Skip to content

Security · data handling

Security and data handling. The honest version.

No badges, no implied certifications. Every sentence on this page is something we do today.

Last reviewed 16 July 2026

Protection

How we protect your data.

Encryption

Data is encrypted in transit over TLS, and at rest with AES-256.

Residency

Your data stays in India. We run in a single India region and do not replicate outside it.

The DPDP Rules don't require this. They use a negative-list model: personal data may be transferred abroad unless the Central Government restricts the destination. We keep it in India anyway.

How Consentry maps to the DPDP Act

Access

Access to customer decision records is restricted to named engineers on the Consentry team. Access is granted per-person, not per-role, and is revoked when it is no longer needed for a specific operational task.

Every access to a customer's decision records is itself logged. We hold ourselves to the record-keeping standard we sell. We do not read customer data for product development, analytics, or model training.

Retention

What we keep for seven years, and what we don't.

Kept for seven years

The decision record: what was permitted, for what purpose, when, and which systems obeyed it. The DPDP Rules require one. Proof that expires isn't proof.

Not kept

The personal data the decision governed. When consent is withdrawn and the purpose is served, that data is erased on the schedule the Act requires.

The record of the decision survives; the data it permitted does not.

Subprocessors

Every vendor that can see data.

Under the DPDP Act, liability sits with the Data Fiduciary even when a processor does the handling, so here is every vendor that can see personal data or decision records.

Subprocessors
VendorPurposeData touchedLocation
Amazon Web Services (ap-south-1, ap-south-2)Cloud infrastructure and India-region hostingApplication data, decision records, logsIndia (Mumbai, Hyderabad)
Managed PostgreSQL (AWS RDS)Primary datastore for decision recordsDecision records, account metadataIndia (Mumbai)
Zoho CRMRequest-access CRM and early-access pipelineName, work email, company, role, systems describedIndia
Amazon SESOperational and access-request emailName, work emailIndia (Mumbai)
Amazon CloudWatchApplication error monitoring and operational logsTechnical logs; may include request metadataIndia (Mumbai)
How we handle personal data ourselves →

Honest boundaries

What we say plainly.

SOC 2 Type II · Target April 2027

SOC 2 Type II audit targeted for April 2027. We are not certified today.

  • Not a registered Consent Manager.
  • No customer data sold or shared for advertising.
  • No training on customer data.

See it on your stack

Security posture is one layer. The decision record is the product.