CRYPTOGRAPHIC AUDIT VAULT · CONSENT LEDGER

An append-only ledger for every consent decision.

Every decision becomes a signed receipt, bound to a hash of the notice the visitor saw and sealed into periodic Merkle root checkpoints. The result is audit-ready, tamper-evident proof of consent.

Definition

What is a consent ledger?

A consent ledger is an append-only record of every consent given, changed or withdrawn. In ConsentPlix, each entry is cryptographically signed and committed to a Merkle tree, so you can show a regulator or auditor exactly what a person agreed to, when, and under which notice, and prove the record has not been altered since.

Integrity model

Four properties every receipt carries.

  • HMAC-SHA256 signatures

    Each consent receipt is signed with keys held in a managed key service, so any later edit to a record breaks its signature and is detectable.

  • Notice hashing

    The exact notice text and purposes shown to the visitor are hashed into the receipt, proving which version of the notice a person agreed to.

  • Merkle root checkpoints

    Receipt hashes are grouped into Merkle trees and sealed at periodic checkpoints, so a single root commits to every record before it.

  • Pseudonymous by design

    The ledger stores pseudonymous consent records only, with no names or emails, hosted by default in AWS Mumbai.

How it works

From a click to verifiable evidence.

  1. 01

    Decision captured

    Widget or SDK

    A visitor accepts, rejects or customises purposes. The widget records the choice, a pseudonymous subject ID and a hash of the notice shown.

  2. 02

    Receipt signed

    HMAC-SHA256

    The record is signed and appended to the ledger. Existing entries are never updated in place; a withdrawal is a new entry.

  3. 03

    Checkpoint sealed

    Merkle root

    Recent receipt hashes are rolled into a Merkle tree and its root is sealed, linking every record to a tamper-evident checkpoint.

  4. 04

    Proof exported

    Audit bundle

    For any subject or date range, export receipts with their inclusion proofs so an auditor can verify them independently.

FAQ

Common ledger questions.

Can a consent record be edited or deleted after it is written?
No record is edited in place. Changes such as a withdrawal are appended as new entries, and any tampering with a stored entry breaks its signature and Merkle inclusion proof.
Does the ledger store personal data?
It stores pseudonymous consent records: a subject identifier, purposes, timestamps and notice hashes. Names, emails and other direct identifiers are not required.
Which regulations is the ledger designed to support?
It provides evidence of consent for India DPDP, EU GDPR and UK GDPR, CCPA/CPRA, LGPD, PDPA and PIPEDA programmes. Your legal team decides how that evidence is used.
How does an auditor verify a receipt?
Each exported receipt includes its signature and Merkle inclusion proof. The receipt verifier recomputes the path to the sealed root, so verification does not depend on trusting our dashboard.
Related

Works with the rest of ConsentPlix.

AUDIT-READY FROM DAY ONE

See sealed receipts generated on your own site.

The cryptographic ledger is included on every plan, from Starter at ₹399 per month. Book a 30-minute technical walkthrough to inspect proofs in action.