OpenSPP is an open-source social protection platform providing a social registry, beneficiary and programme management, a farmer registry and deduplication, with DCI-compliant data exchange. It is in the collection as a registry building block whose social registry connects civil registration, health and ID systems rather than serving one programme.
All DPGs in the DPGs for DPI Collection are assessed by the DPGA Secretariat against the DPGs for DPI criteria v2.0. Assessments use publicly available documentation and link to their evidence below. Assessed September 2026.
2 partially met
Layer 1
Recognised DPG
Layer 2
DPI Relevance
Layer 3
DPI Architecture Alignment

Does it provide a foundational DPI function, reusable across sectors, at population scale?
It sits in the Registries domain as a social protection registry for beneficiary and population data. DCI APIs connect it to civil registration (including OpenCRVS), health, ID and education systems across multiple programmes, and it is designed for national systems managing millions of beneficiaries.
How the solution's architecture reflects the principles that distinguish DPI from conventional digitisation.
Can other systems connect without modifying the core, using documented open standards?
A RESTful DCI API is documented with Swagger/OpenAPI specifications in the developer guide. It adopts the Digital Convergence Initiative standard, CRVS-SP interface standards and G2P Connect, exchanging JSON in DCI payload formats against published schemas.
Is it a modular building block that does one thing well, rather than a monolithic platform?
Social Registry, SP-MIS and Farmer Registry are separate installable products, with the core registry engine distinct from programme-specific modules such as cash transfer and food distribution. Built on the Odoo framework, it is configured through module installation rather than forking.
Can other public and private actors build on top of it?
DCI APIs and the Odoo module architecture let third parties extend and integrate, with documented integrations to OpenCRVS, ID systems and payment platforms via DCI and G2P Connect. The open-source licence and community development model keep it free of single-vendor control.
Can it run in distributed or federated deployments suited to national infrastructure?
On-premise deployment is supported and data stays in-country. Each deployment is designed as a national single instance, with federation between instances undocumented and high-availability guidance limited to standard Odoo and PostgreSQL scaling.
Does it meet the security and privacy bar for population-scale infrastructure?
A security guide covers production deployments handling sensitive population data, with Trivy vulnerability scanning and Gitleaks secret detection in the pipeline. A vulnerability disclosure address is published, and privacy-aware design for vulnerable populations is documented in the security guide.
Criteria: DPGs for DPI Collection criteria v2.0 · Co-stewarded by CDPI, Co-Develop and the DPGA Secretariat.
Spot something out of date? Contact the DPGA