Upcoming · AI Suite
Evidence Packager
The evidence already assembles itself. This writes the document that goes on top, for whoever is about to read it.
Join the waitlist See what the pack already contains Manifest, hashes and re-authentication are live today.
Already working
Seven sections, each one hashed
Generating the package is a click today. What still costs a DPO two days is writing the covering note.
01
Assembled from live records
Active notices, notice versions, withdrawals, grievances, legitimate-use records, vendor coverage and the consent audit log — read at the moment you generate it.
02
Hashed section by section
Each section carries its own SHA-256, and a manifest hash is computed across all of them. Change one record afterwards and the hashes stop agreeing.
03
Anchored where it cannot be edited
The manifest hash is written back into the append-only consent log, so the pack can be shown later to be the same pack — by anyone holding it.
04
Re-authentication before download
Your password again, then a fifteen-minute window. An evidence pack is a concentrated view of your compliance posture and it should not be one click from a logged-in tab.
05
Every export recorded
Who generated it, when, and which variant they took. The act of producing evidence becomes part of the evidence, which is the question an auditor asks second.
§33(2) · Rule 13
What a regulator is actually asking
Not whether you have a process. What you did about one named person on one date, and how quickly.
01
Mitigation is an express factor
When the Board sets a penalty it must consider the mitigation you undertook and how promptly. That is a story about your conduct, and it has to be told from records.
02
An auditor arrives annually
Rule 13 puts an independent data auditor in front of a Significant Data Fiduciary every twelve months. They arrive with questions and no time to read a log.
03
Reconstruction is not evidence
A pack assembled the week you are asked for it proves you can assemble a pack. One written as the work happened proves the work happened.
This is why the hashing matters rather than being cryptographic decoration. A record you could have edited before showing it is a claim. A record whose hash was written into an append-only log months earlier is evidence.
Being built to
Turn a manifest into something readable
Nobody reads a manifest. The work that remains manual is the paragraph that makes the evidence underneath it navigable.
1
Narrate the period from the record
What the pack covers, what was handled, what was refused and on what grounds, what remains open. Written from the sections themselves, not from anyone’s recollection of the quarter.
2
Cite every sentence it writes
Each claim points at the record behind it, so a reader can drop from the summary into the evidence at any line. A narrative you cannot check against the pack is a story, and nobody is buying a story.
3
Surface what will be asked first
The overdue item, the refusal with thin grounds, the vendor whose agreement lapsed mid-period. An auditor finds these anyway; meeting them in your own summary is a materially better position than being shown them.
4
State absences as absences
Where the record is silent, the summary says so rather than writing around it. A pack that reads well while the evidence reads badly is the one outcome that would make all of this worthless.
Watch it work
One record. Three very different paragraphs.
The facts do not change and the hashes do not change. What a reader needs explained changes completely.
The record
DSR-2026-000026 · erasure · 3 legs · billing done · outreach done · clinical HELD
Plus the statute cited on the held leg, the two approvers, and the date each leg closed.
For an auditor
“Erasure request DSR-2026-000026 was partially fulfilled. Two of three systems were erased within the window. The clinical record was retained under the statutory minimum-retention period, and the refusal with grounds was issued to the data principal on the same day.”
The same record
DSR-2026-000026 · erasure · 3 legs · billing done · outreach done · clinical HELD
For your board
“One deletion request this quarter could not be completed in full, because another law requires the clinical record to be kept. The patient was told why, in writing, the same day. No deadline was missed.”
No reference numbers, no section numbers, and the reassurance stated explicitly because that is the question actually being asked.
The same record again
DSR-2026-000026 · erasure · 3 legs · billing done · outreach done · clinical HELD
For a customer’s procurement team
“Erasure requests are fulfilled across every system holding the individual, with statutory retention handled as a documented partial refusal rather than silent non-deletion.”
Framed as capability rather than as an incident, because they are clearing you as a supplier, not investigating you.
Same evidence, different reader
Three people, three documents
The facts do not change. What a reader needs explaining, and what they can be assumed to know, changes completely.
