NIC review, pseudonymisation, and the seven-day purge rule
No plaintext document storage. Pacten does not store plaintext identity-card numbers or unencrypted raw document images in persistent database tables.
Manual zero-retention review dashboard. Uploaded front and back NIC images are held in isolated, encrypted AWS S3 quarantine storage (pacten-quarantine). Vetted Pacten review staff check them through a secure dashboard that renders memory-only Blob URLs with dynamic reviewer watermarks showing reviewer ID, timestamp, and IP address. Screen captures, local downloads, and clipboard copies are disabled.
Strict seven-day S3 hard purge. Uploaded NIC images are permanently hard-deleted from S3 quarantine within seven days after an approved or rejected review decision by an automated background process. Pacten maintains no secondary backups or cold-storage archives of raw identity-card images.
HMAC-SHA256 cryptographic identity key. After manual approval, your canonicalised 12-digit NIC number is converted into a non-reversible, unpadded Base64 cryptographic hash using HMAC-SHA256 with a secret pepper managed in AWS Secrets Manager. Plaintext NIC numbers are immediately removed from our database. This supports a one-person, one-account anti-fraud constraint without storing raw ID numbers.
Personal NIC ownership and fraud penalties. Verification is limited to the account holder's authentic government-issued NIC. You must not submit another person's identity document, including that of a spouse, family member, or associate. A third-party NIC, stolen credentials, or fabricated documents may constitute criminal impersonation. Fraudulent attempts can lead to account termination, device blacklisting, referral to the Sri Lanka Police and Department for Registration of Persons, and secure retention of the submitted photos in encrypted quarantine audit logs as legal evidence.