Trust & security

The people we verify are the people we protect.

An identity network is only as good as the promises it keeps about the data inside it. Civic Anchor makes those promises structural: biometrics that never leave the device, credentials the holder controls, and data held in the jurisdiction it belongs to.

Principles

Privacy by construction, not by policy.

These are not settings that can be toggled off under commercial pressure — they are properties of how the system is built.

Biometrics never leave the device

Verification runs against a privacy-preserving template bound to the holder’s own device. No raw biometric data lives on Civic Anchor infrastructure — in any jurisdiction.

The holder is in control

Identity, residency, and reputation are credentials the subject carries, presents with consent, and can revoke. Nothing is shared without an explicit, logged authorisation.

Residency by jurisdiction

Each country runs under its own data-protection framework and regulator, with data held in-partition. The substrate is continental; the compliance is local — by construction, not by exception.

Tamper-evident by design

Every verification is recorded in an append-only, tamper-evident log. Integrity is auditable, and entries are never deleted except on a lawful subject erasure request.

How it works

Verify a person without holding their biometrics.

The whole architecture is arranged so the most sensitive data never centralises. Here is the path a verification takes.

  1. 01

    Captured on the device

    Enrolment produces a privacy-preserving biometric template bound to the holder’s own device. The raw biometric is never transmitted to or stored on Civic Anchor infrastructure.

  2. 02

    Presented with consent

    The holder presents a verifiable credential and authorises each verification explicitly. There is no silent lookup and no shared biometric database for institutions to query.

  3. 03

    Recorded, in jurisdiction

    Each verification is written to a tamper-evident log inside the country’s own data-residency partition, under its data-protection regulator — auditable, and never silently altered.

Regulatory posture

One regulator per jurisdiction.

We do not run a single global data pool that every regulator must reason about. Each country’s data lives under that country’s framework, with its own legal entity and data-protection contact — so a regulator only ever has to reason about their own jurisdiction.

Data-protection frameworks in force

  • South AfricaPOPIA — operating
  • ZimbabweData Protection Act — onboarding
  • Each new marketOpened under its own framework

Jurisdiction-specific data-protection contacts are published on each country site, not here.

Questions

The questions every serious counterparty asks.

On the holder’s device, as a privacy-preserving template — never as raw biometric data on our infrastructure. Verification compares against that on-device template; we operate no central biometric database that an institution, an attacker, or a government could query.

Bring your security and compliance team.

We expect the hard questions — that is the point. Talk to us about an architecture review or a regulator-facing briefing in your jurisdiction.