Customer story · Analytics & Trust
The register is the product
The Private Lending Association of South Africa is not a lender. It does not originate a single rand. It publishes research, education, standards and public registers for a market where the difference between a legitimate private lender and a scheme is genuinely hard for an ordinary person to see. Everything it owns sits in one sentence: the names on the register are actually verified. That is the whole asset, and it is the kind of asset that does not degrade gradually — it survives intact until the first time it is wrong.
An association's product is a claim about other people
Most of the businesses we write up here sell something the customer uses. A standards body sells something stranger: an assertion. When the Association lists an organisation on its register, a member of the public is entitled to lean on that listing when deciding where to put money they cannot afford to lose. The listing is load-bearing in a way a marketing page never is.
That changes what instrumentation is for. The question is not "how do we convert more visitors". It is two much sharper questions. Does the education actually reach the person before they make a decision? And is the register clean — is every application that reaches it what it claims to be? The first is an analytics problem. The second is a Trust problem. The Association runs Crossdeck for both.
Did the warning arrive before the decision?
The site is built as a deliberate path rather than a pile of pages. There is a guided route through what private lending is, what a lender would actually hold, when the law applies, how the models work, and what the risks are — alongside a page on scams and red flags that exists for exactly one reason: to be read by someone who is about to be defrauded.
A page-view counter cannot answer whether that worked. It reports that the red-flags page got traffic. It cannot tell you whether the people who checked a register entry had read it first, or whether the guided path loses people at the third step and they arrive at the register with no context at all. Those are journey questions, and a journey is a sequence belonging to one person — not a total belonging to a page.
Crossdeck's analytics are built around that sequence. The same visitor moving from an explainer, to a register lookup, to an application is one timeline, and the useful findings live in its shape: which explainer reliably precedes a register check, where the guided path sheds people, which entry point produces a reader who goes deep versus one who bounces off the glossary. For an organisation whose mission is comprehension rather than conversion, that ordering is the performance metric.
The risk is not the reader. It is the applicant.
Almost all of the Association's traffic is harmless: people trying to understand a market. The exposure is concentrated in a very small number of forms — applications for verification, membership applications, partner submissions. Those are the doors where someone stands to gain something material by getting through: a listing on a public register, carrying the Association's name, pointed at consumers.
That is a different threat model from spam. A bot filling a contact form wastes an afternoon. A fraudulent verification application that reaches a register damages the only thing the organisation has. It also damages the legitimate members who paid dues to stand next to a name that meant something.
- The gate is server-side. Crossdeck Trust evaluates at the write layer, not in the browser, because the browser is the attacker's machine. A submission that never renders the page still has to pass the same gate.
- Rules act on facts, not vibes. Trust surfaces evidence — origin, country, the shape of the request — and the Association's own rules decide. Crossdeck does not autonomously block anyone; a standards body cannot outsource a judgement call about who gets refused to a score it did not set.
- Refusing is not deleting. A blocked submission is declined, not erased. For a body that may later have to explain a decision to an applicant or an ombud, the evidence trail surviving the refusal is the point.
One person, three surfaces
The reason both jobs sit in one product rather than two is that they are the same person. Someone reads the material, checks a register, and later applies for verification themselves — practitioners in this market are frequently consumers of the education first. Split across an analytics tool and a fraud tool, that is three unrelated records. Joined by identity, it is a single history, and the history is what makes a decision defensible.
It cuts both ways, which is the honest part. A long, patient reading history is context in favour of an applicant. An application that arrives with no history at all, from an origin that does not match anything else about it, is context of a different kind. Neither is a verdict. Both are facts the reviewer should have in front of them, and the published verification methodology remains what actually decides — not the software.
A standards body is held to its own standard
There is an obvious trap in an organisation that publishes conduct standards running loose data practices of its own. Under POPIA, the people reading these pages have rights over what is collected about them, and an association telling the market how to behave is the last organisation that can afford a careless answer.
So consent is a first-class part of the install rather than a banner bolted on afterwards. A decline is enforced, not recorded and ignored. Erasure physically removes the data rather than flagging it. The Association is in the business of telling people what good conduct looks like; the instrumentation had to be something it could describe out loud without wincing.
Why this install is worth reading
The other stories on this site are commercial: a lender handing a consultant the journey before the call, an assistant deciding whether a paying customer can open the app. This one has no revenue in it at all. There is no subscription to measure, no entitlement to grant, no churn to predict.
It is here because it isolates something the commercial cases blur. Strip out the money and what is left is identity and evidence — knowing that a sequence of actions belongs to one person, and being able to show why a decision was made about them. That is the part that is actually hard, and it turns out to matter just as much to an organisation whose product is a claim about who can be trusted.
Disclosure: the Private Lending Association of South Africa and Crossdeck are both part of the same group of companies. It is written up here because the install is a genuinely unusual one, not as an independent endorsement.
Your credibility is a claim about other people too
If something you publish is load-bearing for someone else's decision, the gate in front of it is worth more than the analytics behind it. Crossdeck is free until your app earns real money.