Your verified identity, encrypted and yours alone.
Identity data becomes a long-term liability after verification unless you store it right. Encrypt, control, and erase every credential with built-in consent and lifecycle management.
Trusted by compliance and engineering teams across fintech, healthcare, Web3, and regulated industries.
Feature Overview
Everything You Need to Store Identity Safely
A complete identity storage stack with consent-linked access, lifecycle management, and compliance controls built in.
Dual Vault Architecture
Separate encrypted vaults for individual users and business entities each with its own access controls and lifecycle.
AES-256 Encryption
Every record encrypted at rest using AES-256-GCM. All transit protected by TLS 1.3. Keys managed per customer, not shared.
Consent-Linked Access Control
Access to stored records is gated by active consent. Withdraw consent, access stops automatically.
Full Lifecycle Management
Create, update, revoke, or expire any credential in the vault. Every change logged with a tamper-evident audit entry.
GDPR Right-to-Erasure Engine
Issue a deletion request; the vault purges the record and writes a signed erasure certificate within seconds.
Immutable Audit Log
Every read, write, update, and deletion is logged with timestamp, actor, and action type. Tamper-evident, queryable, exportable.
Dual Vault Architecture
One platform. Two vault types.
Individual users generate personal verification data documents, biometrics, consent records. Businesses generate entity data company records, UBO maps, director KYC. Hypersign provides a dedicated, isolated vault for each.
Storing personal and entity data in the same container creates governance conflicts. Separation by design means a GDPR erasure request from an individual never inadvertently affects the business entity record they were associated with, and vice versa.
AES-256 Encryption
Encrypted before it touches storage.
Trust-no-one security means the platform operator cannot read what is stored. Every identity record is encrypted before it is written to disk, with per-customer keys generated in a Hardware Security Module.
Bring your own key manager AWS KMS, Azure Key Vault, GCP Cloud KMS, or HashiCorp Vault. Keys rotate without data re-encryption downtime. Biometric templates are isolated under a separate Customer Master Key.
Consent-Linked Access Control
Access stops when consent stops.
Every record in the Identity Vault is tagged with the consent event that authorised its collection. Before any API call returns a vault record, the vault checks active consent for the requesting purpose.
Withdraw consent, and access stops automatically no application code changes required. Purpose codes travel with the credential downstream, enforcing access at every read point, not just at first collection.
Lifecycle Management
Every credential has a life.
Identity data is not static. Documents expire. KYC status changes. Users update addresses. Organisations change directors. Hypersign gives you full lifecycle control over every record update, revoke, expire, suspend, or delete all via REST API or dashboard.
Every state change emits a typed webhook event. Downstream systems stay in sync automatically. Every operation is logged with a tamper-evident audit entry.
GDPR Right-to-Erasure Engine
Delete on demand. Prove you did it.
GDPR Article 17 requires erasure of every version, every cached copy, every downstream reference and proof the deletion happened. Hypersign handles all of it automatically: purge, anonymise, notify, and certify.
A signed erasure certificate is generated on completion a machine-readable proof of deletion, timestamped and hashed, designed to satisfy Article 17 documentation requirements. Erasure completes at p99 in under two seconds.
Immutable Audit Log
Every access. Every change. Every decision.
Regulators don't ask what happened. They ask for proof. Every read, write, update, revocation, expiry, and deletion is logged with event type, actor, purpose code, consent reference, timestamp, and a SHA-256 hash for tamper detection.
Modifying any field in a log entry invalidates its hash tampering is detected and surfaced immediately. Logs are queryable by subject, date range, event type, actor, purpose, and outcome. Exportable as JSON, CSV, or via real-time webhook to your SIEM.
Verifiable Credentials Storage
Standards-based identity portability.
The Identity Vault stores W3C Verifiable Credentials portable, cryptographically signed identity proofs that can be shared without re-verification. Once a user is verified, their credential is stored and reusable across any platform that accepts Hypersign-issued VCs.