01
The regulator or auditor
Wants provisions, dates and traceability. Assumes the law. Needs to get from a question to the underlying record in as few steps as possible.
02
Your board
Wants position and direction — better or worse than last quarter, and what it would cost if it went wrong. Does not want section numbers.
03
A customer’s procurement team
Wants to close a questionnaire and clear you as a supplier. Needs the same facts framed as assurance rather than as a filing.
Three variants exist today — the regulator pack, the board report and a handover pack — and each is currently written by hand from the same underlying sections. Generating all three from one dataset, with the same evidence behind each, is the part worth automating.
Your control
Written by the model, attested by you
You are handing this to someone who may act on it. That signature has to belong to a person.
01
You read it before it leaves
The summary is editable and the download still requires re-authentication. Nothing is sent anywhere on your behalf.
02
It cannot improve a bad quarter
Three breached deadlines is three breached deadlines. The summary describes the record it was given, and the record is hashed.
03
The approval is recorded
Whoever approved the pack is named in the log alongside it, which is precisely the fact an auditor is establishing when they ask who signed it.
The pack itself works today.
Seven hashed sections, a manifest anchored in a log nobody can edit, and re-authentication before download. Only the covering note is still written by hand.
Questions
About the Evidence Packager
What can we hand an auditor today?
The package itself, which is the substantial part. Seven sections — active notices, notice versions, withdrawals, grievances, legitimate-use records, vendor coverage and the consent audit log — each hashed with SHA-256, with the manifest hash written back into an append-only log so the pack can be shown later to be unaltered. Downloading it requires re-authentication and a fifteen-minute window. What you write by hand today is the covering summary.
Is there a 48-hour deadline to respond to the Board?
No, and it is worth being careful with that number because it appears in DPDP material a lot. The only 48 hours in the DPDP framework is Rule 8(2)’s pre-erasure notice — the warning you must give a person before erasing their data on inactivity. It has nothing to do with audits. The timings that do exist are Rule 7’s breach obligations, which are without delay to the Board and to affected people plus full particulars within 72 hours, and Rule 13’s annual audit for a Significant Data Fiduciary.
Does the Board publish a format for evidence?
Not at the time of writing, and anyone claiming their pack conforms to an official investigation format is describing something that does not exist. What you can do is structure evidence the way an investigation actually proceeds — by obligation, by person, by date — and make every claim traceable to a record. That is what the sections are organised around.
Why does a summary need AI at all?
It does not, strictly. A DPO can write one, and they do — it costs a day or two per quarter and it is the least interesting day of the quarter. The reason to automate it is consistency rather than effort: a summary generated from the record covers the awkward parts, and one written by the person being assessed sometimes does not. The audience variants are the other reason — the same evidence has to become three quite different documents.
Could we just paste our logs into a general AI tool?
Please do not. Those logs contain hashed data principal identifiers and the full shape of your processing, and putting them into a general model is itself a processing decision you would have to justify — possibly in the very audit you are preparing for. Doing it inside the platform keeps the summary tied to hashed evidence that never leaves the boundary you have already assessed.
When does it ship?
No date. Join the waitlist and we will tell you when the summary is one we would put in front of an auditor ourselves. The pack it sits on top of is live and does not depend on it.
What compliance teams tell us
Real client quotes, attributed by role and sector — we never name a client.
DPDP, explained properly
DPDP in India: The Complete Guide to Data Protection Compliance, DPDP Guidelines and Automated Compliance Management (2026)
3 September 2026 · 35 min read DPDP ActHealthcare Vendor Governance Under India’s DPDP Act: The Complete 2026–27 Compliance Framework
27 August 2026 · 32 min read DPDP ActDPDP vs GDPR Compliance Tool: What’s Actually Different, and What a Tool Needs to Handle Both
26 August 2026 · 34 min readWorking across
Evidence, already assembled.
Every action recorded as it happened, hashed, and anchored where it cannot be revised. That part is live now.


