Settings
Organisation profile, people, modules and the integrations that feed them.
Core
Compliance register, processing register, risk register, evidence vault, audit trail and reporting. Always on — every other module writes into it.
Access, correction, erasure, nomination and grievance handling with the statutory clocks. Paired with the public Data Principal portal.
Service lines
The eleven service lines. Codes match the procurement line items so a buyer can map the product onto a rate contract without a translation table.
Map data flows, test every processing activity against the Act, and produce a risk-rated gap register with a remediation roadmap.
A named DPO, an advisory queue with response SLAs, regulatory monitoring, and the monthly reporting the role is expected to produce.
Granular, purpose-bound consent with multilingual notices, one-click withdrawal, an immutable artefact trail, and Consent Manager interoperability.
Find personal data everywhere it lives, classify it, bind it to consent and purpose, and drive retention and erasure from that binding.
Watch every identity that touches personal data, baseline normal behaviour, and cut off access when it deviates.
Role-based bilingual curriculum, phishing simulation, certification, and department-level completion evidence.
Round-the-clock intake, a war-room with the statutory clocks running, and both Board and Data Principal notifications drafted from real impact data.
Classification-driven enforcement across email, endpoint, cloud, web, API and database — the last-mile control when everything else fails.
Inspect prompts and outputs across every AI system, including shadow AI, and enforce consent and purpose at the model boundary.
Full session context on every query against a personal-data table, with tamper-resistant audit and mass-read detection.