BBS+ selective disclosure lets users share only specific attributes from a stored credential prove age without revealing date of birth, prove nationality without sharing document number. Third parties verify the signature, not the raw data.
Integration
Three Integration Paths
From automatic storage to full API control. All backed by the same identity vault infrastructure.
Hosted Vault
Any Hypersign verification session · Zero additional integration
Identity records are stored automatically in the vault as part of any Hypersign verification session. Access through the dashboard or API.
- Automatic storage on verification
- Dashboard access to all records
- REST API for read, manage, erase
- No additional integration required
REST API
Enterprise platforms · KYC pipelines · Compliance dashboards
Full CRUD access to vault records via a typed REST API. Create, retrieve, update, trigger lifecycle operations, and query the audit log.
- Full record CRUD operations
- Lifecycle state management
- Audit log query and export
- Webhook event subscriptions
SDK
Product teams · Native mobile · In-app identity flows
The Hypersign SDK exposes vault read and write operations natively. Display identity data, trigger updates, handle lifecycle webhooks in real time.
- JavaScript & mobile SDK
- Native vault read/write
- Erasure requests from your UI
- Real-time webhook event handling
Vault read (p99): under 150ms · Vault write (p99): under 200ms · Erasure completion (p99): under 2 seconds
Performance
Built for Scale
Infrastructure
Compliance & Certifications
Storage That Satisfies Regulators
Certifications
Regulatory Frameworks
Use Cases
Who Uses Identity Vault
Fintech & Neobanks
Store verified KYC records with AES-256 encryption and full audit trail. Meet GDPR retention requirements and respond to regulatory inspection requests in seconds, not days.
Crypto & Web3
Keep verified identity on file for Travel Rule compliance and ongoing AML monitoring. Issue Verifiable Credentials so users can prove verification across wallets without re-submitting documents.
Healthcare & Telehealth
Store patient identity securely with consent-linked access control. Meet HIPAA and national eHealth storage requirements. Right-to-erasure handles GDPR and DPDP requests automatically.
iGaming & Betting
Retain age and identity verification records for regulatory inspection. Erase on request without manual effort. Business Vault tracks operator entity compliance alongside player KYC records.
Enterprise SaaS & HR
Store verified employee and contractor identity across the full workforce lifecycle. Suspend access on contract end, revoke on policy violation, produce records for audits without manual retrieval.
BNPL & Lending
Retain verified borrower identity for credit decisioning audit trails. Honour right-to-erasure at the end of the lending relationship. Data minimisation removes excess data after retention windows close.
Why Hypersign vs. Generic Encrypted Storage
More Than Encrypted Storage
Generic object stores encrypt files. Hypersign Identity Vault encrypts identity data with the compliance controls that identity data specifically requires.
Why Hypersign
Identity storage built for compliance, not just security.
Most encrypted storage products protect files from external attackers. Hypersign Identity Vault protects verified identity data from the full range of legal, regulatory, and operational risks it faces throughout its lifecycle.
- Dual vault types User Vault and Business Vault
- AES-256 encryption at rest with customer-managed keys
- TLS 1.3 in transit on every API call and SDK event
- Consent-linked access control access blocked automatically when consent lapses
- GDPR right-to-erasure engine signed erasure certificate on completion
- Data minimisation and configurable retention windows per record type
- Full lifecycle management create, update, expire, revoke, suspend, delete
- Immutable audit log with tamper detection on every entry
- W3C Verifiable Credentials storage for portable identity proofs
- BBS+ selective disclosure for data-minimised credential sharing
- External Key Manager (EKM) support bring your own HSM or cloud KMS
- Webhook events on every lifecycle state change
FAQ
Everything about Identity Vault
Store identity safely.
From collection to erasure.
Deploy encrypted identity storage with consent-linked access, full lifecycle management, and GDPR right-to-erasure in days. Talk to our team about the right setup for your compliance requirements.
Identity Vault API · Encrypted Identity Storage · AES-256 Data Vault · GDPR Right-to-Erasure