A request enters at the top. The record settles at the bottom.
- Layers
- 5
- Modules
- M1–M7
- Residency
- India
Five layers, in the order a consent event passes through them. Everything below describes the platform as designed and, where stated as shipped, as built — with a section at the end for the three things that are neither.
The five layers
Presentation Layer
Adaptive consent widgets for web, mobile, and IoT interfaces
Business Logic Layer
Consent orchestration, policy evaluation, and consent receipt generation
API Layer
GraphQL & REST endpoints with automatic rate limiting and auth
Data Layer
Encrypted consent vault with an append-only, hash-chained audit trail
Security Layer
Key rotation, least-privilege access, and intrusion detection. Zero-knowledge proofs are planned, not deployed
Each layer talks only to the one beneath it. The vault is reachable from nowhere else.
Technology
What it runs on
Infrastructure
- Kubernetes Orchestration
- Multi-AZ Deployment
- Auto-Scaling Groups
- Load Balancing
Data & Storage
- PostgreSQL (Encrypted)
- Redis Cache Layer
- Elasticsearch (Audit)
- S3 (Cold Storage)
Security
- AES-256 at rest
- TLS 1.3 in transit
- Envelope encryption with rotating keys
- Role-based access, access logs retained 1 year
These are design choices stated as design choices. Nothing on this list asserts an audit that has not happened — see the section below.
Stated plainly
Three things on this page are direction, not product
We would rather you heard it here than found it in diligence. Each one below says what exists today and what does not.
Zero-knowledge proofs
The intent is for a regulator to verify a consent without seeing the data behind it. Today the guarantees are encryption at rest and in transit, least-privilege access, and an append-only hash-chained trail that fails verification if a record is altered. The proof system itself is not implemented.
Consent Manager registration
Registration under Rule 4 opens on 13 November 2026, against Part A of the First Schedule — incorporation in India, a ₹2 crore net worth floor, and an interoperable platform. We are not a registered Consent Manager today, and no one is, because the register does not open until then.
Independent certification
No SOC 2 report or ISO certificate has been issued for this platform. When one is, it will appear here with its scope, date and auditor, and the report will be available under NDA. Until then, treat the security section as design intent you are entitled to test.