The design is the guarantee: even we can’t read your vault — and the law we’re built for requires exactly that.
Your key is derived from a FIDO2 passkey bound to your device. No shared secret exists to leak, reuse, or phish.
A decentralised identifier (DID) you control roots the vault — portable across devices, owned by no one but you.
Every field is encrypted individually with AES-256-GCM and signed with Ed25519. Sealed bytes at rest, never plaintext.
A migration ladder lets the whole vault re-key to post-quantum algorithms — without asking you to re-seal your life.
Consent events hash-link into a chain. Break one link and the very next verification names the position of the break.
Regulators get a signed inspection view. Your actual data stays sealed — transparency without a peephole.
The decryption key never leaves your device. Data-blindness isn’t a policy we could change — it’s the architecture, and the DPDP Rules require it of a Consent Manager.
There is nothing to sell. A Consent Manager is not a data fiduciary; we hold consent, never your information.
Every access is a grant you made and can see. There is no side door — and the chain would show one if there were.
Portability and erasure are one action. Your DID and your atoms are yours to take.
Because your vault is anchored to a DID and not a single phone, recovery is possession-checked, not password-based: enrol a new passkey on a fresh device, with an email-gated second path that proves it’s you before anything unseals.
If a check can’t be satisfied, access stays closed. The default is always “no” until you say yes.