Consent
Purpose, notice, categories, receipt fields, and withdrawal path.
Public controls, routes, and roadmap status for consent-first verification. Legal, security, and certification claims stay scoped to current evidence.
Control map
PRAMAAN keeps public evidence, DSR, DPO, breach, accessibility, and legal routes visible without expanding claims beyond current proof.
Purpose, notice, categories, receipt fields, and withdrawal path.
Operating model for purpose, consent, rights, grievance, breach, and minors.
Public route for access, correction, erasure, grievance, nomination, and withdrawal.
Privacy escalation and DPO contact guidance.
Incident response and communication posture.
WCAG/IS 17802 targets, known limitations, and feedback channel.
Signature, expiry, revocation, and result-state explanation.
Current no-policy-bound posture and underwriting readiness.
Guardian consent, minimization, and child-data safeguards.
Technical brief for procurement and security review.
| Area | Status | Review note |
|---|---|---|
| DPDP operating model | Current | Purpose, notice, consent, DSR, grievance, breach, and under-18 routes are surfaced publicly. |
| Public DSR route | Current | Access, correction, erasure, grievance, nomination, and withdrawal guidance are linked from Trust Center. |
| Named DPO route | Current | Privacy and DPO contact path is public. Response commitments should be case-specific. |
| ISO 27001 | Roadmap | Roadmap / target only. Not a certification claim. |
| SOC 2 | Roadmap | Roadmap only. No SOC 2 attestation is claimed. |
| Cyber-insurance | Not bound | No cyber-insurance or per-verification fraud-cover policy is currently bound. |
Whitepaper, security disclosure, DPA, sub-processors, privacy, terms, changelog, and status routes are linked for business review.