Upcoming · AI Suite

Evidence Packager

The evidence already assembles itself. This writes the document that goes on top, for whoever is about to read it.

Join the waitlist See what the pack already contains Manifest, hashes and re-authentication are live today.
Already working

Seven sections, each one hashed

Generating the package is a click today. What still costs a DPO two days is writing the covering note.

01

Assembled from live records

Active notices, notice versions, withdrawals, grievances, legitimate-use records, vendor coverage and the consent audit log — read at the moment you generate it.

02

Hashed section by section

Each section carries its own SHA-256, and a manifest hash is computed across all of them. Change one record afterwards and the hashes stop agreeing.

03

Anchored where it cannot be edited

The manifest hash is written back into the append-only consent log, so the pack can be shown later to be the same pack — by anyone holding it.

04

Re-authentication before download

Your password again, then a fifteen-minute window. An evidence pack is a concentrated view of your compliance posture and it should not be one click from a logged-in tab.

05

Every export recorded

Who generated it, when, and which variant they took. The act of producing evidence becomes part of the evidence, which is the question an auditor asks second.

§33(2) · Rule 13

What a regulator is actually asking

Not whether you have a process. What you did about one named person on one date, and how quickly.

01

Mitigation is an express factor

When the Board sets a penalty it must consider the mitigation you undertook and how promptly. That is a story about your conduct, and it has to be told from records.

02

An auditor arrives annually

Rule 13 puts an independent data auditor in front of a Significant Data Fiduciary every twelve months. They arrive with questions and no time to read a log.

03

Reconstruction is not evidence

A pack assembled the week you are asked for it proves you can assemble a pack. One written as the work happened proves the work happened.

This is why the hashing matters rather than being cryptographic decoration. A record you could have edited before showing it is a claim. A record whose hash was written into an append-only log months earlier is evidence.

Being built to

Turn a manifest into something readable

Nobody reads a manifest. The work that remains manual is the paragraph that makes the evidence underneath it navigable.

1

Narrate the period from the record

What the pack covers, what was handled, what was refused and on what grounds, what remains open. Written from the sections themselves, not from anyone’s recollection of the quarter.

2

Cite every sentence it writes

Each claim points at the record behind it, so a reader can drop from the summary into the evidence at any line. A narrative you cannot check against the pack is a story, and nobody is buying a story.

3

Surface what will be asked first

The overdue item, the refusal with thin grounds, the vendor whose agreement lapsed mid-period. An auditor finds these anyway; meeting them in your own summary is a materially better position than being shown them.

4

State absences as absences

Where the record is silent, the summary says so rather than writing around it. A pack that reads well while the evidence reads badly is the one outcome that would make all of this worthless.

Watch it work

One record. Three very different paragraphs.

The facts do not change and the hashes do not change. What a reader needs explained changes completely.

The record

DSR-2026-000026 · erasure · 3 legs · billing done · outreach done · clinical HELD

Plus the statute cited on the held leg, the two approvers, and the date each leg closed.
For an auditor

“Erasure request DSR-2026-000026 was partially fulfilled. Two of three systems were erased within the window. The clinical record was retained under the statutory minimum-retention period, and the refusal with grounds was issued to the data principal on the same day.”

The same record

DSR-2026-000026 · erasure · 3 legs · billing done · outreach done · clinical HELD

For your board

“One deletion request this quarter could not be completed in full, because another law requires the clinical record to be kept. The patient was told why, in writing, the same day. No deadline was missed.”

No reference numbers, no section numbers, and the reassurance stated explicitly because that is the question actually being asked.
The same record again

DSR-2026-000026 · erasure · 3 legs · billing done · outreach done · clinical HELD

For a customer’s procurement team

“Erasure requests are fulfilled across every system holding the individual, with statutory retention handled as a documented partial refusal rather than silent non-deletion.”

Framed as capability rather than as an incident, because they are clearing you as a supplier, not investigating you.
Same evidence, different reader

Three people, three documents

The facts do not change. What a reader needs explaining, and what they can be assumed to know, changes completely.

01

The regulator or auditor

Wants provisions, dates and traceability. Assumes the law. Needs to get from a question to the underlying record in as few steps as possible.

02

Your board

Wants position and direction — better or worse than last quarter, and what it would cost if it went wrong. Does not want section numbers.

