Skip to content
The DPDP Operating System

The Complete Operating System for DPDP Governance

Statutory obligations become controls with owners, evidence with reviewers, and a record you can put in front of an auditor.

The Traceability Engine

From statute to evidence, in one unbroken chain

Follow any obligation through the full lifecycle. Select a stage to see how DPDPNiti links regulation to real, auditable proof.

Regulatory Act

DPDP Act, 2023

The statutory source. Provisions of the Act and the Rules are held as versioned content with the Gazette citation, the publication date and the retrieval date recorded against each one — and a summary is always labelled as our summary, never as the statute.

The actual product

Screens, not mock-ups

Captured from a synthetic organisation in the running product. Nothing here is drawn, composited or retouched.

app.dpdpniti.com/
The DPDPNiti dashboard showing seven tiles: compliance readiness, assessment status, control coverage, evidence coverage, top risks, top gaps and open remediation. Each count is shown as a number out of a total, with undetermined items counted separately rather than folded into either side.
The dashboard. Seven tiles, each carrying the basis it was calculated on — and counts of the form “X of Y, with Z undetermined”, because a percentage hides which of the three moved.
app.dpdpniti.com/readiness
A completed DPDP readiness result showing an overall rating, the sections it decomposes into, and a note that the rating is capped by a blocking gap.
The readiness result. Stored and versioned against the scoring model that produced it, decomposed by section, and showing where a blocking gap caps the rating regardless of the arithmetic.
app.dpdpniti.com/controls
The controls register listing adopted controls with their accountable owner and an implementation status of Implemented, In progress or Not started.
Controls, owners and status. Every obligation that applies has a control; every control has somebody accountable for it.
app.dpdpniti.com/readiness/gaps/Q-DPDP-022
A single readiness gap opened in full, marked with a Blocking gap chip. The question asks whether the organisation could notify every affected individual, with all five required elements, without delay after discovering a breach. The screen sets out what the law says — labelled as an operational rendering rather than a quotation or legal advice — why the provision applies to this organisation, what good looks like and how to check it, and the answer given, with its weight and what it is costing the readiness score.
One gap, in full. A blocking gap caps the rating however well everything else scores — and the screen shows the provision, why it reaches you, and what closing it would take, while labelling its own rendering of the law as a rendering rather than advice.

Core capabilities

Five modules that are running, and one that is not

These are the product's own headings. The roadmap tab is marked so you can tell the difference without booking a call.

Sections 4–17, and the Rules

Applicability, assessment and readiness

Decide what the Act actually asks of your organisation, answer it once, and keep the answer — versioned, decomposed and defensible.

  • Scope questions drive applicability rules; a provision that cannot be decided from the rules says so instead of guessing
  • A stored, versioned readiness result with the scoring model recorded against it
  • Blocking gaps cap the rating regardless of the arithmetic, and the cap is shown
  • Re-assess later without destroying what the last one said

One application, one tenant boundary, one audit trail. Every module reads the same records rather than keeping its own copy.

Deployment and architecture

How it runs, stated plainly

One deployment model today and one on the roadmap — told apart on the page rather than in a sales call.

Deployment

Managed SaaS

The way DPDPNiti ships today: multi-tenant, hosted by us in India, updated continuously, with no infrastructure for your team to run.

Private deploymentComing

The same containers as an annual term licence for organisations whose policy requires their own infrastructure, with a signed licence file carrying the tenant, the tier and the entitlements. Designed and decided; not available today.

Regulatory content updates

The corpus of provisions, obligations and controls is versioned content with its own release trail, so the law moving does not mean your platform standing still.

Hosted in India

Production runs in the Mumbai region. The Act does not broadly mandate localisation today, and we do not claim it does — we host here because Indian buyers ask, and because transfer restrictions may yet arrive for Significant Data Fiduciaries.

Isolation enforced by the database

Row-level security on every tenant-owned table, with an application role that cannot bypass it and a separate, narrowly scoped role for tenant resolution. A forgotten WHERE clause returns nothing, not somebody else’s data.

A documented REST API

Every screen in the product is built on the same versioned REST API, published as an OpenAPI document, authenticated and permission-checked exactly as the interface is.

See it against your own obligations

A walkthrough of the real product — the assessment, the controls, the evidence and the audit trail — with the roadmap shown as the roadmap.