New: Hypersign is now eIDAS 2.0 ready verifiable credentials and EUDI Wallet compliance built in. See case studies →
← Platform
Platform

Every data share needs consent. Here is the proof.

Consent is a legal record, not a checkbox. Hypersign captures it at verification, timestamps it cryptographically, and produces a complete audit trail on demand.

✓ GDPR Article 7 Compliant✓ Immutable Audit Log✓ Purpose-Level Granularity✓ Multi-Jurisdictional Rules✓ Consent Receipts (PDF + VC)

Trusted by compliance teams across fintech, healthcare, Web3, and regulated industries.

10M+
Consent Events
30+
Jurisdictions
8+
Regulations
< 2s
Time to Record

Feature Overview

Everything You Need to Prove Consent

A complete consent management stack from explicit capture to lifecycle management in one platform.

Explicit Consent Capture

Capture affirmative user consent at the point of identity verification not after, not assumed.

Purpose-Based Disclosure

Display clear, granular purposes at consent time. Users see exactly what they are agreeing to.

Immutable Audit Log

Every consent event is timestamped, signed, and stored in a tamper-evident log you can query instantly.

Consent Receipts

Issue a machine-readable receipt confirming what was consented to and when PDF, JSON, or W3C VC.

Consent Lifecycle Management

Track consent status across its full lifecycle active, withdrawn, expired, or refreshed.

Multi-Jurisdictional Rules

Configure different consent flows for GDPR, DPDP, CCPA and more from a single platform.

Explicit Consent Capture

Consent at the moment that matters.

Hypersign captures consent at the start of verification when the user is present, the purpose is clear, and the record is legally meaningful. The audit entry is written before any data is processed.

Consent Capture
Affirmative Consent Collection
● Captured
User Identifier✓ Recorded
Timestamp (ISO 8601 UTC)✓ Sealed
Purposes Consented To✓ 3 of 3
Capture Method✓ Click-to-agree

Purpose-Based Disclosure

Consent for specific purposes, not blanket permission.

A blanket "I agree" is not GDPR consent. Users see each purpose clearly and accept or decline individually every decision recorded as its own event.

Purpose-Based Consent
IDENTITY_VERIFICATION✓ Accepted
AML_SCREENING✓ Accepted
DOCUMENT_STORAGE✓ Accepted
MARKETING_PERSONALISATION✗ Declined

Immutable Audit Log

Prove consent to any regulator, any time.

GDPR places the burden of proof on you. Every event is timestamped, signed, and SHA-256 hashed at write time queryable and exportable on demand for any regulator.

Audit Log
Tamper-Evident Record
● Sealed
consent.given2026-06-15 09:42:11Z
consent.refreshed2026-01-08 14:17:03Z
consent.withdrawn2025-09-20 11:55:44Z

Consent Receipts

A machine-readable record for every agreement.

A signed, structured record issued at the moment consent is given delivered as PDF to the user, JSON to your systems, and W3C Verifiable Credential for identity wallets.

Consent Receipt
Format: PDF✓ Issued
Format: JSON✓ Issued
Format: W3C VC✓ Issued
Delivered to User✓ Sent

Consent Lifecycle Management

Consent is not a one-time event.

Consent can be withdrawn, expire, or need refreshing when notice text changes. Hypersign tracks every transition and fires a webhook so downstream systems react immediately.

Consent Lifecycle
State Tracking
● Active
ActiveProcessing permitted
WithdrawnProcessing must stop
Expired⚑ Re-consent required
consent.withdrawn↩ Webhook fired

Multi-Jurisdictional Consent

One platform. Every regulation.

Configure GDPR, DPDP, CCPA, and more from a single platform. Jurisdiction is auto-detected per user and the appropriate notice is shown no separate flows per market.

Multi-Jurisdictional Rules
GDPR (EU)✓ Active
DPDP Act 2023 (India)✓ Active
CCPA / CPRA (California)✓ Active
eIDAS 2.0 (EU)✓ Active

Integration

Three Integration Paths

From no-code to full API control. All backed by the same consent infrastructure.

Drop-in Hosted Flow

No-code teams · Fast deployments · Embedded journeys

Embed a hosted consent step into your existing verification flow with a single URL parameter. No front-end code required.

  • No integration required
  • Consent modal rendered by Hypersign
  • Audit record created automatically
  • Session returns with consent event attached
Learn more →

JavaScript / Mobile SDK

Product teams · Custom UI · Native mobile

Use the Hypersign SDK to render a native consent component inside your own UI. Full control over styling, flow position, and language.

  • Full UI control
  • Custom branding and language
  • SDK handles audit writing
  • Receipt generation included
Learn more →

Consent API (REST)

Enterprise platforms · Compliance dashboards · Data governance

Programmatically create, query, and update consent records. Integrate into your own onboarding flow or compliance dashboard.

