity wallet and reused instantly across banks, fintechs, lending platforms, and marketplaces, with consent oversight and audit reports available to regulators.

Principle 3 · Identity Vault

Store less. Isolate what you do store.

Every record is encrypted with per-customer keys before it's written to disk, so even the vault operator can't read it. Retention windows close automatically, purging or anonymizing the record with a signed erasure certificate.

  • AES-256 at rest with per-customer keys: trust-no-one by design
  • Dual vault architecture: individual and business data isolated
  • Access is consent-gated, checked on every record request
Vault Access
Consent-gated · Isolated
● Encrypted
Individual Vault✓ Isolated
Business Vault✓ Isolated
Retention Window Closed✓ Auto-purged

Principle 4 · Selective Disclosure

Share a yes or no. Not the underlying document.

Selective disclosure (zero-knowledge proofs and BBS+ signatures) returns "over 18" or "KYC passed" without the document, DOB, or biometric ever leaving the vault. Minimization becomes structural, not a policy to enforce.

  • Verifier gets a pass/fail claim, never the raw document
  • Zero-knowledge proofs and BBS+ signatures, not redaction
  • Works for age, KYC status, or any single claim
/api/v1/presentation/generate
Claim Requestedkyc_passed
Disclosed✓ true
Document, DOB, Biometric✗ Not disclosed

Mapped to the Law

Global Data protection regulations, mapped to Compass.

DPDP Act 2023 (India)

DPDP §5, §6(1)Consent must be free, specific, informed, and revocable
Consent API
DPDP §6(1)Data collected must be limited to what's necessary for the purpose
Selective Disclosure
DPDP §8(7)–(8)Data held only as long as the purpose requires, then deleted
Identity Vault
DPDP §11–13Data principals get enforceable access, correction, and erasure rights
Verifiable Credentials

GDPR (EU)

GDPR Art. 6(1)(a), 7Consent must be freely given, specific, and as easy to withdraw as to give
Consent API
GDPR Art. 5(1)(c)Data collected must be adequate, relevant, and limited to what's necessary
Selective Disclosure
GDPR Art. 17Data subjects have a right to erasure, enforceable on request
Identity Vault
GDPR Art. 30Controllers must maintain a record of processing activities
Verifiable Credentials

Every Feature, One Place

The full Compass feature set.

Purpose-Based Consent

Verification, AML, storage, marketing: each captured and revoked independently.

Signed Consent Receipts

Issued as a PDF and a W3C Verifiable Credential, not just a database row.

Jurisdiction Presets

DPDP, GDPR, and eIDAS 2.0 as configurable presets on one engine.

Reusable Verifiable Credentials

A completed check becomes a portable, W3C-standard credential.

Instant Revocation

Credentials revoked the moment fraud or a withdrawal is detected.

Encrypted Identity Vault

AES-256 at rest with per-customer keys, so even Compass can't read it.

Dual Vault Architecture

Individual and business data isolated by design.

Automated Retention & Erasure

Windows close automatically with a signed erasure certificate.

Selective Disclosure

Share a pass/fail claim through zero-knowledge proofs, never the document.

Consent-Gated Access

Vault access checked against live consent on every request.

Signed Webhooks

HMAC-SHA256 signed, session-scoped, no long-lived credentials.

Audit Trail

Every consent and access event logged and producible on demand.

For Your Customers

Less data liability for the businesses you sell to.

What changes for you changes for your customers too. They receive a claim, not raw documents: a smaller breach surface, one less gap in their vendor review.

  • A pass/fail claim through selective disclosure, never the document
  • Their users inherit a reusable credential instead of re-verifying
  • A signed audit trail for their own regulators or auditors
  • Your compliance posture clears their vendor review, not stalls it
What Your Customer Receives
Per verified user
Pass/Fail Claim✓ Received
Raw Document✗ Not received
Reusable Credential✓ Received
Signed Audit Trail✓ Received

Where Compass Fits

Not a consent platform. Not a replacement for your engine.

A general-purpose CMP covers your whole business: cookies, marketing, partner data-sharing. Compass covers one moment, the identity check itself, as an API layer beside your engine, not inside it. Your verification stack stays yours.

Two Ways to Work with Compass

Self-integrate, or join the Compass Partner Program.

Option A

Self-Integrate

Add Compass to your stack. Keep your brand, your customers, your engine.

  • Consent, credentials, vault, disclosure: one API
  • No vendor switch, your engine stays
  • DPDP, GDPR, eIDAS 2.0 as presets
  • Live in days, priced separately
Book a demo →

Option B

Compass Partner Program

We integrate your API and bring you new business.

  • We handle the integration
  • Your API, listed for our customers
  • Compliance included, out of the box
  • L1 support, on us
  • New revenue, per verification
  • A channel partner, not just software
  • New geographies, compliance included
Talk to Partnerships →
Built to align with:DPDP Act 2023 (India)GDPR (EU)CCPA/CPRA (US)Illinois BIPA (US)eIDAS 2.0 / EUDI WalletSOC 2 · ISO 27001

FAQ

Everything about Hypersign Compass

Your verification engine.
Compass underneath it.

