Product

The Proof Pack: Your Data Protection Evidence

Jan 25, 20266 min read

When auditors, investors, or customers ask about data protection, can you prove it in 10 minutes or 10 weeks?

Three situations trigger the question every founder dreads: an enterprise customer sends a 200-question security questionnaire, an investor asks for a data protection overview during due diligence, or a regulator requests evidence that personal data is being handled appropriately. In all three cases, the difference between a 15-minute response and a three-week scramble is whether you built your evidence before the question was asked.

What a Proof Pack is

A Proof Pack is not a compliance certificate. It is not a dashboard screenshot. It is a structured, externally presentable document that answers the core question an auditor, investor, or customer is actually asking: "Can you show me what personal data you hold, what the risks are, and what evidence you have that you are managing those risks?"

The answer requires four things: a current inventory of personal data sources and fields, a risk register showing open findings by severity, an evidence timeline showing recent verification and scan activity, and a posture summary that contextualises everything for a non-technical reader.

The three moments that demand it

  • Enterprise procurement: B2B SaaS companies trying to close deals with large enterprises routinely face security questionnaires with 150-300 questions, 3-4 week response timelines, and requirements for specific documentation. Most questionnaires include a dedicated data protection section. A Proof Pack answers 80% of those questions in a format procurement teams can verify.
  • Investor due diligence: Post-DPDP, data risk has become a standard due diligence category alongside financial and operational risk. Series A and above investors are specifically asking about personal data exposure, breach notification capability, and evidence of a functioning compliance programme. A company with a Proof Pack demonstrates it has thought about this — a company without one raises red flags.
  • Regulatory response: If the Data Protection Board initiates an inquiry — either on complaint or suo motu — the first thing they will request is evidence that reasonable security safeguards were in place. A Proof Pack that was generated regularly before any inquiry provides a timestamped record that is materially harder to challenge than documentation assembled after the fact.

What it contains

  • Executive summary: Overall posture status (Defensible / At Risk / Improving), source count, fields inventoried, open risks by severity. Readable by a board member in 90 seconds.
  • Data inventory: Which systems are connected, what personal data fields are detected, how many records, and what subject categories (employee, customer, vendor) are covered.
  • Risk findings: Open findings by category — data risk, consent gaps, access risk, breach readiness, DPR readiness — with severity, detection basis, and recommended action.
  • Evidence timeline: The last 30 days of scan events, verification activities, and control checks — each with a timestamp. This is what proves the programme is running, not just documented.
  • Coverage gaps: What is not yet connected, what is stale, what is based on inference rather than direct detection. Transparency about gaps is a mark of a mature programme, not a weakness.

Why the timing matters

A Proof Pack generated before anyone asks for it is qualitatively different from documentation assembled in response to a request. The evidence timeline contains dates. If your first scan was run two weeks ago in response to an investor question, the timeline shows it. If you have been running scans for six months, the timeline shows that too.

The evidentiary value of a continuous programme — one that generates records as a byproduct of normal operations — is orders of magnitude higher than a point-in-time assessment. This is the same principle that makes continuous monitoring more valuable than annual penetration tests.

Enterprise security questionnaires typically ask for evidence that controls have been operational for at least 6 months. A company that starts its evidence programme 3 weeks before a deal closes will fail that question regardless of how good its controls actually are.

The market shift making Proof Packs standard

The Indian enterprise market is maturing rapidly. Large Indian conglomerates, multinationals operating in India, and government entities are all tightening their vendor risk management requirements. The question used to be 'do you have a privacy policy?'. It is increasingly 'show me your data inventory and your last 90 days of evidence'.

Foreign companies expanding to India — particularly those from the EU and the US that are already operating under GDPR or CCPA — are applying their home-market standards to their Indian vendor assessments. Indian startups selling to these companies are being held to international evidence standards, not just DPDP minimum requirements.

Takeaway

The Proof Pack is your data protection evidence on demand. It is not a one-time document — it is a continuously updated artefact that grows more valuable with every scan, every verified control, every resolved finding. The best time to generate your first one is before anyone asks for it.