  • Full CRUD on consent records
  • Typed JSON API
  • Webhook stream or batch export
  • Query by user, session, date, or purpose
Learn more →

Consent event write: under 200ms at p99  ·  Consent record query: under 100ms at p99

Response Structure

Structured Consent Records Your Systems Can Act On

Every consent event returns a consistent, typed JSON record regardless of jurisdiction or purpose configuration.

Consent Event Response Fields

consent_idsubject_idsession_idevent_typetimestamppurposes[]consent_versionmethodjurisdictionlanguagereceipt_urlreceipt_vcrecord_hashcontroller_iduser_agentip_address

Consent Status Values

ActiveUser has given consent; processing is permitted.
WithdrawnUser exercised Right to Withdraw; processing must stop.
ExpiredConsent period has elapsed; re-consent required.
Pending RefreshConsent text updated; re-consent flow triggered.
DeclinedUser was shown the notice and actively refused.
Not CollectedUser exists but no consent record is on file.

Performance

Built for Scale

Consent event write (p99)Under 200ms
Consent record query (p99)Under 100ms
Audit log exportReal-time stream or batch
Platform uptime99.99% SLA
Jurisdictions supported30+
Languages supported30+
Consent events processed10M+

Infrastructure

All consent records encrypted at rest (AES-256) and TLS 1.3 in transit
Stored in the European Union by default; US and APAC regions available
WORM (Write Once Read Many) log storage for tamper-evident records
Configurable data residency per jurisdiction
Per-record deletion on Right to Erasure request with deletion audit event
Pen-tested quarterly

Compliance & Certifications

Consent That Satisfies Regulators

Certifications

SOC 2 Type IAICPA · audit-ready, certification in progress · 2026
ISO/IEC 27001:2022International · audit-ready, certification in progress · 2026

Regulatory Frameworks Supported

GDPR (EU 2016/679) Art.7DPDP Act 2023 (India)CCPA / CPRA (California)UK GDPReIDAS 2.0 (EU)PIPEDA (Canada)APPI (Japan)PDPA (Thailand / Singapore)DORA (EU 2022/2554)

Use Cases

Who Uses Consent Management

Fintech & Neobanks

Capture GDPR and DPDP-compliant consent at account opening. Produce audit records for regulatory inspection without manual effort.

Healthcare & Telehealth

Record patient consent for data sharing before any health data is processed. Meet HIPAA and national eHealth consent requirements in a single flow.

Crypto & Web3

Capture user consent for wallet screening, Travel Rule compliance, and sanctions checks. Log it before any data leaves your platform.

iGaming & Betting

Consent for age verification, marketing communications, and responsible gambling tools each purpose tracked separately, each withdrawal honoured instantly.

Enterprise SaaS

Embed consent into your B2B onboarding. Collect, version, and produce consent records for data processing agreements and DPA schedules.

BNPL & Lending

Obtain explicit consent for credit bureau queries and fraud screening before running checks. Produce the record as part of your credit decision file.

Why Hypersign vs. Standalone CMPs

More Than a Consent Banner

Most consent management platforms were built for cookie banners. Hypersign was built for identity data the highest-sensitivity category in any organisation's data estate.

CapabilityCookie / Banner CMPHypersign
Consent at point of identity verification
Linked to verified user identity
Biometric-backed consent
Purpose-level granularitySometimes
Immutable tamper-evident audit logRarely
Consent receipts (PDF + Verifiable Credential)
Multi-jurisdictional rules engineAdd-on
Right-to-withdraw webhook
Consent lifecycle (expiry / refresh / version)
Integration with KYC / AML pipeline
W3C Verifiable Credential consent proof

Why Hypersign

Consent that is part of your identity infrastructure, not separate from it.

Most organisations treat consent as a layer on top of their compliance stack. Hypersign embeds consent into every identity event so there is no gap between what you collected and what you have permission to use.

  • Explicit consent at the point of identity verification
  • Purpose-level granularity not blanket permission
  • Immutable, tamper-evident audit log
  • Consent receipts in PDF and Verifiable Credential format
  • Right-to-withdraw in under 2 seconds
  • Consent expiry tracking and automatic re-consent triggering
  • Multi-jurisdictional rules GDPR, DPDP, CCPA, eIDAS 2.0
  • Webhook events for every consent state change
  • Integrated with ID Verification, Biometrics, AML, and Credential Vault
Hypersign Consent Management
Explicit Consent Capture
Purpose-Level Granularity
Immutable Audit Log
Consent Receipts (PDF + W3C VC)
Right-to-Withdraw in Under 2 Seconds
Consent Expiry Tracking
Automatic Re-Consent Triggering
Multi-Jurisdictional Rules Engine
Webhook Events on Every State Change
Integrated with ID Verification & AML

FAQ

Everything about consent management

Prove consent to any regulator.
From any jurisdiction. Instantly.

Deploy GDPR Article 7 compliant consent capture with purpose-level granularity, immutable audit log, and consent receipts in days. Talk to our team about the right setup for your compliance requirements.

Consent Management API · GDPR Consent Platform · Digital Consent Infrastructure