NewFree DPDP audit for Indian SaaS founders — 10 questions, ~3 minutes, instant gap report

Sanad · Compliance infrastructure for India

Hardware-anchored compliance evidence for India’s regulated public and private sectors.

सनद — हर अनुपालन का प्रमाणिक रिकॉर्ड।

DPDP 2025 and CERT-In evidence on a single platform. Ed25519 signatures rooted in TPM 2.0, per-tenant SHA-256 hash chain — verifiable offline by any auditor without trust in our servers. Indian-domiciled, Indian-patented, Indian-funded.

What’s inside

Every DPDP and CERT-In obligation, with the evidence already signed.

DPDP §6 · §7

Consent receipts

Granular purpose-bound consent capture with revocation, audit trail, and per-tenant Ed25519 signature on every receipt.

DPDP §11–§14

Rights workflows

Access, correction, erasure and grievance flows wired to your DPO inbox. SLA-tracked, evidence-stamped.

DPDP §8(6) · CERT-In Dir. 12

Incident & breach

6-hour CERT-In window and 72-hour DPB notification playbook with one-click filing, log preservation and chain-of-custody.

DPDP §10 · §11

DPIA · RoPA · Vendor DPAs

Sector-specific DPIA templates, processing register, and signed Data Processing Agreements with every sub-processor.

CERT-In Dir. 1–17

Sentinel monitoring

TPM-anchored Windows agent. Continuous evidence collection for 7 automated CERT-In directives (logs, clock, patches, encryption, inventory, prohibited software, EDR posture).

Public API

Verify

Cryptographically signed compliance state for any tenant. Insurers, lenders, district administrations and auditors can verify offline without trusting our servers.

Read more →

How Sanad works

Collect → sign → chain → any auditor verifies.

01

Collect from the source

Sentinel agent and in-app workflows capture DPDP & CERT-In evidence at the point of action — no manual log copy-pasting.

02

Sign & chain

Per-tenant Ed25519 signs every event. BEFORE-INSERT trigger writes it into a SHA-256 hash chain. Any auditor can replay from genesis and detect a single bit of tampering.

03

Verify offline

Auditors, insurers, district administrations verify with three open-source SDKs — no account, no API call, no trust in our servers.

Built on

The infrastructure your auditor will recognise.

Sanad is built by COGNOSHIFT PRIVATE LIMITED — a DPIIT-recognised Haryana-domiciled startup with four provisional patents in regulatory compliance technology. Every byte of customer data, signing key, and audit log sits in India.

4
Provisional patents · DPDP & CERT-In compliance tech · 2 filed Apr 2026
100%
India-hosted · Supabase ap-south-1 · Vercel edge · Razorpay
TPM 2.0
Hardware-anchored Sentinel · Ed25519 + EV code signing
SHA-256
Per-tenant hash chain · independently replayable offline
CIN: U85499HR2025PTC130446
GSTIN: 06AAMCC6054B1ZW
DPIIT Recognised Startup
Govt of Haryana Cat-1 Funded

Next step

Ready for an audit-ready compliance rail under your name?

Pick the door that fits — state administration, SaaS, or sub-tenant — and we’ll route you to the right onboarding flow.