Comply
DPDP Suite + Consent SDK — capture consent you can prove, and a banner that actually blocks.
NoIdMe builds focused products for privacy, consent, device intelligence and auth — each with its own docs, API and pricing. Use one, or compose several.
Free, no signup — scan your homepage and see which trackers need consent, in about 30 seconds.
Independent products, one account · built in India, ahead of the DPDP enforcement window.
DPDP Suite + Consent SDK — capture consent you can prove, and a banner that actually blocks.
noidme.js blocks unconsented requests; glassprint tells real humans from bots and agents.
Passkeys — phishing-resistant auth with no password database to breach.
A product for each job — compliance, enforcement, device intelligence, auth. Each stands on its own, with its own docs and pricing. Use one, or compose several.
Capture consent under the right lawful basis, mint tamper-evident §6(10) receipts, run rights/DSAR and breach, and crypto-shred on erasure — an API + self-host engine for India's DPDP Act 2023.
A ~5 KB drop-in banner that gates tags until consent — and turns every consent into a cryptographically verifiable receipt. One snippet, zero dependencies.
Patches every networking primitive so unconsented requests never leave the page — fail-closed by default, and honest about exactly what it covers. MIT, on npm.
Tell real humans from bots and agents, with spoof-resistant device IDs and additive fraud signals that feed your risk engine. Self-host so your signals never leave your perimeter.
A correct WebAuthn engine for web, iOS and Android — add passkeys to your existing auth with no password database to breach.
This isn't a cookie banner with a compliance label. It implements the statutory obligations in full, each backed by a verifiable record.
Versioned, hashed notices with 22 Eighth-Schedule language coverage and a stale-notice serving gate.
Per-tenant, append-only hash chain. Every consent, withdrawal and erasure is a signed, verifiable link.
Person-verified access, correction, withdrawal and reversible erasure that ends in a crypto-shred.
Multi-clock breach lifecycle (without-delay / 72h / 6h), SIEM auto-open, and affected-principal intimation.
Records of processing, DPIA register, vendor/processor risk register and DPO state for Significant Data Fiduciaries.
Declared cookie registry, banner config and a scan-diff that flags undeclared trackers.
Multi-tenant, Postgres + row-level isolation, SaaS or self-host. Notice content & translations stay counsel-gated.
Capture consent against the exact notice version, record the lawful basis, and gate processing on it. The §6(10) proof comes back in the same call.
Affirmative-action capture, per-purpose selection
Withdrawal as easy as giving consent (§6(4))
Processing gate: can-I-process purpose X now?
Regulator-ready evidence pack in one call
Independent chain verification (with or without a key)
Sandbox / live data isolation
Consent-freshness expiry (re-consent due)
Per-principal auditable answer, by notice version
Rights act on a verified person, never a value the caller supplies. That blocks erasure-as-DoS and DSAR-as-exfiltration.
OTP / DigiLocker / SSO identity verification
§11 access summary + processing disclosure
Correction & completion requests
§6(4) consent withdrawal
Step-up assurance for destructive erasure
§14 nominee on death / incapacity
§13 grievance with a time-bound response
Verifiable consent receipt for the individual
A browser embed, four server SDKs, webhooks, and connectors. Run it as SaaS or self-hosted in your own cloud.
One snippet adds a themeable, multilingual consent banner with prior script-blocking and a verifiable receipt.
Node, Python, Go and Java share one 116-endpoint surface: check consent, run rights, handle breach, pull evidence.
React to consent withdrawal, erasure execution, breach clocks and grievance SLAs in real time.
Auto-open a breach (and start the Rule-7 clocks from detection time) from Splunk / Sentinel / QRadar alerts.
Per-tenant non-repudiation signing where the private key never enters the process.
Deploy into your AWS / GCP / Azure with your Postgres + KMS. Data stays in your VPC / region.
Multi-tenant Postgres with row-level security keyed per request; crypto-shred erasure; per-tenant signing with HMAC / ECDSA / KMS; least-privilege publishable / secret / read-only / operator key classes.
Self-host so personal data never leaves your VPC, bring your own KMS for full residency control, and hand a regulator a chain anyone can verify against your published key. Not legal advice; DPDP guidance stays counsel-gated.
01
Record consent against a versioned §5 notice, with affirmative action and the §6/§7/§17 lawful-basis taxonomy enforced.
02
Append each event to a per-tenant tamper-evident hash chain and sign it. The result is a §6(10) receipt you can hand a regulator.
03
Gate processing on live consent; on §12 erasure, crypto-shred the per-principal key so the data is unrecoverable.
The questions a DPO and an engineer both ask.
Every consent, withdrawal and erasure is appended to a per-tenant, append-only hash chain and the head is signed. Edit, back-date or delete a link and verification breaks.
Free-text PII is sealed under a per-principal data-encryption key. §12 erasure destroys that key, so ciphertext left in tables, WAL and backups is undecryptable.
§9(3) absolutely bars tracking, behavioural monitoring and targeted ads at children. The gate is fail-closed: a restricted purpose clears only for a verified adult, and a self-declared 'adult' is treated as a child.
Yes. Run NoIdMe in your own cloud with your Postgres and your KMS, so personal data never leaves your VPC or region.
We're onboarding design partners ahead of the DPDP enforcement window. See the suite end-to-end, or start integrating today.
Book a demo