03

A customer’s procurement team

Wants to close a questionnaire and clear you as a supplier. Needs the same facts framed as assurance rather than as a filing.

Three variants exist today — the regulator pack, the board report and a handover pack — and each is currently written by hand from the same underlying sections. Generating all three from one dataset, with the same evidence behind each, is the part worth automating.

Your control

Written by the model, attested by you

You are handing this to someone who may act on it. That signature has to belong to a person.

01

You read it before it leaves

The summary is editable and the download still requires re-authentication. Nothing is sent anywhere on your behalf.

02

It cannot improve a bad quarter

Three breached deadlines is three breached deadlines. The summary describes the record it was given, and the record is hashed.

03

The approval is recorded

Whoever approved the pack is named in the log alongside it, which is precisely the fact an auditor is establishing when they ask who signed it.

The pack itself works today.

Seven hashed sections, a manifest anchored in a log nobody can edit, and re-authentication before download. Only the covering note is still written by hand.

Questions

About the Evidence Packager

What can we hand an auditor today?

The package itself, which is the substantial part. Seven sections — active notices, notice versions, withdrawals, grievances, legitimate-use records, vendor coverage and the consent audit log — each hashed with SHA-256, with the manifest hash written back into an append-only log so the pack can be shown later to be unaltered. Downloading it requires re-authentication and a fifteen-minute window. What you write by hand today is the covering summary.

Is there a 48-hour deadline to respond to the Board?

No, and it is worth being careful with that number because it appears in DPDP material a lot. The only 48 hours in the DPDP framework is Rule 8(2)'s pre-erasure notice — the warning you must give a person before erasing their data on inactivity. It has nothing to do with audits. The timings that do exist are Rule 7's breach obligations, which are without delay to the Board and to affected people plus full particulars within 72 hours, and Rule 13's annual audit for a Significant Data Fiduciary.

Does the Board publish a format for evidence?

Not at the time of writing, and anyone claiming their pack conforms to an official investigation format is describing something that does not exist. What you can do is structure evidence the way an investigation actually proceeds — by obligation, by person, by date — and make every claim traceable to a record. That is what the sections are organised around.

Why does a summary need AI at all?

It does not, strictly. A DPO can write one, and they do — it costs a day or two per quarter and it is the least interesting day of the quarter. The reason to automate it is consistency rather than effort: a summary generated from the record covers the awkward parts, and one written by the person being assessed sometimes does not. The audience variants are the other reason — the same evidence has to become three quite different documents.

Could we just paste our logs into a general AI tool?

Please do not. Those logs contain hashed data principal identifiers and the full shape of your processing, and putting them into a general model is itself a processing decision you would have to justify — possibly in the very audit you are preparing for. Doing it inside the platform keeps the summary tied to hashed evidence that never leaves the boundary you have already assessed.

When does it ship?

No date. Join the waitlist and we will tell you when the summary is one we would put in front of an auditor ourselves. The pack it sits on top of is live and does not depend on it.

In their words

What compliance teams tell us

“We always thought DPDP compliance was the client’s responsibility since we were only executing services. The evaluation made it clear that how we handle client data creates risk on our side too. It changed how we work internally.”
DSFounderDigital services firm
“We had a basic understanding of DPDP requirements, but the scorecard highlighted gaps we hadn’t identified internally — especially around consent handling and data visibility. It gave us a much clearer starting point.”
BSFounderB2B SaaS company
“The DPDP score was surprisingly insightful. Within minutes we could see where we stood and what needed immediate attention. It simplified something that initially felt quite complex.”
FPProduct HeadFintech platform
“After reviewing our score we opted for a consultation. The discussion was very practical — we got clear direction on what to fix first and how to approach DPDP compliance in a structured way.”
LGFounderLogistics company

Real client quotes, attributed by role and sector — we never name a client.

Insights

DPDP, explained properly

All articles

Working across

Healthcare & HospitalsDiagnostics & Labs Education & EdtechBFSI & Fintech InsuranceLogistics & Mobility Retail & E-commerceIT & SaaS ManufacturingReal Estate
Hospitality & TravelMedia & Publishing Professional ServicesStaffing & HR TelecomOnline Gaming NGO & Non-profitGovernment & PSU Pharma & Life SciencesAutomotive

Evidence, already assembled.

Every action recorded as it happened, hashed, and anchored where it cannot be revised. That part is live now.