Questions
Evaluating the platform
How long before we are actually using it?
The Scorecard takes five minutes and needs no login. From signing up, a first consent notice can be live the same afternoon — you pick a vetted template, fill in your details and publish. The registry and the phased plan are the work of the first week or two, and you are confirming a pre-filled map rather than drawing one from nothing.
What does DPDP compliance automation actually do here?
It does the work that has a clock on it. A retention date arrives and the pre-erasure notice goes out on its own; a consent is withdrawn and every downstream purpose stops; a rights request lands and the tasks fan out to each system that holds the person’s data; a breach is declared and the 72-hour Board clock starts running with the filing half-drafted. What DPDP compliance automation does not do is decide anything a person should be deciding — approving an erasure, judging a grievance, signing a Board filing. Those stay with your named people, and the platform records who did them and when. That line is the difference between privacy automation you can defend to the Board and a system that acted on its own and left nobody accountable.
Do you need access to our customer data?
No, and this is deliberate. We hold the shape of your estate — which systems you run, what categories of data they hold, which purposes they serve, who owns them. No agents on your servers, no database credentials, no copies of anyone’s records. The one exception is consent itself, where we hold the record of what was agreed, and the person is identified by a one-way hash rather than by name.
Where does it run, and who can see our information?
On infrastructure in India — data at rest and backups both stay in-country, which is what makes the residency conversation short. We are ISO 27001 certified. Inside your account, access is by role, and the audit log is append-only at the database level: the system will refuse an edit or a delete on it, which is enforcement rather than policy.
Do we have to map every system before anything works?
No. Consent, rights requests and breach logging all work from day one. The registry makes them better — a rights request that knows which systems to look in, a breach that knows who was affected — so most teams do it in the first month. You can start with the two or three systems that matter and grow the map as you go.
Does it connect to the systems we already run?
Over 300 systems are recognised out of the box — Indian and global, by sector — so you pick your hospital system, CRM or HRMS from a catalogue that already knows what it typically holds and how sensitive that is. Which of those you connect live, versus declare and manage, depends on your stack; that is a conversation for the demo rather than a claim on a page.
Can our consultant, DPO or auditor work inside it?
Yes. External advisors get their own access to the account they are engaged on, and an auditor gets a read-only view with the evidence and its hashes. That matters for Rule 13, which requires an independent data auditor — they need to verify your programme without us or you standing between them and the record.
What happens to our evidence if we stop using RuleExpert?
You take it with you. The evidence pack is a set of ordinary files — the audit log, the notices and their versions, withdrawal and grievance records, vendor coverage — with a SHA-256 manifest anyone can re-verify independently. It is designed to be readable and checkable without our software, because evidence that only works inside one vendor’s product is not much use in front of the Board.
Which modules are live today?
All ten compliance modules on this page are live and in use: consent, data principal rights, breach, vendor governance, data registry, retention and erasure, assessments, audit and evidence, the scorecard and the trust centre. The AI suite is in development and marked as such wherever it appears — we would rather show you a shipping product than a roadmap.