The people we verify are the people we protect.
An identity network is only as good as the promises it keeps about the data inside it. Civic Anchor makes those promises structural: biometrics that never leave the device, credentials the holder controls, and data held in the jurisdiction it belongs to.
Principles
Privacy by construction, not by policy.
These are not settings that can be toggled off under commercial pressure — they are properties of how the system is built.
Biometrics never leave the device
Verification runs against a privacy-preserving template bound to the holder’s own device. No raw biometric data lives on Civic Anchor infrastructure — in any jurisdiction.
The holder is in control
Identity, residency, and reputation are credentials the subject carries, presents with consent, and can revoke. Nothing is shared without an explicit, logged authorisation.
Residency by jurisdiction
Each country runs under its own data-protection framework and regulator, with data held in-partition. The substrate is continental; the compliance is local — by construction, not by exception.
Tamper-evident by design
Every verification is recorded in an append-only, tamper-evident log. Integrity is auditable, and entries are never deleted except on a lawful subject erasure request.
How it works
Verify a person without holding their biometrics.
The whole architecture is arranged so the most sensitive data never centralises. Here is the path a verification takes.
- 01
Captured on the device
Enrolment produces a privacy-preserving biometric template bound to the holder’s own device. The raw biometric is never transmitted to or stored on Civic Anchor infrastructure.
- 02
Presented with consent
The holder presents a verifiable credential and authorises each verification explicitly. There is no silent lookup and no shared biometric database for institutions to query.
- 03
Recorded, in jurisdiction
Each verification is written to a tamper-evident log inside the country’s own data-residency partition, under its data-protection regulator — auditable, and never silently altered.
Regulatory posture
One regulator per jurisdiction.
We do not run a single global data pool that every regulator must reason about. Each country’s data lives under that country’s framework, with its own legal entity and data-protection contact — so a regulator only ever has to reason about their own jurisdiction.
Data-protection frameworks in force
- South AfricaPOPIA — operating
- ZimbabweData Protection Act — onboarding
- Each new marketOpened under its own framework
Jurisdiction-specific data-protection contacts are published on each country site, not here.
Questions
The questions every serious counterparty asks.
Bring your security and compliance team.
We expect the hard questions — that is the point. Talk to us about an architecture review or a regulator-facing briefing in your jurisdiction.