Platform
Personal data detection, risk scoring, and auditable proof — built for Indian DPDP.
ztrust connects to your actual systems, scans for personal data automatically, scores your DPDP exposure against five risk categories, and generates a Proof Pack your investors and enterprise customers can verify. No consulting project. No questionnaires.
How it works
Four steps. First result in under 10 minutes.
If you connect a source and don't find personal data risk in under 10 minutes, you don't need us.
Connect a source
Connect your database, cloud storage, or file upload. ztrust reads schema metadata only — column names, table names, row counts. Never actual personal data values.
Scan detects personal data fields
The engine detects Aadhaar numbers, PAN cards, bank account fields, health data, email addresses, and children's data across your connected sources. India-specific field types included.
Risk findings surface automatically
Each finding maps to a DPDP rule: data exposure, consent gaps, rights readiness, breach blast radius, access risk, third-party processor gaps. Severity scored. Detection basis shown.
Export your Proof Pack
One button. Structured export with posture summary, inventory, risk register, evidence timeline, and priority actions. Ready for investor due diligence, enterprise procurement, or board review.
Platform
Everything in one automated loop.
Detection, scoring, evidence, and export. The Proof Pack is the flagship output. Every other feature exists to make that output credible and continuously current.
Proof Pack
Structured export with inventory, risks, evidence, and actions. Answers 80% of security questionnaire data protection questions in a format procurement teams can verify.
Evidence Timeline
Every scan, finding, and resolved action is timestamped automatically. 30, 90, 180 days of continuous evidence — always current, never assembled after the fact.
Dark Source Detection
Flags known Indian SaaS apps in your stack that hold personal data but aren't yet connected — Keka, Razorpay, Freshdesk, Zoho. Your inventory reflects reality, not just what's convenient to scan.
Role-aware Views
Founders see posture status and the Proof Pack trigger. Ops leads see the action queue and source health. One product, two workflows — no customisation required.
Access Risk
Detects internal actors with excessive access to sensitive personal data — database roles, service accounts, file owners. DPDP insider risk, not just external threats.
Incident Readiness
Pre-built inventory and evidence means your 6-hour CERT-In and 72-hour DPDP breach notification windows are achievable. Response is a process, not a panic.
Use cases
Three moments that drive the decision to start.
Enterprise procurement questionnaire
The deal closes.
B2B enterprise procurement teams send 150-300 question security questionnaires with 3-4 week timelines. A Proof Pack with 90 days of evidence answers the data protection section before your competitors have started assembling screenshots.
Investor due diligence
The question is answered before it's asked.
Post-DPDP, data risk is a standard due diligence category alongside financial and operational risk. A company with a Proof Pack demonstrates it has thought about this. A company without one raises flags at Series A and above.
Regulatory inquiry
You have evidence, not assertions.
The Data Protection Board can initiate investigations suo motu. A timestamped evidence programme running continuously before the inquiry is materially harder to challenge than documentation assembled after the fact.
Clarity
ztrust is a detection engine. Not these.
Prospects sometimes arrive with a mental model from another product category. Here is what ztrust is not — and why that distinction matters.
Consent management platform
OneTrust, Cookiepro
DSAR / data request portal
DataGrail, Transcend
GRC / compliance framework tool
Vanta, Drata
Breach management system
Cybereason, Resilience
ROPA / processing records tool
TrustArc
ztrust is a detection engine
Detect, score, and prove. Not execute.
Why the boundary matters: ztrust must never become the system that processes the personal data it audits. It reads metadata — column names, row counts, field type signatures. It never reads actual Aadhaar numbers, names, or transaction values. That is what makes its evidence defensible and what keeps your org from adding a new personal data processor to your own supply chain.
Principles
Three things that make evidence defensible.
Continuous, not periodic
Evidence generated automatically as a byproduct of normal operations is orders of magnitude more credible than documentation assembled before an audit.
Inventory before claims
You cannot protect data you haven't located. You cannot fulfill a rights request for data you can't find. The inventory is the foundation — everything else depends on it.
Actions with owners
Findings that don't turn into actions don't improve posture. Every critical and high finding generates a prioritised task. Every resolved task updates the evidence trail.