Platform and services

Six modules.
Spans your Whole IT & Management Infrastructure.

Software that does the compliance work, run by certified DPOs inside the systems you already have.

The platform

Built as modules.

Each one runs on its own and reports into the same evidence trail.

01Live

Data Intelligence

Finds and classifies personal data everywhere it sits.

Connects to databases, cloud storage and SaaS, classifies the personal data it finds, and builds the processing register from the result.

  • Discovery
  • Classification
  • Lineage
  • RoPA
02Live

DSAR Module

Access, correction and erasure requests, answered on the clock.

A hosted request portal with identity verification, SLA timers on every request, and triage for the ones that turn out to be incidents.

  • Request portal
  • Identity checks
  • SLA timers
  • Breach triage
03Live

Consent and Rights

Purpose bound consent with tamper evident receipts.

Scans your site for cookies and trackers, captures purpose bound consent, and keeps tamper evident receipts alongside withdrawal logs.

  • Cookie scanner
  • Consent receipts
  • Withdrawal logs
  • Notices
04Live

Third Party Risk

Every processor touching personal data, tiered and watched.

Discovers the processors touching personal data, tiers them by risk, checks contract coverage and keeps watching after onboarding.

  • Vendor discovery
  • Risk tiering
  • Contract coverage
  • Monitoring
05Live

Continuous Monitoring

Posture and audit evidence, rebuilt every night.

Watches encryption, access and retention posture, flags anomalies against normal behaviour, and rebuilds the audit evidence pack nightly.

  • Anomaly detection
  • Posture dashboards
  • Evidence packs
  • Alerting
06Roadmap

AI Governance

Model auditing, bias testing and EU AI Act readiness.

Model registry, bias testing, explainability reporting and mapping against the EU AI Act.

  • Model registry
  • Bias testing
  • Explainability
  • AI Act mapping

How we connect

We read.
We never write.

What our access does and does not allow, in full.

Read only, always

SELECT statements. No INSERT, UPDATE or DELETE path exists.

Sampling capped

At most 100 rows per table, only to classify the data type.

Encrypted end to end

TLS 1.3 in transit, AES-256 at rest.

No credentials in code

Secrets held in a managed vault, scoped to least privilege.

No personal data in logs

Identifiers redacted at source.

Seven year audit trail

Every action against your systems is logged and kept.

Engagements

Three ways
to start.

01DPDPA ImplementationAssessment to live controls across your stack.2 to 6 weeksNothing formal in place
02DPO as a ServiceA certified officer who owns the programme and signs off.OngoingNo in-house DPO
03Audit and SDF ReadinessIndependent audit prep for Significant Data Fiduciaries.3 to 5 weeksSDF designated

Sector experience

BFSIHealthcareE-commerceManufacturingHR TechEdTech

How we work

Four phases.
No cliff edge at handover.

Most programmes end when the consultant leaves. Ours moves into an operating phase.

011 to 2 weeks

Assess

Gap assessment against the Act and Rules, with penalty exposure per gap.

022 to 6 weeks

Implement

Controls built into your stack. No rip and replace.

03Ongoing

Operate

A named DPO runs the programme and answers to the regulator.

04Continuous

Prove

Evidence regenerates itself, so an audit is a download.

What you get

Artefacts, not
a slide deck.

The records a Board inquiry asks for, kept current.

  • Records of Processing Activities
  • Privacy notices in 22 languages
  • Consent artefacts and withdrawal logs
  • Data principal rights portal
  • Retention and erasure schedule
  • Breach response plan and templates
  • Processor register
  • DPIAs for high risk processing
  • Audit evidence pack

What shapes an engagement

Scoped, not
priced off a list.

A call settles these in about thirty minutes.

01

Systems in scope

Databases, cloud stores and SaaS holding personal data.

02

Volume and sensitivity

Financial, health or children's data raises the bar.

03

SDF status

Adds a DPO, DPIAs and independent audit.

04

Cross-border processing

Transfers and overlapping frameworks such as GDPR.

05

What you already have

Existing controls reduce the work.

06

In-house capacity

How much your team wants to own.

Next step

Thirty minutes to know
what this takes.

A scoping call with a certified DPO. You leave with your obligations, your gaps and a timeline.

Named DPORead only accessIndian data residencyNo obligation