Security · data handling
Security and data handling. The honest version.
No badges, no implied certifications. Every sentence on this page is something we do today.
Last reviewed 16 July 2026
Protection
How we protect your data.
Encryption
Data is encrypted in transit over TLS, and at rest with AES-256.
Residency
Your data stays in India. We run in a single India region and do not replicate outside it.
The DPDP Rules don't require this. They use a negative-list model: personal data may be transferred abroad unless the Central Government restricts the destination. We keep it in India anyway.
Access
Access to customer decision records is restricted to named engineers on the Consentry team. Access is granted per-person, not per-role, and is revoked when it is no longer needed for a specific operational task.
Every access to a customer's decision records is itself logged. We hold ourselves to the record-keeping standard we sell. We do not read customer data for product development, analytics, or model training.
Retention
What we keep for seven years, and what we don't.
Kept for seven years
The decision record: what was permitted, for what purpose, when, and which systems obeyed it. The DPDP Rules require one. Proof that expires isn't proof.
Not kept
The personal data the decision governed. When consent is withdrawn and the purpose is served, that data is erased on the schedule the Act requires.
The record of the decision survives; the data it permitted does not.
Subprocessors
Every vendor that can see data.
Under the DPDP Act, liability sits with the Data Fiduciary even when a processor does the handling, so here is every vendor that can see personal data or decision records.
| Vendor | Purpose | Data touched | Location |
|---|---|---|---|
| Amazon Web Services (ap-south-1, ap-south-2) | Cloud infrastructure and India-region hosting | Application data, decision records, logs | India (Mumbai, Hyderabad) |
| Managed PostgreSQL (AWS RDS) | Primary datastore for decision records | Decision records, account metadata | India (Mumbai) |
| Zoho CRM | Request-access CRM and early-access pipeline | Name, work email, company, role, systems described | India |
| Amazon SES | Operational and access-request email | Name, work email | India (Mumbai) |
| Amazon CloudWatch | Application error monitoring and operational logs | Technical logs; may include request metadata | India (Mumbai) |
Honest boundaries
What we say plainly.
SOC 2 Type II · Target April 2027
SOC 2 Type II audit targeted for April 2027. We are not certified today.
- Not a registered Consent Manager.
- No customer data sold or shared for advertising.
- No training on customer data.
See it on your stack
Security posture is one layer. The decision record is the product.