Skip to content

Case study

SmartKYC

Reusable verified identity: the customer owns the file, institutions get explicit, limited and revocable access.

Client
Think Dev
Years
2026 – present
Domain
SecurityFintechSaaS

01

Context

In the CEMAC zone, customers re-submit the same identity documents to every bank, microfinance institution or operator they deal with. SmartKYC is an internal Think Dev product built around that friction.

02

Problem

Make a verified identity file reusable without turning it into a data leak: the customer must stay in control of who sees what, for how long, and every access must be accountable.

03

What I did

Product, architecture and development at Think Dev, in a monorepo shared by the web app, the mobile app and the API.

04

Key technical decisions

  1. The customer owns the file

    Each institution is granted explicit, scoped and revocable access by the customer. Revoking access is a first-class action, not a support ticket.

  2. Multi-tenant isolation

    Institutions are isolated tenants: one partner can never read another partner’s data.

  3. Audit trail on every access

    Every read of an identity file is recorded with who, when and under which grant.

  4. Signed partner API and webhooks

    Partners integrate through a signed API and receive webhooks, so requests can be authenticated and events trusted.

  5. Mobile capture

    A mobile flow with camera capture collects documents where customers actually are: on their phone.

05

Result

In development since January 2026.

06

Stack

  • Nuxt 4
  • Expo
  • PostgreSQL
  • Redis
  • AdonisJS
  • Monorepo