AI Suite

Compliance is a bad place to be confidently wrong

Four AI modules are being built. None has shipped, and this page will not pretend otherwise while you are deciding.

Join the waitlist See what is automated today Or check your DPDP score — free, five minutes, no account.
Today

Automated already, and none of it guesses

The platform decides a great deal on its own. Every one of those decisions is a rule you can read, not a model you have to trust.

01

Your score and your exposure

Ten weighted dimensions, penalties drawn from the Act’s own Schedule, and the three gaps that cost you most, ranked. The same answers from the same inputs, every time.

02

Which notices you need

Your industry and a few facts about what you process select the templates that apply, and flag where §9 children’s provisions change the answer.

03

What a request is really asking

A grievance mentioning deletion is recognised as carrying an erasure right and routed as one, so it lands in the right queue rather than the polite one.

04

Which systems a breach touched

Naming an affected system derives the categories and the cohort from your registry, which is the hardest question of the first hour.

05

What is overdue, everywhere

Every clock across every module — rights, breach, retention, expiring agreements — resolved into one queue, worst first, with nobody maintaining a spreadsheet of deadlines.

This is AI compliance automation in the sense that matters commercially — work that used to need a person no longer does. It is not a language model, and we would rather tell you that than let the word do work the software is not doing. Where AI compliance automation usually means a model answering, here it means a rule deciding and showing you which rule.

§10 · Rule 13

Deploying AI on personal data is itself an obligation

If you are named a Significant Data Fiduciary, algorithmic due diligence is not good practice. It is prescribed.

01

You must verify the software

An SDF has to satisfy itself that algorithmic software it deploys to process personal data is not likely to put data principals’ rights at risk. Including software it bought.

02

A model you cannot inspect

“The tool decided” is not diligence. If a vendor cannot tell you what its system relied on, you cannot discharge the duty by buying it.

03

The audit will ask

Rule 13 also requires a data protection impact assessment and an independent audit every twelve months. Both look at exactly this.

Which is the awkward position most AI compliance tools are in: sold to reduce your compliance burden, and adding one the moment you switch them on. It is also why these four modules are taking longer than they would if we only had to make them impressive.

In build

Four modules, and what each will do

Written as intentions rather than features, because not one of them is finished and you are entitled to know which is which.

AI Consent Drafter

Coming soon

Drafts a Rule 3 notice from the processing your registry already describes, in plain language and in the languages you serve. Your DPO edits and publishes it. How the drafter works

Policy Gap Detector

Coming soon

Reads the privacy policy and notices you already have and says where they fall short of the Act, naming the provision rather than the general shortfall. What it finds

Evidence Packager

Coming soon

Writes the plain-English summary that sits on top of an audit pack, so a board or a regulator meets a paragraph before they meet a manifest. What it writes

Compliance Copilot

Coming soon

Answers “are we allowed to do this?” against your own configuration, and shows the clause and the record it relied on to say so. What it answers

DPDP documentation automation is the near-term prize here: notices, policies and audit summaries are the work that consumes a DPO’s week and follows patterns a model is genuinely good at. Judgement calls are not on that list, deliberately.

Watch them work

One judgement from each

Four things a rule engine cannot do. Each is the argument its own page makes at length.

Consent Drafter · you wrote

“We process patient data to improve our services.”

It returns

Four separate purposes, only two of them optional — because a bundle cannot be consented to under §6.

And two more judgements
Policy Gap Detector · your policy says

“We will provide your information in a commonly used electronic format so you can transfer it to another provider.”

It flags

A portability commitment the Act never required. The word “portability” never appears, so no keyword scan finds it.

And what else it reads
Evidence Packager · the record

DSR-2026-000026 · erasure · billing done · clinical HELD

For your board

“One deletion request could not be completed in full, because another law requires the clinical record to be kept. The patient was told why the same day.”

And the same row for an auditor
Compliance Copilot · marketing asks

“Can we send the camp invite to everyone who visited endocrinology last year?”

It answers

No, not to all of them — 1,204 accepted that purpose, the rest consented only to treatment. Cited to §6(1) and to your own notice.

And when it declines instead
Where the line sits

Five decisions a model will never make here

Not because it could not produce an answer. Because someone has to be accountable for the answer, and it cannot be the software.

01

Whether a purpose needs consent

§6 consent or a §7 legitimate use is the most consequential call in the Act, and getting it wrong either way is expensive. It shows you what you set, and what follows.

02

Whether to erase

Erasure is irreversible and often owed to nobody — another statute may require you to keep the record. Two named people approve it, and no model is either of them.

03

Whether something is a breach

Rule 7 has no materiality threshold, so this is not a judgement about severity. It is a decision to start a clock, and a person makes it and is timestamped doing so.

04

What goes to the Board

A filing is a statement to a regulator by your organisation. It can be drafted from the record; it is signed by somebody who read it.

05

Whether a notice may publish

That already runs on a deterministic gate checking Rule 3 and §6 line by line. A generated draft goes through the same gate and earns no exemption from it.

A useful test for any tool in this category: ask which decisions it makes without a person, then ask who is answerable when one of them is wrong. If the answer is you, you have bought a liability with a subscription attached.

How they are being built

Four rules we are holding ourselves to

These are the reason it is slower, and the reason it will be defensible when it arrives.

1

It cites, or it says nothing

Every output names the provision and the record behind it. An answer you cannot trace is an answer you cannot use in front of the Board, so producing one is not a partial success.

2

Nothing binding happens unattended

Drafting is automated. Publishing a notice, approving an erasure, filing to the Board and signing anything remain a named person’s act, recorded as theirs.

3

It says when it does not know

A model that answers everything is worse than one that declines, because you cannot tell the confident answers from the invented ones until it matters.

