Blog

Notes from building Consent Tree.

What the DPDP Act actually requires, and what we found when we checked our own product against it first.

28 AUGUST 2026

A checklist that cites its sections, not vibes

Most "DPDP compliance checklists" are a lead-gen form wearing a listicle's clothes. This one names the actual section for every item — notice, consent, breach response, and data-principal rights — so you can go read the text instead of taking our word for it.

READ THE POST →
26 AUGUST 2026

Trust us less, not more

"We log everything" is not the same claim as "our logs can't be quietly edited after the fact." How the hash-chained, Ed25519-signed audit trail actually works, why it's not an audit opinion, and a live verifier you can check it against yourself.

READ THE POST →
26 AUGUST 2026

Three terms worth getting right

"Consent Manager," "Significant Data Fiduciary," and "Data Protection Board" get used loosely in a lot of DPDP explainers. The Act defines all three precisely — what each one actually means, with the section numbers, and where Consent Tree itself stands against each.

READ THE POST →