Financial Data Interoperability Infrastructure
One governed gateway. Every institution you need.
ThiqaConnect lets banks, insurers, regulators and telecoms request and receive financial data from one another through a single, auditable, policy-controlled rail — with provable consent, deny-by-default access, and nothing shared beyond exactly what a purpose requires.
The problem
Bilateral integrations don't scale — and consent isn't provable
Ad-hoc channels, no shared audit trail
Emails, portals, and one-off APIs — each with its own security posture and no common record of what moved, when, or why.
Consent that can't be proven
Consent is often implicit or captured on paper — nobody can show a regulator, auditor, or subject exactly what was shared and under what authority.
Lawful access runs informally
Court orders and AML/CFT requests run through separate, inconsistent processes — with no standard approval workflow or disclosure record.
Data minimisation is a promise, not a control
Most integrations have no technical way to limit a counterparty to only the fields a specific purpose actually needs.
The pipeline
Every request moves through the same governed path
Whether triggered by a customer's consent or a regulator's authority, the same five-stage pipeline decides, fetches, filters, and records — before a single byte reaches the requester.
-
1
Request
A requester names the subject, the purpose, and the exact data scope needed.
-
2
Authorize
Checked against the governed catalogue, organisation eligibility, and a live consent, regulatory, or legal grant.
-
3
Decide
The policy engine issues an auditable allow or deny, failing closed on any error.
-
4
Fetch
A hardened connector calls the provider — SSRF-checked, TLS-enforced, rate-limited, and correlated.
-
5
Deliver & record
The response is filtered to an allow-list, schema-validated, disclosed, and written to an append-only audit ledger.
Built for trust
Nothing is disclosed by default. Nothing bypasses the ledger.
Deny-by-default
Every access decision is evaluated fresh against the current catalogue — no grant silently expands over time.
Structural data minimisation
Responses pass through an allow-list projection and versioned schema validation — an unlisted field can never leak.
One policy engine for all access
Consumer consent and regulatory or legal access share the same engine and the same audit trail — no separate, less-governed path.
Hardened connectors
One choke point to every provider, with runtime SSRF checks, bounded retries, enforced TLS, and size limits.
No raw data retained
Only the final, filtered payload is disclosed; only its hash is kept for audit. Raw provider responses are never stored.
Strict tenant isolation
API access, dashboards, and roles are enforced independently — a misconfigured participant can never see another's data.
Who it's for
One rail, every participant in the data ecosystem
Banks & lenders
Fast, governed access to an applicant's financial data at another institution for underwriting.
Insurers
Verified financial, identity, or claims-history data for underwriting and fraud checks.
Fintechs & non-bank lenders
Underwriting-grade access without negotiating a bilateral integration with every bank.
Regulators & central banks
Standing, governed visibility into cross-institution data flows and one lawful-access channel.
Law enforcement & courts
A single, auditable channel for lawful data requests, replacing informal or paper-based processes.
Telecoms & registries
Monetise governed, consented access to identity and account data as a data provider.
Not a concept
A working platform, operating end-to-end today
What's next: onboarding the first live institutional participants and extending the catalogue to their use cases.
Let's build the interoperability layer together
Whether you're a bank, an insurer, a regulator, or a data provider — we'd like to talk about a pilot.
hello@thiqaconnect.com