Going to production

Production gives your application access to real citizen and business records from the national digital identity. Before RDCPASS issues production keys, it reviews two dossiers: one about your organization (business due diligence, completed once) and one about each application (application due diligence). Both are submitted from the console and must be approved.

At a glance

  • Two dossiers: business (once per organization) and application (once per application, updated on scope changes).
  • Submitted by an Owner, Administrator or Compliance officer from the console.
  • Typical review: 5–10 business days standard, 10–20 business days with enhanced due diligence.
  • Approval unlocks production keys and an mTLS client certificate.
  • Obligations continue after launch: annual re-review, incident notification and review of scope changes.

Status lifecycle

Every application moves through the statuses below. Each transition is shown in the console and sent to your webhook as application.production_status_changed.

sandboxsubmittedin_review|changes_requestedapproved|rejected
StatusWhat it meansWhat you do
sandboxBuilding and testing with synthetic data.Complete your integration and gather test evidence.
submittedDossiers submitted; waiting for a reviewer.Nothing — a reviewer is assigned within two business days.
in_reviewA reviewer is assessing both dossiers.Answer reviewer questions in the console promptly.
changes_requestedThe reviewer needs changes or more evidence. The review clock pauses.Update the dossier and resubmit; it returns to submitted.
approvedProduction access granted.Issue production keys and your mTLS certificate.
rejectedProduction access refused, with written reasons.Address the reasons; you may submit again after 30 days.
Webhook — application.production_status_changed
{
  "id": "evt_1f6b3d9a0c2e7485",
  "object": "event",
  "type": "application.production_status_changed",
  "livemode": true,
  "created_at": "2026-10-08T14:05:12Z",
  "data": {
    "object": {
      "id": "app_5d20e8a1c4",
      "object": "application",
      "production_status": "approved",
      "reviewer_comment": "Business and application dossiers approved. Production keys can be issued."
    },
    "previous_attributes": { "production_status": "in_review" }
  }
}

Business due diligence

Governance checks about your organization. They are completed once and shared by all your applications; RDCPASS re-checks them at the annual re-review.

Business dossier (governance)
Legal existence
RCCM registration, ID NAT and NIF — verified directly against the registries through KYB Verification.
Statutes
Current articles of association, with any amendments.
Directors and beneficial owners identified with RDCPASS
Every director and every owner of 25 % or more is identified by their RDCPASS ID. Foreign nationals are identified by passport.
Sector licence where applicable
For example BCC (banks, microfinance, mobile money, payment institutions), ARPTC (telecommunications), ARCA (insurance) or the relevant ministry approval.
Data-protection officer
A named person responsible for personal-data protection, with contact details RDCPASS can use.
AML/CTF policy
Required for financial-sector organizations: your anti-money-laundering and counter-terrorist-financing policy, approved by management.
Signed RDCPASS data-sharing agreement
Signed electronically in the console by the Owner or a legal representative.
Sanctions screening of the company
RDCPASS screens the organization, its directors and beneficial owners against the sanctions and watchlists used by AML & CTF Screening.

Application due diligence

Checks about how each application protects the data it receives. Answer them in the application’s Production tab; each item accepts attachments.

Security
Security questionnaire completed
Architecture, hosting location, network segmentation, patching and vulnerability management.
Key storage
Secret Key, Payload Encryption Key and the mTLS private key are held in an HSM or a secrets vault — never in source code, images or plain configuration files.
mTLS ready
Your servers can present a client certificate on every connection to api.rdcpass.cd.
Penetration-test report
Required for applications using Sensitive or Biometric scopes, Face Recognition or Credit Scoring: a test less than 12 months old by an independent tester, with remediation status.
Scope
Justification for every scope
Why this application needs each additional scope, and which feature uses it.
Data minimization
Requests narrow scopes to what each flow needs; unused scopes are removed from the application.
Purposes match the product
Each declared purpose corresponds to a real user journey you can demonstrate.
Authorization
Who sees returned data
The staff roles in your organization that can view identity data returned by RDCPASS, and why.
Access controls
Role-based access, individual accounts and MFA on the internal tools that display RDCPASS data; access reviews at least twice a year.
Best practices
Encryption at rest
Stored identity data and documents are encrypted at rest.
Retention and deletion policy
How long you keep each category of data, and how it is deleted. Signed document URLs are never stored.
Logging without personal data
Application logs record request IDs and outcomes, not names, identifiers, documents or biometrics.
Incident response
A documented procedure, with a named contact, covering notification to RDCPASS.
Testing
Sandbox test evidence
Request logs from sandbox showing successful calls, error handling (for example scope_not_granted, invalid_identifier), asynchronous jobs, batches and verified webhook deliveries, for every enabled service.
Business outcomes handled
Your flow handles not_found, not_certified, no_match and withheld scopes gracefully, as demonstrated with the sandbox test identities.

