DPDP-native data vault
आत्म कोश

Your data, sealed under your own key.

Atma Kosha is a self-sovereign vault for your personal data — encrypted so only you can open it, and shared with a business only on consent you can revoke at any moment.

Passkey secured· DID anchored· AES-256 atoms· Post-quantum ready· DPB-inspectable
Atma Kosha
Built for the DPDP Act, 2023 FIDO2 passkeys AES-256 · Ed25519 Crypto-agile · PQC ready Tamper-evident audit chain
The idea

Today your data lives in a hundred vaults — none of them yours. Atma Kosha gives you one that is.

Every form you fill, every check-in, every KYC leaves a copy of you on someone else's server. Atma Kosha inverts that: your details are sealed into encrypted atoms in a vault anchored to an identity you control. Businesses don't get a copy — they get consent, scoped and revocable, and nothing more.

How it works

Four turns of the wheel

From sealing your first atom to proving an erasure — the whole lifecycle stays in your hands.

How it works, step by step →
01

Seal

Your details become encrypted atoms, locked with a key derived from your passkey. No password to phish, nothing we can read.

02

Hold

Your vault is anchored to a DID you own — not an account we own. Change devices, keep your vault. Lose a phone, not your identity.

03

Grant

Share exactly what a business needs, for exactly as long as it needs it. The wheel of guards refuses anything unlawful, sensitive, or unconsented.

04

Prove

Every grant, revocation, and erasure is written to a tamper-evident chain — provable to you, and to the Data Protection Board.

The chakra of guards

A wheel of guards, always turning

Consent isn't a checkbox — it's a policy engine. Each request to your data passes the ring before anything moves.

Explicit for sensitive

Special-category data can only be shared on clear, explicit consent — never bundled.

Children protected

No tracking, profiling, or targeted use of a minor's data. Ever.

Border-aware

Cross-jurisdiction transfers are checked against where the data may lawfully go.

Purpose-bound

Data is usable only for the purpose you allowed — nothing repurposed in the dark.

Retention floors

Nothing is kept past its lawful life; expiries are enforced, not suggested.

Erasure with proof

Withdraw and the cascade sweeps every copy — and hands you the receipt.

Two sides, one vault

Sovereignty for people. Compliance for business.

Atma Kosha for business →
For you
व्यक्ति · the data principal

One vault for the whole of you

  • Hold everything in one place — identity, documents, history, sealed and searchable only by you.
  • Grant and revoke in a tap. See exactly who holds what, and pull it back anytime.
  • Take it with you. Portability and erasure are one action, not a support ticket.
For business
संस्था · the data fiduciary

DPDP compliance, in days not quarters

  • Data-blind by design. Hold consent, not raw PII you were never meant to keep.
  • Audit-ready. A hash-chained ledger and a one-call DPB inspection endpoint.
  • Drop it in. Sector packs, an SDK, a hosted portal, or a pure API — your choice.
Security & trust

Sovereign by architecture, not by promise

The design is the guarantee: even we can't read your vault, and the law we're built for requires exactly that.

The full security model →

Passkey possession

Your key is derived from a FIDO2 passkey bound to your device — there's no shared secret to leak.

DID-anchored

A decentralised identifier you control roots the vault — portable across devices, owned by no one but you.

Encrypted atoms

Every field is sealed individually with AES-256-GCM and signed with Ed25519 — sealed bytes, never plaintext.

Crypto-agile

A migration ladder lets the whole vault re-key to post-quantum algorithms without re-sealing your life.

Tamper-evident chain

Consent events hash-link into a chain; break one link and the very next verify names the position.

Inspectable, not exposed

Regulators get a signed inspection view; your actual data stays sealed. Transparency without a peephole.

The DPDP Act, 2023

Every right, as a first-class action

Not bolted on — the vault is shaped around what the Act gives every Data Principal.

Your rights in detail →
Access §11 Correction §12 Completion §12 Erasure §12 Portability Grievance §13 Nomination §14 Withdraw consent §6(4)
Questions

Straight answers

Can Atma Kosha read my data?

No. Each atom is encrypted under a key only your passkey can derive — we hold sealed bytes and pointers, never plaintext. As a data-blind consent manager, being unable to read your data is both our architecture and, under the DPDP Rules, our legal obligation.

What happens if I lose my device?

Your vault is anchored to a DID, not a single phone. Re-enrol a passkey on a new device to regain access; an email-gated recovery path adds a second, possession-checked route. Losing hardware doesn't lose the vault.

Where does my data actually live?

Sealed blobs sit in object storage you can pin to your own region; only authentication and concurrency metadata — plus a pointer — live in the database. The ciphertext and the key never share a home.

Is this a wallet, or a bank?

A vault for data, not money. Think of the key like a bank-vault key — except no one, not even us, holds a copy. You grant access; you never hand over the original.

How does a business adopt it?

Pick a surface: a drop-in SDK for your app, a hosted consent portal, or the pure API. Sector packs bring purposes, notices, and retention floors for your industry; the audit chain and DPB inspection come switched on.

आत्म कोश

Hold your own key.

Join the early-access list and be among the first to seal a vault only you can open.

Early access · no spam · your address is only used to invite you.

Bringing Atma Kosha to your organisation? Talk to us →