Vishwaas AI v2.1 · March 2026

225 Features. 15 Modules.
One Platform.

Complete DPDP Act Compliance — End to End.

Every capability Vishwaas AI delivers is mapped directly to a provision of the Digital Personal Data Protection Act 2023 or DPDP Rules 2025. Nothing built for hypothetical compliance — every feature answers a specific legal obligation.

225
Features
15
Modules
188
API Endpoints
22
Indian Languages
7yr
Retention
MODULE 01

Non-Repudiable Consent Management

The consent ledger is the legal heart of Vishwaas AI. Every consent decision — grant, withdrawal, modification, expiry — is recorded as an append-only event with four independent proof layers.

The Four-Layer Non-Repudiation Proof

Proof Layer Technology What It Proves
record_hashSHA-256 of deterministic JSONRecord content was not modified
chain_hashSHA-256(record_hash + prev_chain_hash)Record sequence intact; nothing inserted or deleted
digital_signatureRSA-2048 via AWS KMS HSMCreated by this organisation's authorised system only
tsa_tokenRFC 3161 TSA · DigiCert / GlobalSignMoment of consent is legally defensible and third-party verified

Purpose Catalog

Define consent purposes with lawful basis, data categories, retention period, and explicit opt-in requirement

Per-purpose consent collection

Granular, unbundled consent; no pre-ticked boxes

Append-only ledger

DB-level REVOKE UPDATE, DELETE — not just an application guard

Consent text snapshot

Exact multilingual text shown to the data principal, captured immutably at the moment of consent

7-year retention

Enforced per DPDP Rules 2025 Rule 4; automated retention policy per purpose

Chain verification API

POST /api/v1/consent/verify-integrity/{id} — any record verifiable on demand

Consent Receipt PDF

RFC 3161-signed PDF generated on demand from the data principal's portal

Bulk consent collection

API and campaign-based bulk collection from existing customer bases

Read the Non-Repudiation Whitepaper
MODULE 02

Multilingual Privacy Notices

The Challenge

DPDP Rules 2025 Rule 3 requires notices in English and at least one Eighth Schedule language. But a data principal in Tamil Nadu who receives a notice only in Hindi has not meaningfully received it.

22 Indian languages + English

All Eighth Schedule languages supported natively in the platform

TipTap rich-text editor

Author notices in a Word-like interface; DPDP-compliant standalone format enforced

Multilingual completeness indicator

Flags incomplete translations before a notice can be published

Notice versioning

Every published version retained; content_hash on each version for integrity

DPO approval workflow

Notices require DPO sign-off before publication — required for SDFs

Legal review gate

Legal officer review step before DPO approval — recorded with name and timestamp

Delivery tracking

Per-principal sent_at, delivered_at, acknowledged_at timestamps

Historical access

All published versions accessible to data principals at any time in the portal

MODULE 03

Data Principal Rights (DPR) Management

RightAct SectionSLA
Access — summary of data processed§1190 days
Correction — fix inaccurate data§12(1)(a)90 days
Erasure — delete data on withdrawal§12(2)90 days
Nomination — nominate a person§1490 days
Grievance — escalate complaint§1330 days

Auto-generated request numbers

DPR-YYYY-NNNNN format for all correspondence

SLA countdown with overdue alerts

Overdue requests highlighted; DPO alerts triggered before deadline passes

Identity verification

Email OTP, DigiLocker, or Aadhaar — documented per request before any data is disclosed

Append-only activity timeline

Every action on every request, immutable

DPBI escalation panel

One-click escalation for unresolved grievances with timestamp and DPO notification

Erasure job orchestration

Per-system deletion tasks based on unified identity graph; completion tracked

Self-service portal

Submit, track, and receive responses without admin mediation

Completion email with written response

Required by Rule 9 for grievances; dispatched with delivery confirmation

MODULE 04

Breach Incident Management

The 72-hour clock starts the moment you become aware of a breach. Vishwaas AI ensures you never miss the DPBI notification window. Penalty for failure to notify: up to ₹200 Crores.

