From sealing your first atom to proving an erasure, the whole lifecycle of your data stays in your hands — not on someone else’s server.
Each detail — a name, an ID number, a document — is encrypted into its own atom with a key derived from your passkey. There’s no password to phish, and nothing we can read.
Your atoms live in a vault anchored to a DID you control — not an account we own. Move devices and keep your vault; lose a phone and you never lose your identity.
Share exactly what a business needs, for exactly as long as it needs it. The wheel of guards refuses anything unlawful, sensitive, or unconsented before it moves.
Every grant, revocation and erasure is written to a tamper-evident chain — provable to you, and to the Data Protection Board, without exposing the data itself.
Aarav checks into a hotel. At the desk, instead of photocopying his Aadhaar, the tablet asks his vault for exactly two things: proof of identity and a payment mandate, each for the length of his stay.
He approves both with a tap of his passkey. The hotel receives a verifiable grant — a signed token that says “identity confirmed, payment authorised, until checkout” — not a copy of his passport. When he declines marketing, that guard simply never opens.
At checkout the identity grant expires on its own. The hotel kept a receipt it can show an inspector; it never kept Aarav.
The most common data breach is a filing cabinet of ID photocopies no one needed to keep. Atma Kosha replaces the copy with a grant — so there is nothing to leak.
The vault is shaped around what the Act gives every Data Principal — not bolted on after.
Withdraw consent and the cascade sweeps every downstream copy under that grant — then hands you a signed proof of erasure. Where a lawful retention floor applies (a tax record, a regulator’s mandate), the vault tells you exactly what must wait and for how long.