Architecture & trust
Enterprise-grade. India-first.
Data and AI inference run in India, in line with DPDP §16.
In India
In India, by design.
Data and AI inference run in India, in line with DPDP §16.
- Database-level tenant isolation, fail-closed
- MFA, 15-minute access tokens, HSM-backed keys at rest
- TLS enforced at boot; secrets in a vault
- CI gated on types, coverage & CVE scans
Defensibility
Built to be provable.
Tamper-evident audit log
Hash-chained and append-only, enforced in the database.
Evidence snapshots
A dated, captured bundle of the evidence behind your posture.
Human-in-the-loop trail
The AI's verdict, recorded before the override.
Integrity-checked exports
Every export ships with a hashed manifest of its contents.
Dated bundles of this project's questionnaires, report summary and company documents.
- ViewPre-audit — Q3 2026 Report
Sep 4, 2026, 3:21 PM · by R. Mehta
3 questionnaires 24 documents - ViewBoard review Report
Aug 21, 2026, 11:04 AM · by R. Mehta
3 questionnaires 21 documents - ViewSnapshot
Aug 2, 2026, 6:47 PM · by A. Nair
2 questionnaires 18 documents
Recreated from the product interface
Measured, not claimed
Quality you can hold to account.
Benchmarked, not asserted.
Every release is scored against a fixed golden-set benchmark before it ships — and the prompt that runs in the evaluation is the prompt that runs in production.
- Citations checked against the statute corpus
- Inference pinned to an India region in our deployment (§16)
- Aadhaar and PAN redacted from model prompts
- Prompt-injection and hallucination guardrails on model calls
Why the approach is better
Not just AI — trustworthy AI.
Grounded, not generative
Cited provisions are checked against the statute corpus, and uncertain answers abstain rather than guess.
Hybrid, not black-box
Deterministic rules, retrieval and an LLM cross-check one another.
Self-calibrating
The confidence router learns from every lawyer decision.
India-native
Data residency and Indian-PII handling built into the core.
On our roadmap — not yet held.
SOC 2, ISO 27001, and a third-party pentest. These are planned certifications and an independent security test — not attestations we hold today. We're hardening for them now and will publish each as it's completed.
See Radicept on your own documents.
A guided demo on a real DPDP assessment — from intake to a regulator-ready report.