72-hour DPBI countdown clock

Starts at incident creation; on-time/late compliance indicator always visible

Structured breach intake

Captures all Rule 8(2) mandatory fields: nature, data categories, principal count, consequences, measures

DPBI notification editor

Guided notification draft with mandatory fields enforced

Principal notification panel

Bulk email dispatch to affected principals; per-principal delivery tracking

Remediation tracker

Per-step checklist with completion timestamps and DPO sign-off

Multi-authority notifications

DPBI + RBI / IRDAI / CERT-In workflow for BFSI organisations

Breach register export

Signed PDF for DPBI inspection; RFC 3161-timestamped at generation

Append-only activity timeline

Immutable incident record for post-incident review and DPBI submission

MODULE 05

Data Protection Impact Assessment (DPIA)

Required for Significant Data Fiduciaries. A complete, structured DPIA workflow with DPO approval, risk heatmap, and signed certificate.

Likelihood × Severity Risk Heatmap

Rare
Unlikely
Possible
Likely
Critical
Med
High
Crit
Crit
Major
Low
Med
High
Crit
Moderate
Low
Low
Med
High
Minor
Low
Low
Low
Med

DPIA questionnaire

Processing description, data categories, necessity, proportionality, risks, safeguards

Likelihood × severity risk heatmap

Colour-coded matrix; risk levels auto-calculated

DPO approval workflow

DPO sign-off creates an immutable approval record with timestamp

DPIA register

Filterable by status (draft, under review, approved, rejected) and risk level

Signed PDF certificate

DPIA completion certificate with DPO signature and RFC 3161 timestamp

Risk register

All identified risks tracked with mitigation status; DPIA submitted-to-DPBI tracking (Rule 7(3))

MODULE 06

Vendor & Data Processor Management

Vendor onboarding

DPA upload, status tracking, and renewal reminders (active, expiring, expired, not signed)

Automated risk scoring

Risk score based on data categories shared, processing location, and DPA status

Cross-border transfer tracking

Flags transfers outside India; documents legal basis per transfer arrangement

Annual vendor assessments

Scheduled workflow with completion tracking and assessment history

Processor liaison role

Separate access level for vendor staff with scoped consent visibility

Vendor Risk Report

Signed PDF exportable for DPBI inspection in 30 seconds

MODULE 07 · v2.1

Identity Unification

Unique Differentiator

The only DPDP compliance platform with a built-in identity resolution engine.

Four-Stage Pipeline

1

Connect

Register source systems: Salesforce, HRIS, Shopify, HubSpot, CSV uploads, custom APIs

2

Ingest

Normalise fields: email lowercase, phone E.164, name transliteration, Aadhaar hashed (never plaintext)

3

Resolve

Deterministic (auto-link: exact email/phone/PAN/Aadhaar) + Probabilistic (Jaro-Winkler ≥85%, human review queue)

4

Unify

One canonical data principal with identity graph, data asset map, and tamper-proof merge audit trail

Auto-link throughput

> 50,000 records/hour per tenant

Resolution latency

< 5 minutes for 10,000-record batch

Human review queue

Side-by-side comparison, confidence score display, bulk operations

Configurable resolution rules

Thresholds, field weights, auto-link controls per tenant

Append-only merge audit trail

Every merge decision tamper-proof at DB level — verifiable by the DPBI

MODULE 08 · v2.1

Real-Time Consent Propagation

<5s

SLA from consent change to confirmed webhook delivery across all downstream systems.

Layer 1 · Push

HMAC-SHA256 Webhooks

Signed delivery to all registered downstream systems on every consent event

Layer 2 · Pull

Redis Consent Status API

<50ms single lookup · <200ms for 1,000-record batch · always fresh

Layer 3 · Enforce

API Gateway Plugin + SDK

Blocks processing without active consent at the gateway layer

Event types

consent.granted · consent.withdrawn · consent.expired · consent.renewed

Exponential backoff retry

Immediate → +1s → +5s → +30s — no lost events

Dead-letter queue

Payload inspection, manual retry, and audit-log dismiss

Propagation delivery log

Timestamped, immutable record per delivery — DPBI evidence of withdrawal enforcement

MODULE 09

Compliance Dashboard & Reports

Real-time KPI cards

Consent rate, pending DPR, active breaches, DPIA status, vendor risk — live

Compliance posture score

Aggregate risk score across all 15 modules

Trend analytics

Consent grant/withdrawal rates over time (TimescaleDB)

Risk heatmap

Data asset × processing risk matrix

Activity feed

Live stream of all compliance-significant events across all modules

Signed report generation

DPR Performance · Consent Analytics · Breach Register · DPIA Register · Vendor Risk · Training Completion — all signed PDF/Excel

MODULE 10

Data Principal Portal

A consumer-facing portal where data principals manage their own privacy in 22 Indian languages — passwordless, self-service, and fully auditable.