Talk to our compliance team about adding consent, credentials, a vault, and selective disclosure alongside the KYC stack you already run.

From the Blog

Best Digio Alternatives for DPDP-Compliant Aadhaar KYC (2026)
Comparison

Best Digio Alternatives for DPDP-Compliant Aadhaar KYC (2026)

Digio's Aadhaar eSign and KYC line predates DPDP consent rules, sold separately via its CoTrust add-on. Compare 7 real Digio alternatives, including Hypersign.

Best Jukshio Alternatives for Video KYC in India (2026)
Comparison

Best Jukshio Alternatives for Video KYC in India (2026)

Jukshio's privacy policy never mentions India's DPDP Act. See how six real Jukshio alternatives compare on video KYC coverage and DPDP-ready consent handling.

Socure & IDnow Alternatives for India Expansion (2026)
Comparison

Socure & IDnow Alternatives for India Expansion (2026)

Socure's fraud-risk scoring and IDnow's supervised video-ident are both strong in their home markets, but neither publishes a single India-specific claim. Here's where each actually fits, and the one alternative built for the DPDP, CKYC, and Aadhaar gap both leave open.

Best IDfy Alternatives for DPDP-Compliant KYC (2026)
Comparison

Best IDfy Alternatives for DPDP-Compliant KYC (2026)

IDfy's DPDP tool, Privy, is a separate product from its KYC API, not built into verification. See six real IDfy alternatives, including one that builds it in.

Best Sumsub Alternatives for DPDP-Compliant KYC (2026)
Comparison

Best Sumsub Alternatives for DPDP-Compliant KYC (2026)

Sumsub's AML, KYB, and Travel Rule tools sit behind a $299/month tier or a custom Enterprise quote, and nothing on its site addresses India's DPDP Act. Here's how seven real Sumsub alternatives compare, including the one built for DPDP-regulated fintechs and Web3 teams.

Best Trulioo Alternatives for India-Compliant KYC (2026)
Comparison

Best Trulioo Alternatives for India-Compliant KYC (2026)

Trulioo's own site claims 195 countries and 450+ data sources, but nothing on it, including its India KYC blog post, mentions CKYC or the DPDP Act. Here's how seven real Trulioo alternatives compare, including the one built for DPDP-regulated Indian fintechs.

DPDP Consent Manager vs. Consent Management Platform vs. KYC-Embedded Consent: What Your Fintech Actually Needs
Compliance

DPDP Consent Manager vs. Consent Management Platform vs. KYC-Embedded Consent: What Your Fintech Actually Needs

"Consent Manager" is a specific, registered role under the DPDP Act. A "consent management platform" is a software category most vendors selling into fintech actually belong to. Neither is the same as consent captured at the KYC moment. Here's the boundary between all three, and which one (or two) a fintech actually needs.

Your Account Aggregator License Meets DPDP for Financial Data Consent. It Was Never Built for KYC Consent.
Compliance

Your Account Aggregator License Meets DPDP for Financial Data Consent. It Was Never Built for KYC Consent.

RBI built the Account Aggregator framework to move financial data with consent and nothing else. It was never scoped to cover PAN, Aadhaar, or biometric KYC consent and that's exactly the part of onboarding still sitting with whichever KYC vendor an NBFC plugged in years ago. Here's the boundary, mapped point-to-point against DPDP.

cKYC Doesn't Mean "Verify Once" Anymore: The OTP and Stale-Data Problem Under DPDP
Compliance

cKYC Doesn't Mean "Verify Once" Anymore: The OTP and Stale-Data Problem Under DPDP

cKYC was built so a bank could pull a customer's verified identity once and skip re-KYC. Since April 2025, every pull needs a fresh OTP and the record sitting behind that OTP is often years out of date. How cKYC actually works, why DPDP just made reuse harder, and what fixes both problems at once.

DPDP Act Compliance for Fintech KYC: What Changes, and What Your Stack Needs to Handle It
Compliance

DPDP Act Compliance for Fintech KYC: What Changes, and What Your Stack Needs to Handle It

India's DPDP Act doesn't replace RBI's KYC Master Directions it runs alongside them, with a different legal basis, different retention logic, and its own penalties. Here's what that means for a fintech's KYC stack, mapped to the controls that actually satisfy it.

The PII Liability Hiding in Every Indian Event Company's Database and How to Stop Storing It
Guide

The PII Liability Hiding in Every Indian Event Company's Database and How to Stop Storing It

A ticketing platform running large venues doesn't just process payments it accumulates ID scans, face photos, and gig-worker documents by the thousand, every event. Under India's DPDP Act, every one of those records is a liability sitting in your database. Here's how to verify people without owning the data.