Hypersign Compass.
Compliance-ready identity infrastructure for growing regulatory and audit demands, powered by consent, verifiable credentials, encrypted identity vaults, and selective disclosure.
The Gap
Identity verification and data privacy compliance are not the same problem.
Document checks, liveness, and biometric matching answer one question: is this person who they claim to be? What happens to their data afterward (consent, minimal use, real deletion) is a different problem most engines were never built to solve.
- Verification is a point-in-time decision; privacy compliance is ongoing
- Data collected at onboarding usually outlives its real purpose
- A stack can verify perfectly and still fail on how it handles the data

What Compass Gives You
Four building blocks. One API.
4
Privacy Primitives: Consent, Credentials, Vault, Disclosure
0
Changes Required to Your Verification Engine
100%
Consent & Vault Access Events Logged
<2s
Webhook Response Time (p99)
The Difference
Same verification stack. A different privacy posture.
Without Compass
With Compass
Principle 1 · Consent
Capture consent once. Prove it forever.
Consent is captured per purpose (verification, AML, document storage), each accepted or declined independently, timestamped, and signed. The receipt is a PDF and a W3C Verifiable Credential: proof your client can hold, not a row only you can query.
- Purpose-based, granular, and revocable, not a blanket "I agree"
- Signed, portable consent receipts, not just an internal log entry
- Downstream systems stop processing the moment a purpose is withdrawn
Principle 2 · Verifiable Credentials
Turn a completed check into a reusable credential.
Most verification vendors stop at proofing identity. Compass adds a credential layer on top, so a completed check becomes a signed W3C Verifiable Credential. That's proof your clients, and their partners, can trust instantly instead of re-verifying from scratch.
- W3C standard: interoperable with any compliant verifier, not locked to Compass
- A portable proof your clients can present again, not just an internal record
- Instant revocation the moment fraud or a withdrawal is detected

Principle 3 · Identity Vault
Store less. Isolate what you do store.
Every record is encrypted before it's written to disk, with per-customer keys, so even the vault operator can't read it. Personal and business data stay in separate vaults, and when a retention window closes, the record is purged or anonymized automatically with a signed erasure certificate.
- AES-256 at rest with per-customer keys: trust-no-one by design
- Dual vault architecture: individual and business data isolated
- Access is consent-gated, checked on every record request
Principle 4 · Selective Disclosure
Share a yes or no. Not the underlying document.
Traditional verification hands a relying party the full document and biometric record, even for a single yes/no question. Selective disclosure (zero-knowledge proofs and BBS+ signatures) returns "over 18" or "KYC passed" without the document, DOB, or biometric ever leaving the vault. Minimization becomes structural, not a policy to enforce.
- Verifier gets a pass/fail claim, never the raw document
- Zero-knowledge proofs and BBS+ signatures, not a redaction step bolted on after the fact
- The same mechanism works for age, KYC status, or any other single claim
Mapped to the Law
DPDP and GDPR clauses, mapped to Compass.
DPDP Act 2023 (India)
GDPR (EU)
Every Feature, One Place
The full Compass feature set.
Purpose-Based Consent
Verification, AML, storage, marketing: each captured and revoked independently.
Signed Consent Receipts
Issued as a PDF and a W3C Verifiable Credential, not just a database row.
Jurisdiction Presets
DPDP, GDPR, and eIDAS 2.0 as configurable presets on one engine.
Reusable Verifiable Credentials
A completed check becomes a portable, W3C-standard credential.
Instant Revocation
Credentials revoked the moment fraud or a withdrawal is detected.
Encrypted Identity Vault
AES-256 at rest with per-customer keys, so even Compass can't read it.
Dual Vault Architecture
Individual and business data isolated by design.
Automated Retention & Erasure
Windows close automatically with a signed erasure certificate.
Selective Disclosure
Share a pass/fail claim through zero-knowledge proofs, never the document.
Consent-Gated Access
Vault access checked against live consent on every request.
Signed Webhooks
HMAC-SHA256 signed, session-scoped, no long-lived credentials.
Audit Trail
Every consent and access event logged and producible on demand.
For Your Customers
Less data liability for the businesses you sell to.
What Compass changes for you also changes for your customers. They receive a claim, not raw documents, so it's a smaller breach surface on their side and one less compliance gap for their own vendor review to flag.
- They get a pass/fail claim through selective disclosure, never the raw document
- Their users inherit a reusable credential instead of re-verifying every time
- A signed audit trail they can hand their own regulators or auditors
- Your compliance posture clears their vendor security review instead of stalling it
Where Compass Fits
Not a consent platform. Not a replacement for your engine.
A general-purpose CMP covers your whole business: cookies, marketing, partner data-sharing. Compass covers one moment, the identity check itself: consent, credentialing, and minimization built in as an API layer beside your engine, not inside it. Your verification stack stays yours.
FAQ
Everything about Hypersign Compass
Your verification engine.
Compass underneath it.
Talk to our compliance team about adding consent, credentials, a vault, and selective disclosure alongside the KYC stack you already run.
From the Blog

