The full consent lifecycle: capture, store, refresh, withdraw — across a hosted preference centre, cookie banner, and embeddable widget.js, all on one audit trail. Per-purpose granular consent, OTP-gated withdrawal, returning-principal recognition, 22-language notices. DPDP §6 · §7 · Rule 4.
A 30-policy bank drafted by AI from your org profile and the live DPDP spec. Version-controlled, role-signed, PDF export, hosted-URL publication, AI gap analysis + regulator response drafter. DPDP §5(3) · 8(1).
Two-tier engine — Protect Pro (self-serve) + Protect Max (DeepDive) — 350+ sectoral questions, Healthcare/BFSI banks, per-question evidence upload with AI vision validation, module assignments with SLA. DPDP §8 obligations.
Honours the five §11 rights via a public portal at /rights/[org]: OTP-verified intake, auto-routing, AI response drafter, SLA timer + escalation, Rule-12 refusal-must-state-reasons, PDF + signed audit exports. DPDP §11 · Rules 12 & 13.
Public form at /grievance/[org], per-org DPO inbox, category routing, 90-day SLA with two escalations, full state-transition audit trail, Rule-13 refusal logic, satisfaction capture. DPDP §13 · Rule 13.
72-hour detection clock, 24-hour Board-notification clock, containment/RCA/corrective workflow, regulator-notification record with reference number, multilingual principal-notification campaign, standing breach register. DPDP §8(6).
Records of Processing Activities, data-flow diagrams, vendor/processor catalog with DPA tracking, sub-processor disclosure register, and a cross-module risk heatmap for the DPO weekly review. DPDP §8(7) · 8(8).
60+ DPDP-specific checks across 10 weighted domains (notice, consent, withdrawal, cookies, children, forms, headers, vendor sharing, retention, grievance). Severity-tagged, section-anchored, scored 0-100 with re-run deltas. DPDP §5 · §6 · §13.
Every plan includes the same audit trail, so you can add modules later without re-onboarding.