08 / For you
Check your identity once.Use your passkey after that.
Opening a mailbox tied to your identity requires a careful check. Keepable checks your NIN with NIMC and checks that your face matches during setup. After that, you use your passkey rather than entering the NIN again.
Your NIN · your face · your passkey · your sign-in history · your download
In the app
What we hold about you
After your Keepable is open
- Your NIN
- What is left of it
- Your face
- Your password
-
Check
Once, to prove who opens the mailbox
We check your NIN with NIMC when you open your Keepable, and then the number itself is not retained after verification. What is left cannot be turned back into it. The check binds the mailbox to you. It is not a password, and it cannot sign you in, recover the mailbox or sign a document.
-
Open
Nothing to forget, and nothing to intercept
You sign in with a passkey on your own device. No password to reuse somewhere worse, no OTP sitting on a SIM for somebody else to catch, and nothing that works without the phone in your hand.
-
Leave
Take it all with you, whenever you like
Download everything we hold about you, or close the account and take the lot. Under the NDPA these are your rights, and here they are buttons in the app rather than a letter from a lawyer and a six-week wait.
A NIN proves identity. Your passkey controls your Keepable.
- What we keep
- The last four digits, and a scrambled version that cannot be turned back into your NIN.
- Why the face
- Once, to be sure it is you opening this and not somebody who bought your details.
- Your rights
- Download everything, or close the account and take it with you.
The detail
- What is the scrambled version, and why is it not just a hash?
- Because a plain hash of an eleven-digit number is no protection at all: there are only a hundred billion of them, and anybody who took a copy of the database could work through every one on a single machine in an afternoon and match them all back. Ours is scrambled with a secret key held separately from the data, which makes that impossible without the key as well. A stolen copy of the database on its own is a list of values nobody can turn back into anybody's NIN.
- Why do you keep anything at all?
- So a bank can address a letter to you and to nobody else. When mail arrives for a NIN, the same scrambling is applied to the number the sender used and the two are compared. That comparison is all it can do: it can tell that two numbers are the same, and it cannot produce either of them.
- What happens to my face?
- It is used once, when you open your Keepable, to check that the person holding the number is the person it belongs to. That is the step that stops somebody who bought your details from opening a mailbox in your name. It is not kept as a way of signing you in afterwards, and the app never asks for it to unlock something.
- How do I know a page asking for my NIN is really Keepable?
- You cannot know from a message, a logo or a request for information alone. Criminals can copy all three. Keepable will never ask you to send your NIN, face capture, passkey, password, BVN or OTP to staff in an email, WhatsApp message, social-media message, phone call or support conversation. If a message makes you unsure, stop and report it. A NIN check can protect your mailbox after it is complete; it cannot make an unsolicited message trustworthy.
- How do I sign in, then?
- With a passkey on your own device, unlocked by your face, your fingerprint or your device PIN. There is no password to reuse somewhere worse, no one-time code sitting on a SIM for somebody to intercept, and nothing that works without the phone in your hand. You can register more than one device, and you can see and remove them.
- Someone signed in and it was not me. What happens?
- You are told when a new device signs in, you can see the list of them, and you can sign out everywhere at once. Since there is no password, there is also nothing that can be phished out of you and used from somewhere else.
- What can I take with me?
- Everything, and it is a button rather than a request. Download the whole of it, or close the account and take the lot. Under the NDPA these are your rights, and a right that takes a letter from a lawyer and a six week wait is not much of one.
The limit
This protects your Keepable, not your NIN everywhere else. Nobody honestly can promise that a copied website will not ask for information. What we can do is make a stolen NIN useless for entering, recovering or signing from your mailbox, and make sure the raw number is not one more copy we retain after the check.
Start here
Check a Keepable document yourself
You do not have to believe any of this. Anyone can check a document without an account. Open your Keepable.