New: Hypersign is now eIDAS 2.0 ready verifiable credentials and EUDI Wallet compliance built in. See case studies →
← Platform
Platform

Your verified identity, encrypted and yours alone.

Identity data becomes a long-term liability after verification unless you store it right. Encrypt, control, and erase every credential with built-in consent and lifecycle management.

✓ AES-256 at Rest✓ TLS 1.3 in Transit✓ GDPR Right-to-Erasure✓ Dual Vault Architecture✓ W3C Verifiable Credentials

Trusted by compliance and engineering teams across fintech, healthcare, Web3, and regulated industries.

10M+
Records Encrypted
Dual Vault
User & Business
8+
Regulations Covered
AES-256
Encryption at Rest

Feature Overview

Everything You Need to Store Identity Safely

A complete identity storage stack with consent-linked access, lifecycle management, and compliance controls built in.

Dual Vault Architecture

Separate encrypted vaults for individual users and business entities each with its own access controls and lifecycle.

AES-256 Encryption

Every record encrypted at rest using AES-256-GCM. All transit protected by TLS 1.3. Keys managed per customer, not shared.

Consent-Linked Access Control

Access to stored records is gated by active consent. Withdraw consent, access stops automatically.

Full Lifecycle Management

Create, update, revoke, or expire any credential in the vault. Every change logged with a tamper-evident audit entry.

GDPR Right-to-Erasure Engine

Issue a deletion request; the vault purges the record and writes a signed erasure certificate within seconds.

Immutable Audit Log

Every read, write, update, and deletion is logged with timestamp, actor, and action type. Tamper-evident, queryable, exportable.

Dual Vault Architecture

One platform. Two vault types.

Individual users generate personal verification data documents, biometrics, consent records. Businesses generate entity data company records, UBO maps, director KYC. Hypersign provides a dedicated, isolated vault for each.

Storing personal and entity data in the same container creates governance conflicts. Separation by design means a GDPR erasure request from an individual never inadvertently affects the business entity record they were associated with, and vice versa.

User Identity Vault
Verified Documents
Biometric Templates
Verifiable Credentials
Consent Records
Business Identity Vault
Company Registry
UBO Verification
Director KYC Records
Risk Scoring History

AES-256 Encryption

Encrypted before it touches storage.

Trust-no-one security means the platform operator cannot read what is stored. Every identity record is encrypted before it is written to disk, with per-customer keys generated in a Hardware Security Module.

Bring your own key manager AWS KMS, Azure Key Vault, GCP Cloud KMS, or HashiCorp Vault. Keys rotate without data re-encryption downtime. Biometric templates are isolated under a separate Customer Master Key.

Encryption Stack
End-to-End Protection
● Active
Data at RestAES-256-GCM
Data in TransitTLS 1.3
Biometric DataSeparate CMK
Key DerivationPBKDF2 / HKDF

Consent-Linked Access Control

Access stops when consent stops.

Every record in the Identity Vault is tagged with the consent event that authorised its collection. Before any API call returns a vault record, the vault checks active consent for the requesting purpose.

Withdraw consent, and access stops automatically no application code changes required. Purpose codes travel with the credential downstream, enforcing access at every read point, not just at first collection.

Consent Access Check
Consent active, purpose match✓ Granted
Purpose mismatch✗ 403
Consent withdrawn✗ 403
Consent expired✗ 403
Record deleted404

Lifecycle Management

Every credential has a life.

Identity data is not static. Documents expire. KYC status changes. Users update addresses. Organisations change directors. Hypersign gives you full lifecycle control over every record update, revoke, expire, suspend, or delete all via REST API or dashboard.

Every state change emits a typed webhook event. Downstream systems stay in sync automatically. Every operation is logged with a tamper-evident audit entry.

Credential States
Lifecycle Engine
● Live
Active✓ Access permitted
Expired⚑ Re-verify
Revoked✗ Invalidated
Suspended⚑ Under review
DeletedErased

GDPR Right-to-Erasure Engine

Delete on demand. Prove you did it.

