Privacy & security products

Independent products. One account.

NoIdMe builds focused products for privacy, consent, device intelligence and auth — each with its own docs, API and pricing. Use one, or compose several.

Free, no signup — scan your homepage and see which trackers need consent, in about 30 seconds.

Independent products, one account · built in India, ahead of the DPDP enforcement window.

The product portfolio

Comply

DPDP Suite + Consent SDK — capture consent you can prove, and a banner that actually blocks.

Enforce & identify

noidme.js blocks unconsented requests; glassprint tells real humans from bots and agents.

Authenticate

Passkeys — phishing-resistant auth with no password database to breach.

Independent, composableComply · Enforce · Identify · Authenticate
Deadline · India DPDP Act 2023

India's DPDP Act is now law, and the compliance clock is running.

The DPDP Rules are notified and rolling out in phases. Itemised §5 consent notices, breach reporting, data-principal rights, the §9 children's-data gate, and penalties up to ₹250 crore are all on the clock. That's your build window, not your buffer.

Source: DPDP Rules 2025, MeitY (Gazette G.S.R. 846(E)). Phased dates per the published timeline; informational, not legal advice.

  1. NowData Protection Board is live
  2. ~ Nov 2026Consent Manager framework lands
  3. ~ May 2027Full enforcement for every Data Fiduciary

What you get

DPDP Act coverage
§5–§14 + Rules
Server SDKs + embed
Node · Python · Go · Java
Consent receipts
Tamper-evident
Erasure
Crypto-shred

Everything the DPDP Act asks of a Data Fiduciary

This isn't a cookie banner with a compliance label. It implements the statutory obligations in full, each backed by a verifiable record.

Notice manager (§5)

Versioned, hashed notices with 22 Eighth-Schedule language coverage and a stale-notice serving gate.

Consent ledger (§6/§6(10))

Per-tenant, append-only hash chain. Every consent, withdrawal and erasure is a signed, verifiable link.

Rights & DSAR (§11/§12)

Person-verified access, correction, withdrawal and reversible erasure that ends in a crypto-shred.

Breach (Rule 7)

Multi-clock breach lifecycle (without-delay / 72h / 6h), SIEM auto-open, and affected-principal intimation.

RoPA & SDF (§10)

Records of processing, DPIA register, vendor/processor risk register and DPO state for Significant Data Fiduciaries.

Cookie CMP

Declared cookie registry, banner config and a scan-diff that flags undeclared trackers.

Multi-tenant, Postgres + row-level isolation, SaaS or self-host. Notice content & translations stay counsel-gated.

Data principals, verified and in control

Rights act on a verified person, never a value the caller supplies. That blocks erasure-as-DoS and DSAR-as-exfiltration.

OTP / DigiLocker / SSO identity verification

§11 access summary + processing disclosure

Correction & completion requests

§6(4) consent withdrawal

Step-up assurance for destructive erasure

§14 nominee on death / incapacity

§13 grievance with a time-bound response

Verifiable consent receipt for the individual

Drop it into any stack

A browser embed, four server SDKs, webhooks, and connectors. Run it as SaaS or self-hosted in your own cloud.

Browser embed

One snippet adds a themeable, multilingual consent banner with prior script-blocking and a verifiable receipt.

Server SDKs

Node, Python, Go and Java share one 116-endpoint surface: check consent, run rights, handle breach, pull evidence.

Webhooks & events

React to consent withdrawal, erasure execution, breach clocks and grievance SLAs in real time.

SIEM connectors

Auto-open a breach (and start the Rule-7 clocks from detection time) from Splunk / Sentinel / QRadar alerts.

KMS (AWS / GCP)

Per-tenant non-repudiation signing where the private key never enters the process.

Self-host & residency

Deploy into your AWS / GCP / Azure with your Postgres + KMS. Data stays in your VPC / region.

Security, isolation & data residency

Multi-tenant Postgres with row-level security keyed per request; crypto-shred erasure; per-tenant signing with HMAC / ECDSA / KMS; least-privilege publishable / secret / read-only / operator key classes.

Self-host so personal data never leaves your VPC, bring your own KMS for full residency control, and hand a regulator a chain anyone can verify against your published key. Not legal advice; DPDP guidance stays counsel-gated.

01

Capture

Record consent against a versioned §5 notice, with affirmative action and the §6/§7/§17 lawful-basis taxonomy enforced.

02

Prove

Append each event to a per-tenant tamper-evident hash chain and sign it. The result is a §6(10) receipt you can hand a regulator.

03

Enforce & erase

Gate processing on live consent; on §12 erasure, crypto-shred the per-principal key so the data is unrecoverable.

How it actually works

The questions a DPO and an engineer both ask.

How are consent receipts tamper-evident?

Every consent, withdrawal and erasure is appended to a per-tenant, append-only hash chain and the head is signed. Edit, back-date or delete a link and verification breaks.

  • Signed with HMAC (dev), ECDSA P-256, or a KMS-delegated per-tenant key
  • Verifiable with the tenant's PUBLISHED public key (JWKS), even by a third party
  • The §6(10) receipt carries the exact notice version, hash and lawful basis
What does crypto-shred erasure actually do?

Free-text PII is sealed under a per-principal data-encryption key. §12 erasure destroys that key, so ciphertext left in tables, WAL and backups is undecryptable.

  • Sealed at write, so the row never holds plaintext
  • Sticky tombstone: the key can't be re-minted after a shred
  • A reversible grace window (also the Rule-8 48h pre-erasure intimation) precedes the shred
How does the §9 children gate work?

§9(3) absolutely bars tracking, behavioural monitoring and targeted ads at children. The gate is fail-closed: a restricted purpose clears only for a verified adult, and a self-declared 'adult' is treated as a child.

  • A server-trusted age verdict (DigiLocker / UIDAI) overrides any client claim
  • Verifiable parental consent for a child's ordinary processing (§9(1))
  • A lying 'adult/verified' request is overridden by the stored verdict
Can we self-host and keep data in India?

Yes. Run NoIdMe in your own cloud with your Postgres and your KMS, so personal data never leaves your VPC or region.

  • Managed SaaS, an annual license, or a one-time self-host license
  • Bring-your-own KMS + Postgres; row-level tenant isolation throughout
  • Docker / Helm / Terraform deployment (rolling out)

Get DPDP-ready, with evidence

We're onboarding design partners ahead of the DPDP enforcement window. See the suite end-to-end, or start integrating today.

Book a demo