Best Digio Alternatives for DPDP-Compliant Aadhaar KYC (2026)
Digio's Aadhaar eSign and KYC line predates DPDP consent rules, sold separately via its CoTrust add-on. Compare 7 real Digio alternatives, including Hypersign.

Best Jukshio Alternatives for Video KYC in India (2026)
Jukshio's privacy policy never mentions India's DPDP Act. See how six real Jukshio alternatives compare on video KYC coverage and DPDP-ready consent handling.

Socure & IDnow Alternatives for India Expansion (2026)
Socure's fraud-risk scoring and IDnow's supervised video-ident are both strong in their home markets, but neither publishes a single India-specific claim. Here's where each actually fits, and the one alternative built for the DPDP, CKYC, and Aadhaar gap both leave open.

Best IDfy Alternatives for DPDP-Compliant KYC (2026)
IDfy's DPDP tool, Privy, is a separate product from its KYC API, not built into verification. See six real IDfy alternatives, including one that builds it in.

Best Sumsub Alternatives for DPDP-Compliant KYC (2026)
Sumsub's AML, KYB, and Travel Rule tools sit behind a $299/month tier or a custom Enterprise quote, and nothing on its site addresses India's DPDP Act. Here's how seven real Sumsub alternatives compare, including the one built for DPDP-regulated fintechs and Web3 teams.

Best Trulioo Alternatives for India-Compliant KYC (2026)
Trulioo's own site claims 195 countries and 450+ data sources, but nothing on it, including its India KYC blog post, mentions CKYC or the DPDP Act. Here's how seven real Trulioo alternatives compare, including the one built for DPDP-regulated Indian fintechs.

DPDP Consent Manager vs. Consent Management Platform vs. KYC-Embedded Consent: What Your Fintech Actually Needs
"Consent Manager" is a specific, registered role under the DPDP Act. A "consent management platform" is a software category most vendors selling into fintech actually belong to. Neither is the same as consent captured at the KYC moment. Here's the boundary between all three, and which one (or two) a fintech actually needs.

Your Account Aggregator License Meets DPDP for Financial Data Consent. It Was Never Built for KYC Consent.
RBI built the Account Aggregator framework to move financial data with consent and nothing else. It was never scoped to cover PAN, Aadhaar, or biometric KYC consent and that's exactly the part of onboarding still sitting with whichever KYC vendor an NBFC plugged in years ago. Here's the boundary, mapped point-to-point against DPDP.

cKYC Doesn't Mean "Verify Once" Anymore: The OTP and Stale-Data Problem Under DPDP
cKYC was built so a bank could pull a customer's verified identity once and skip re-KYC. Since April 2025, every pull needs a fresh OTP and the record sitting behind that OTP is often years out of date. How cKYC actually works, why DPDP just made reuse harder, and what fixes both problems at once.

DPDP Act Compliance for Fintech KYC: What Changes, and What Your Stack Needs to Handle It
India's DPDP Act doesn't replace RBI's KYC Master Directions it runs alongside them, with a different legal basis, different retention logic, and its own penalties. Here's what that means for a fintech's KYC stack, mapped to the controls that actually satisfy it.

The PII Liability Hiding in Every Indian Event Company's Database and How to Stop Storing It
A ticketing platform running large venues doesn't just process payments it accumulates ID scans, face photos, and gig-worker documents by the thousand, every event. Under India's DPDP Act, every one of those records is a liability sitting in your database. Here's how to verify people without owning the data.