GDPR Article 17 requires erasure of every version, every cached copy, every downstream reference and proof the deletion happened. Hypersign handles all of it automatically: purge, anonymise, notify, and certify.

A signed erasure certificate is generated on completion a machine-readable proof of deletion, timestamped and hashed, designed to satisfy Article 17 documentation requirements. Erasure completes at p99 in under two seconds.

Erasure Engine · GDPR Art.17
Request received✓ Done
All versions purged✓ Done
Audit anonymised✓ Done
Webhook dispatched✓ Done
Erasure certificate issued✓ Done

Immutable Audit Log

Every access. Every change. Every decision.

Regulators don't ask what happened. They ask for proof. Every read, write, update, revocation, expiry, and deletion is logged with event type, actor, purpose code, consent reference, timestamp, and a SHA-256 hash for tamper detection.

Modifying any field in a log entry invalidates its hash tampering is detected and surfaced immediately. Logs are queryable by subject, date range, event type, actor, purpose, and outcome. Exportable as JSON, CSV, or via real-time webhook to your SIEM.

Audit Log Entry
Tamper-Evident · WORM
● Secure
event_typeread
timestampISO 8601 UTC
purposekyc.verify
outcomegranted
log_entry_hashSHA-256 ✓

Verifiable Credentials Storage

Standards-based identity portability.

The Identity Vault stores W3C Verifiable Credentials portable, cryptographically signed identity proofs that can be shared without re-verification. Once a user is verified, their credential is stored and reusable across any platform that accepts Hypersign-issued VCs.

BBS+ selective disclosure lets users share only specific attributes from a stored credential prove age without revealing date of birth, prove nationality without sharing document number. Third parties verify the signature, not the raw data.

Verifiable Credential · W3C VC 2.0
typeAgeVerification
claim: over18true
issuerHypersign
signatureBBS+ ✓
formatJSON-LD · JWT

Integration

Three Integration Paths

From automatic storage to full API control. All backed by the same identity vault infrastructure.

Hosted Vault

Any Hypersign verification session · Zero additional integration

Identity records are stored automatically in the vault as part of any Hypersign verification session. Access through the dashboard or API.

  • Automatic storage on verification
  • Dashboard access to all records
  • REST API for read, manage, erase
  • No additional integration required
Learn more →

REST API

Enterprise platforms · KYC pipelines · Compliance dashboards

Full CRUD access to vault records via a typed REST API. Create, retrieve, update, trigger lifecycle operations, and query the audit log.

  • Full record CRUD operations
  • Lifecycle state management
  • Audit log query and export
  • Webhook event subscriptions
Learn more →

SDK

Product teams · Native mobile · In-app identity flows

The Hypersign SDK exposes vault read and write operations natively. Display identity data, trigger updates, handle lifecycle webhooks in real time.

  • JavaScript & mobile SDK
  • Native vault read/write
  • Erasure requests from your UI
  • Real-time webhook event handling
Learn more →

Vault read (p99): under 150ms  ·  Vault write (p99): under 200ms  ·  Erasure completion (p99): under 2 seconds

Performance

Built for Scale

Vault read (p50)Under 80ms
Vault read (p99)Under 150ms
Vault write (p99)Under 200ms
Erasure completion (p99)Under 2 seconds
Audit log queryUnder 100ms
Platform uptime99.99% SLA
Records supportedUnlimited per account
Encryption standardAES-256-GCM at rest

Infrastructure

Data processed and stored in the European Union by default
US and APAC regions available for data residency requirements
Hosted on AWS with AES-256 encryption at rest and TLS 1.3 in transit
Biometric data stored under a separate Customer Master Key
Configurable data retention: 30 days to 10 years or indefinite
External Key Manager (EKM) support: AWS KMS, Azure Key Vault, GCP Cloud KMS, HashiCorp Vault
Hardware Security Module (HSM) for key generation and storage
WORM log storage for tamper-evident audit records
Pen-tested quarterly