Passwordless email OTP login

No passwords, no credential database

Per-purpose consent toggles

Identical UX for granting and withdrawing — §6(5) compliance

Active consents view

With notice version links for full transparency

Self-service rights requests

Access, correction, erasure, nomination, grievance — without admin mediation

Request status tracking

Full activity timeline visible to the data principal

Privacy notice library

All published versions accessible at any time

Cookie preference management

Category-level control from within the portal

Consent Receipt PDF

RFC 3161-signed PDF downloadable on demand

MODULE 11

Cookie Consent SDK

20 KB vanilla TypeScript banner

Single <script> tag embed — no dependencies

Category-level consent

Essential · analytics · marketing · personalisation

Ledger-connected

Cookie consent recorded in the main hash-chained, signed consent ledger

Admin-managed configuration

Colours, position, language, granularity — no code change required

Downstream propagation

Cookie consent changes propagated via the same webhook architecture

Public consent record lookup

Third-party verification API — no auth required

MODULE 12 · v2.1

Consent Campaigns

For organisations needing to collect retroactive consent from existing customer bases — with notice delivery, per-principal tracking, and full analytics.

Campaign targeting

By data principal attributes, source system, or purpose status

Notice attachment

Privacy notice version delivered alongside consent request

Scheduled or immediate dispatch

Full scheduling control per campaign

Per-principal tracking

Sent · opened · responded · pending — per recipient

Campaign analytics

Response rate · consent granted % · declined % · pending %

Bulk consent collection

Via email link or embedded form

MODULE 13

Multi-Tenant Platform Management

For Cross Identity and large organisations managing multiple subsidiaries or brands from a single platform instance.

Super admin isolation

Platform-level management with zero access to any tenant's compliance data

Auto-provisioning

Roles, seed purposes, slug-based routing — fully automated on tenant creation

Per-tenant user management

Role assignments, invitations, deactivation — scoped to tenant

Slug-based routing

/{tenantSlug}/admin/ · /{tenantSlug}/portal/

Platform overview dashboard

Tenant count, overall consent volume, support tickets

Custom DPA management

Per-tenant DPA tracking and management

MODULE 14

Training

6 built-in DPDP Act compliance courses

Covering all major obligations under the Act and Rules 2025

Role-based course assignment

Assign specific courses to specific roles and users

Enrolment management

Track assigned, in-progress, and completed enrolments

Completion certificates

Generated and timestamped on module completion

Training completion reports

For SDF annual audit obligations (Rule 7) — signed PDF with completion rates per role

MODULE 15

Audit Trail

The audit.events table captures every mutation across all 14 other modules — append-only, hash-chained, and independently verifiable.

Append-only hash-chained ledger

audit schema — INSERT + SELECT only at DB level; same SHA-256 chain design as consent

Universal coverage

Every mutation across all 14 modules writes an immutable audit event

Chain verification endpoint

GET /api/v1/audit/verify-chain?from=&to= — verify any date range in one call

Full-text search

Elasticsearch-powered search across all audit events

Audit log export

CSV + chain verification result — DPBI-ready package

Complete event capture

Actor, IP address, timestamp, and action on every event — no gaps

Feature Count Summary

Vishwaas AI v2.1
Module Features
Platform Access & Authentication12
Compliance Dashboard10
Consent Management22
Privacy Notices15
Data Principal Rights18
Breach Incident Management14
DPIA & Risk Assessment13
Vendor Management9
Identity Unification16
Consent Propagation14
Data Principal Portal13
Cookie Consent SDK9
Consent Campaigns8
Training8
Audit Trail & Reports14
Total 225