Questions Evaluating the platform
How long before we are actually using it?
The Scorecard takes five minutes and needs no login. From signing up, a first consent
notice can be live the same afternoon — you pick a vetted template, fill in your details and
publish. The registry and the phased plan are the work of the first week or two, and you are
confirming a pre-filled map rather than drawing one from nothing.
What does DPDP compliance automation actually do here?
It does the work that has a clock on it. A retention date arrives and the pre-erasure
notice goes out on its own; a consent is withdrawn and every downstream purpose stops; a
rights request lands and the tasks fan out to each system that holds the person’s data;
a breach is declared and the 72-hour Board clock starts running with the filing half-drafted.
What DPDP compliance automation does not do is decide anything a person should be deciding
— approving an erasure, judging a grievance, signing a Board filing. Those stay with your
named people, and the platform records who did them and when. That line is the difference
between privacy automation you can defend to the Board and a system that acted on its own
and left nobody accountable.
Do you need access to our customer data?
No, and this is deliberate. We hold the shape of your estate — which systems you
run, what categories of data they hold, which purposes they serve, who owns them. No agents
on your servers, no database credentials, no copies of anyone’s records. The one
exception is consent itself, where we hold the record of what was agreed, and the person is
identified by a one-way hash rather than by name.
Where does it run, and who can see our information?
On infrastructure in India — data at rest and backups both stay in-country, which is what
makes the residency conversation short. We are ISO 27001 certified. Inside your account,
access is by role, and the audit log is append-only at the database level: the system will
refuse an edit or a delete on it, which is enforcement rather than policy.
Do we have to map every system before anything works?
No. Consent, rights requests and breach logging all work from day one. The registry makes
them better — a rights request that knows which systems to look in, a breach that
knows who was affected — so most teams do it in the first month. You can start with the two
or three systems that matter and grow the map as you go.
Does it connect to the systems we already run?
Over 300 systems are recognised out of the box — Indian and global, by sector — so you
pick your hospital system, CRM or HRMS from a catalogue that already knows what it typically
holds and how sensitive that is. Which of those you connect live, versus declare and manage,
depends on your stack; that is a conversation for the demo rather than a claim on a page.
Can our consultant, DPO or auditor work inside it?
Yes. External advisors get their own access to the account they are engaged on, and an
auditor gets a read-only view with the evidence and its hashes. That matters for Rule 13,
which requires an independent data auditor — they need to verify your programme
without us or you standing between them and the record.
What happens to our evidence if we stop using RuleExpert?
You take it with you. The evidence pack is a set of ordinary files — the audit log, the
notices and their versions, withdrawal and grievance records, vendor coverage — with a
SHA-256 manifest anyone can re-verify independently. It is designed to be readable and
checkable without our software, because evidence that only works inside one vendor’s
product is not much use in front of the Board.
Which modules are live today?
All ten compliance modules on this page are live and in use: consent, data principal
rights, breach, vendor governance, data registry, retention and erasure, assessments, audit
and evidence, the scorecard and the trust centre. The AI suite is in development and marked
as such wherever it appears — we would rather show you a shipping product than a roadmap.