Compliance & Certifications

Storage That Satisfies Regulators

Certifications

SOC 2 Type IAICPA · audit-ready, certification in progress · 2026
ISO/IEC 27001:2022International · audit-ready, certification in progress · 2026

Regulatory Frameworks

GDPR (EU 2016/679) Art.17DPDP Act 2023CCPA / CPRAUK GDPReIDAS 2.0DORA (EU 2022/2554)HIPAAFATF Travel Rule / IVMS-101

Use Cases

Who Uses Identity Vault

Fintech & Neobanks

Store verified KYC records with AES-256 encryption and full audit trail. Meet GDPR retention requirements and respond to regulatory inspection requests in seconds, not days.

Crypto & Web3

Keep verified identity on file for Travel Rule compliance and ongoing AML monitoring. Issue Verifiable Credentials so users can prove verification across wallets without re-submitting documents.

Healthcare & Telehealth

Store patient identity securely with consent-linked access control. Meet HIPAA and national eHealth storage requirements. Right-to-erasure handles GDPR and DPDP requests automatically.

iGaming & Betting

Retain age and identity verification records for regulatory inspection. Erase on request without manual effort. Business Vault tracks operator entity compliance alongside player KYC records.

Enterprise SaaS & HR

Store verified employee and contractor identity across the full workforce lifecycle. Suspend access on contract end, revoke on policy violation, produce records for audits without manual retrieval.

BNPL & Lending

Retain verified borrower identity for credit decisioning audit trails. Honour right-to-erasure at the end of the lending relationship. Data minimisation removes excess data after retention windows close.

Why Hypersign vs. Generic Encrypted Storage

More Than Encrypted Storage

Generic object stores encrypt files. Hypersign Identity Vault encrypts identity data with the compliance controls that identity data specifically requires.

CapabilityGeneric Encrypted StorageHypersign
AES-256 encryption at rest
TLS 1.3 in transit
Customer-managed encryption keysAdd-on
Consent-linked access control
GDPR right-to-erasure engine
Immutable audit log per record
Identity credential lifecycle (expire / revoke / suspend)
Dual vault types (User + Business)
W3C Verifiable Credential storage
BBS+ selective disclosure
Consent management integration
Data minimisation and auto-purge
Erasure certificate (signed proof of deletion)
KYC / KYB pipeline integration

Why Hypersign

Identity storage built for compliance, not just security.

Most encrypted storage products protect files from external attackers. Hypersign Identity Vault protects verified identity data from the full range of legal, regulatory, and operational risks it faces throughout its lifecycle.

  • Dual vault types User Vault and Business Vault
  • AES-256 encryption at rest with customer-managed keys
  • TLS 1.3 in transit on every API call and SDK event
  • Consent-linked access control access blocked automatically when consent lapses
  • GDPR right-to-erasure engine signed erasure certificate on completion
  • Data minimisation and configurable retention windows per record type
  • Full lifecycle management create, update, expire, revoke, suspend, delete
  • Immutable audit log with tamper detection on every entry
  • W3C Verifiable Credentials storage for portable identity proofs
  • BBS+ selective disclosure for data-minimised credential sharing
  • External Key Manager (EKM) support bring your own HSM or cloud KMS
  • Webhook events on every lifecycle state change
Hypersign Identity Vault
User Identity Vault
Business Identity Vault
AES-256-GCM at rest
TLS 1.3 in transit
Customer-managed encryption keys
Consent-linked access control
GDPR right-to-erasure engine
Signed erasure certificate
Data minimisation & auto-purge
Immutable audit log
W3C Verifiable Credentials
BBS+ selective disclosure

FAQ

Everything about Identity Vault

Store identity safely.
From collection to erasure.

Deploy encrypted identity storage with consent-linked access, full lifecycle management, and GDPR right-to-erasure in days. Talk to our team about the right setup for your compliance requirements.

Identity Vault API · Encrypted Identity Storage · AES-256 Data Vault · GDPR Right-to-Erasure