Technology controls for identity, compliance, document intelligence, municipal workflows, and governed AI.
The Deis stack connects verification, document intelligence, compliance controls, municipal workflow, and enterprise AI in a technology foundation that can support regulated operations without fragmenting control, evidence, integration, and workflow ownership.
Connected capabilities that work together in regulated environments.
Deis covers identity, compliance, extraction, decisioning, municipal workflow, and AI governance. The technology story works best when those capabilities are shown as one connected foundation rather than a list of disconnected systems.
Platform
Lending Technology
Bank-statement analysis, OCR-led affordability logic, bureau-aware decisioning, DebiCheck-ready mandate handling, and loan-origination workflows designed for microlenders and financial institutions.
- OCR for payslips and bank statements
- Automated affordability assessment and scorecards
- Credit bureau switching capability
- Real-time loan origination support
- Comprehensive audit trails and review history
Platform
ComplyHub
FICA and AML controls with direct identity checks, sanctions screening, adverse-media review, goAML-ready reporting, and compliance operations built around auditable workflows.
- Home Affairs, CIPC, and Deeds integrations
- PEP, sanctions, and adverse-media screening
- Centralized compliance dashboard and reporting
- Risk-based customer due diligence workflows
- Audit-ready documentation and escalation handling
Platform
ID Trust
Real-time identity verification with facial biometrics, liveness detection, fingerprint support, passport review, and unified verification APIs.
- Biometric authentication
- Liveness detection
- Document tamper review
- Home Affairs verification support
- Unified verification API
Platform
OCR Platform
Document parsing and extraction for affordability checks, compliance validation, transaction classification, and supporting operational flows across bank statements, payslips, IDs, invoices, and supporting records.
- Multi-document support
- Structured data output and validation
- Authenticity and document-trust logic
- Income and affordability analysis
- Real-time processing capabilities
Platform
Indigent Management
Municipal workflow platform for digitizing indigent and grant operations, eligibility checks, field capture, fraud review, and GPS-enabled programme management.
- Mobile-first data collection
- Eligibility verification
- Fraud detection and mapping
- Grant lifecycle automation
- Resource optimization insights
Platform
CorpAI
Governed enterprise AI extends the wider stack with document-grounded assistance, provider flexibility, approval controls, and auditable AI operations.
- Multi-provider AI orchestration
- Document-grounded AI vaults and approvals
- Human-in-the-loop action controls
- Traceable prompts, retrieval, and decisions
- Tenant-aware AI governance and access control
Why the platform is defensible in regulated environments.
The technical value is the combination of modular APIs, audit-ready service design, regulated-workflow fit, and the ability to run multiple trust-critical processes on one connected foundation.
API-first and modular
The stack is designed as API-first services that can operate together or be slotted into an existing workflow without a full replacement programme.
Deploy one capability first, then expand without re-architecting the whole operating model.
Audit-logged and integration-ready
The technology foundation assumes live integrations, audit logging, and fallback-aware service boundaries so teams can deploy one capability or the full stack with clearer control.
Keep evidence, routing, approvals, and operational history intact as the platform surface grows.
South African regulated-workflow fit
The target system design assumes use in financial services and public-sector environments where implementation risk, auditability, and operational discipline matter.
Work with local identity, bureau, public-sector, compliance, and payment realities instead of forcing generic global patterns.
Field-tested and proven
The platforms have been shaped for corporate lenders, financial institutions, and municipalities where scrutiny, continuity, and operator adoption matter.
Reduce implementation risk by starting from workflows that have already been pressure-tested in live environments.
One lending stack without one-bureau lock-in.
Most lending platforms force a permanent bureau choice. The Deis lending stack keeps bureau connectivity flexible so operators can protect continuity, economics, and routing decisions as volumes change.
Multi-bureau flexibility
Switch between major South African credit bureaus or split traffic across multiple providers instead of being locked into one bureau relationship.
Enhanced negotiating power
Use platform-level flexibility to negotiate pricing and commercial terms with bureau partners from a stronger position.
Improved reliability
Introduce fallback options when a primary bureau is degraded or unavailable so origination does not stop with one provider outage.
Four layers that turn technical capability into usable delivery.
Deis technology is not only about integrations. It depends on operational controls, product surfaces, and API-backed capabilities that can support live workflow execution.
Integration layer
Connect Home Affairs, CIPC, Deeds, bureau, messaging, payment, and document-verification rails through one API-first stack.
Control layer
Preserve audit trails, verification evidence, webhook integrity, approval steps, and tenant boundaries across live workflows.
Operator layer
Give teams usable product surfaces for compliance, lending, municipal operations, payment support, and governed AI adoption.
Fallback-aware service design
Design service boundaries so teams can run one product or the wider platform with clearer routing, resilience, and operational visibility.
All-in-one platform depth instead of fragmented vendor sprawl.
Deis brings OCR, identity, compliance, municipal workflow, data, and governed AI into one connected operating model so teams can reduce vendor sprawl while keeping controls, evidence, and workflow decisions aligned.
Module
OCR and document processing
- Bank statements, payslips, IDs, invoices, and supporting records
- Real-time extraction, validation, and structured outputs
Module
Identity and trust controls
- Biometric verification, liveness detection, and document authentication
- Home Affairs-linked identity workflows and tamper review
Module
Compliance and data rails
- FICA and AML screening, goAML support, and FAIS or Fit & Proper oversight
- Home Affairs, bureau, CIPC, Deeds, and related verification-source connectivity
Module
AI operations
- Document-grounded enterprise AI with approval controls and immutable audit logs
- Provider-flexible AI workflows for regulated teams
Single API integration path across multiple trust-critical services
Consistent security and audit posture across modules
Shared data flow between verification, extraction, decisioning, and downstream operations
Lower vendor and maintenance overhead than stitching together multiple separate stacks
Enterprise-grade support for live regulated operations.
The original technology route closed on uptime, response, and support expectations. That still matters, because these products sit inside real onboarding, lending, municipal, payment, and compliance workflows.
Mission-critical uptime
Enterprise support and resilient platform design for workflows that cannot pause during business hours.
Rapid response
Support models tuned for high-impact operational environments where document, payment, or verification delays affect live delivery.
Implementation guidance
Clear advice on which services to deploy first, how APIs fit together, and how existing bureau, ID, or compliance systems connect.
Six independent layers of defence, not one control carrying the weight.
Security is engineered in layers so no single control is load-bearing. Each layer operates independently, and compromising one does not expose the layer beneath it.
Edge
Cloudflare and Azure API Management. All client traffic terminates at a hardened gateway, every API call carries a per-organisation subscription key, and TLS is enforced end to end.
Gateway
The production API only accepts requests carrying a gateway-injected secret, so traffic cannot bypass API Management to reach the application directly.
Network
Production workloads run inside isolated virtual networks with segmented subnets per workload class. Internal databases are reachable only from inside the network.
Egress
All internet-bound traffic is force-routed through Azure Firewall. Only named, approved destinations are permitted; everything else is denied and logged.
Identity
Services authenticate with Azure managed identities, so no credentials live in code, configuration or CI. Secrets are held exclusively in Azure Key Vault under role-based access control.
Monitoring
Microsoft Defender for Cloud with continuous posture assessment, vulnerability management on all compute, and high-severity alerting to the security contact around the clock.
Data is processed and stored in the South Africa North region. Verification evidence (Defender for Cloud posture reports and vulnerability findings) is available on request for due-diligence and procurement via [email protected].
Explore the stack through products, workflows, and supporting reading.
The technology story is easier to understand when the underlying controls connect directly to product depth and supporting operational material.