4

Your data is not the training set

Your records are not used to train models, yours or anyone else’s. The registry is metadata-only for the same reason: what we do not hold cannot leak.

If you are shopping

Six questions worth asking any vendor

Including us. Every one of these has an answer that is easy to give and hard to give honestly.

1

“Show me an answer with its citation”

Not the interface — one real output with the provision and record behind it. A citation generated alongside an answer can be wrong in exactly the way the answer is.

2

“What happens when it does not know?”

Ask them to show you a refusal. A system that has never declined a question in a demo is either being asked easy questions or does not decline, and the second is worse.

3

“Which decisions happen without a person?”

Then ask who is answerable when one of them is wrong. Automation that acts unattended on personal data transfers the work to the vendor and leaves the liability with you, which is rarely how it is sold.

4

“Is our data used for training?”

Read the answer carefully. “We do not train our models on your data” leaves the model provider out of the sentence, and that is usually deliberate.

5

“Where does the processing happen?”

If personal data leaves India to reach a model, that is a transfer you have to be able to describe, and it belongs in your notice and your registry.

6

“What do we give our auditor?”

Rule 13 asks a Significant Data Fiduciary to have verified the algorithmic software it deploys. Ask what they will hand you to evidence that, and whether it exists yet.

Our own answers, for the record: nothing generative has shipped, so today the honest answer to most of these is “not applicable yet” — which is itself worth knowing when a competitor answers all six about a product they have.

We will tell you when one of these actually works.

Not when it demos well. Join the waitlist and you hear from us at the point it is doing something you could rely on — and the compliance suite it sits on is live today.

Questions

About AI and DPDP

Is RuleExpert AI-powered DPDP compliance software?

The platform automates a great deal — scoring, risk classification, template selection, request routing, breach scoping, deadline resolution — and all of it runs on deterministic rules rather than a language model. That is a deliberate choice, not a stage we have not reached: the same inputs give the same answer every time, which is what makes an outcome explainable to an auditor. The four generative modules are in build and every one of them is marked as such wherever it appears on this site.

Does the DPDP Act say anything about AI?

Not by name, and be wary of anyone claiming otherwise. What it does is impose duties that bite when you deploy it. A Significant Data Fiduciary must observe due diligence to verify that algorithmic software it deploys for processing personal data is not likely to pose a risk to data principals’ rights, and must run a data protection impact assessment and an independent audit every twelve months. If your AI touches personal data, that is where your obligation sits.

Could we use ChatGPT for this instead?

For understanding the Act, genuinely yes, and we would rather say so. For running compliance, three things stop it: pasting personal data into a general model is itself a processing decision you would have to justify, nothing it produces is tied to your actual configuration, and none of it lands in a record you can show a regulator. The value here is not the drafting. It is that the draft is anchored to your systems and the act of approving it is recorded.

Will our data be used to train your models?

No. Your records are not training data for us or for anyone we build on. It is worth asking every vendor this and reading the answer carefully, because the common formulation — “we do not use your data to train our models” — leaves the model provider out of the sentence.

Does using AI mean we need a DPIA?

If you are a Significant Data Fiduciary, you owe a data protection impact assessment periodically regardless, and deploying algorithmic software on personal data is exactly the kind of change that belongs in one. If you are not an SDF there is no prescribed DPIA — but the diligence question does not disappear, it just has no form to fill in. Either way, the practical answer is the same: know what the tool decides, what it reads, and where the processing happens, before you switch it on.

What happens to our data when a module runs?

The registry these modules read is metadata-only by design — system, table and column names, categories, owners, never values. That constraint was not built for the AI Suite, but it is what makes the AI Suite tractable: a drafter that works from the shape of your estate rather than its contents has far less to leak, and far less to justify. Where a module needs more than metadata, that will be stated on its own page rather than buried here.

Will any of this be sold separately?

Not decided, and we would rather say so than invent a packaging answer. What is settled is that the compliance suite does not depend on them: consent, rights, breach, vendors and the registry work today and will keep working whether or not you ever turn one of these on.

When do these ship?

We are not giving you a date, because a date we later move is worse than not having given one. The waitlist exists so we can tell you when a module does something you could rely on rather than something that demonstrates well. Meanwhile the compliance suite these sit on top of is live and does not depend on any of them.

In their words

What compliance teams tell us

“We always thought DPDP compliance was the client’s responsibility since we were only executing services. The evaluation made it clear that how we handle client data creates risk on our side too. It changed how we work internally.”
DSFounderDigital services firm
“We had a basic understanding of DPDP requirements, but the scorecard highlighted gaps we hadn’t identified internally — especially around consent handling and data visibility. It gave us a much clearer starting point.”
BSFounderB2B SaaS company
“The DPDP score was surprisingly insightful. Within minutes we could see where we stood and what needed immediate attention. It simplified something that initially felt quite complex.”
FPProduct HeadFintech platform
“After reviewing our score we opted for a consultation. The discussion was very practical — we got clear direction on what to fix first and how to approach DPDP compliance in a structured way.”
LGFounderLogistics company

Real client quotes, attributed by role and sector — we never name a client.

Insights

DPDP, explained properly

All articles

Working across

Healthcare & HospitalsDiagnostics & Labs Education & EdtechBFSI & Fintech InsuranceLogistics & Mobility Retail & E-commerceIT & SaaS ManufacturingReal Estate
Hospitality & TravelMedia & Publishing Professional ServicesStaffing & HR TelecomOnline Gaming NGO & Non-profitGovernment & PSU Pharma & Life SciencesAutomotive

The suite underneath is live.

Consent, rights, breach, vendors and the registry are working today and do not wait on any of this. Come and see those.