Enhanced due diligence

Some services and scopes carry higher risk for citizens. They add the following requirements to the application dossier:

TriggerAdditional requirements
Face RecognitionDPIA, documented and approved reason policy (who may run a search, for what, and how reasons are reviewed), on-site or video audit, penetration test.
Credit ScoringDPIA, consent flow review (how citizens are asked for rdcpass:credit.score consent), on-site or video audit, penetration test.
Sensitive scopes — kyc.religion, kyc.ethnicityDPIA, legal basis for processing, named data-protection officer, penetration test.
Biometric scopes — kyc.biometrics.selfie, kyc.biometrics.fingerprint, kyc.biometrics.irisDPIA, legal basis, named data-protection officer, on-site or video audit, penetration test, biometric template storage description.

Adding one of these triggers to an application already in production starts an enhanced review of that change. Your existing production access continues during the review.

Required documents

DocumentDossierRequired when
RCCM extract, ID NAT certificate, NIF certificateBusinessAlways
Statutes and amendmentsBusinessAlways
List of directors and beneficial owners (with RDCPASS IDs)BusinessAlways
Sector licence or ministry approvalBusinessRegulated activities (BCC, ARPTC, ARCA, …)
AML/CTF policyBusinessFinancial sector
Signed RDCPASS data-sharing agreementBusinessAlways
Security questionnaireApplicationAlways
Scope justifications and data-flow diagramApplicationAlways
Retention and deletion policyApplicationAlways
Incident response procedureApplicationAlways
Sandbox test evidenceApplicationAlways (generated from your sandbox logs)
Penetration-test reportApplicationEnhanced due diligence
Data-protection impact assessment (DPIA)ApplicationEnhanced due diligence
reason policyApplicationFace Recognition

Documents are accepted as PDF in French or English. Documents issued by public authorities must be less than three months old.

Review timelines

ReviewTypical duration
Standard (business + application dossiers)5–10 business days
Enhanced due diligence10–20 business days, including the audit
Scope or purpose change on a production application3–5 business days (enhanced: 10–20)
Annual re-review5 business days

The clock runs from submitted and pauses while an application is in changes_requested. Complete, consistent dossiers are the single biggest factor in a fast review.

After approval

1
Issue production keys
An Owner or Administrator opens the application in the console, switches to production and issues a key set. The Secret Key and Payload Encryption Key are shown once.
2
Request your mTLS client certificate
Generate a private key and certificate signing request (CSR) on your own infrastructure and upload the CSR. RDCPASS issues a client certificate signed by its third-party client CA and binds it to the application.
3
Set your production IP allowlist
Add the public IP addresses of your production servers. Requests from other addresses are rejected.
4
Choose your billing plan
Your Financial officer selects prepaid or postpaid and, for prepaid, tops up the wallet — see Billing.
5
Switch the base URL
Point your integration at https://api.rdcpass.cd. Responses now carry "livemode": true.
Generate a CSR
# Generate the private key and CSR on your own infrastructure — the
# private key never leaves your servers. Upload only the .csr file.
openssl req -new -newkey rsa:4096 -nodes \
  -keyout rdcpass-client.key \
  -out rdcpass-client.csr \
  -subj "/C=CD/L=Kinshasa/O=Congo Microfinance SA/CN=app_5d20e8a1c4"

Production data is real personal data

Every production call returns data about a real citizen or business and is recorded against your purpose. Use sandbox for all testing — never test in production with colleagues’ or customers’ identities.

Ongoing obligations

Annual re-review
Each year RDCPASS asks you to confirm or update both dossiers. Keep your statutes, licences, directors and data-protection officer current.
Incident notification within 72 hours
Notify RDCPASS of any security incident affecting RDCPASS data or credentials within 72 hours of discovery, from the console or through your integration contact. Rotate affected keys immediately.
Scope and purpose changes are reviewed
Adding scopes, purposes or services to a production application goes through review; removing them is immediate.
Material changes within 30 days
Report changes of ownership, directors, sector licence or data-protection officer within 30 days.
Cooperation with audits
RDCPASS may audit your use of the platform, including the purposes recorded on your requests.

Breaching these obligations can lead to suspension of production keys. RDCPASS contacts your Owner and Compliance officer before any suspension, except where citizens’ data is at immediate risk.

Next steps

Questions about your integration? Contact developer support