Rule 4

Consent Manager registration opens — 13 Nov 2026

myconsent+
System architecture

A request enters at the top. The record settles at the bottom.

Layers
5
Modules
M1–M7
Residency
India

Five layers, in the order a consent event passes through them. Everything below describes the platform as designed and, where stated as shipped, as built — with a section at the end for the three things that are neither.

The five layers

L01

Presentation Layer

Adaptive consent widgets for web, mobile, and IoT interfaces

L02

Business Logic Layer

Consent orchestration, policy evaluation, and consent receipt generation

L03

API Layer

GraphQL & REST endpoints with automatic rate limiting and auth

L04

Data Layer

Encrypted consent vault with an append-only, hash-chained audit trail

L05

Security Layer

Key rotation, least-privilege access, and intrusion detection. Zero-knowledge proofs are planned, not deployed

Each layer talks only to the one beneath it. The vault is reachable from nowhere else.

Technology

What it runs on

Infrastructure

  • Kubernetes Orchestration
  • Multi-AZ Deployment
  • Auto-Scaling Groups
  • Load Balancing

Data & Storage

  • PostgreSQL (Encrypted)
  • Redis Cache Layer
  • Elasticsearch (Audit)
  • S3 (Cold Storage)

Security

  • AES-256 at rest
  • TLS 1.3 in transit
  • Envelope encryption with rotating keys
  • Role-based access, access logs retained 1 year

These are design choices stated as design choices. Nothing on this list asserts an audit that has not happened — see the section below.

Stated plainly

Three things on this page are direction, not product

We would rather you heard it here than found it in diligence. Each one below says what exists today and what does not.

Not shipped

Zero-knowledge proofs

The intent is for a regulator to verify a consent without seeing the data behind it. Today the guarantees are encryption at rest and in transit, least-privilege access, and an append-only hash-chained trail that fails verification if a record is altered. The proof system itself is not implemented.

Not shipped

Consent Manager registration

Registration under Rule 4 opens on 13 November 2026, against Part A of the First Schedule — incorporation in India, a ₹2 crore net worth floor, and an interoperable platform. We are not a registered Consent Manager today, and no one is, because the register does not open until then.

Not shipped

Independent certification

No SOC 2 report or ISO certificate has been issued for this platform. When one is, it will appear here with its scope, date and auditor, and the report will be available under NDA. Until then, treat the security section as design intent you are entitled to test.