An append-only ledger for every consent decision.
Every decision becomes a signed receipt, bound to a hash of the notice the visitor saw and sealed into periodic Merkle root checkpoints. The result is audit-ready, tamper-evident proof of consent.
What is a consent ledger?
A consent ledger is an append-only record of every consent given, changed or withdrawn. In ConsentPlix, each entry is cryptographically signed and committed to a Merkle tree, so you can show a regulator or auditor exactly what a person agreed to, when, and under which notice, and prove the record has not been altered since.
Four properties every receipt carries.
HMAC-SHA256 signatures
Each consent receipt is signed with keys held in a managed key service, so any later edit to a record breaks its signature and is detectable.
Notice hashing
The exact notice text and purposes shown to the visitor are hashed into the receipt, proving which version of the notice a person agreed to.
Merkle root checkpoints
Receipt hashes are grouped into Merkle trees and sealed at periodic checkpoints, so a single root commits to every record before it.
Pseudonymous by design
The ledger stores pseudonymous consent records only, with no names or emails, hosted by default in AWS Mumbai.
From a click to verifiable evidence.
- 01
Decision captured
Widget or SDKA visitor accepts, rejects or customises purposes. The widget records the choice, a pseudonymous subject ID and a hash of the notice shown.
- 02
Receipt signed
HMAC-SHA256The record is signed and appended to the ledger. Existing entries are never updated in place; a withdrawal is a new entry.
- 03
Checkpoint sealed
Merkle rootRecent receipt hashes are rolled into a Merkle tree and its root is sealed, linking every record to a tamper-evident checkpoint.
- 04
Proof exported
Audit bundleFor any subject or date range, export receipts with their inclusion proofs so an auditor can verify them independently.
Common ledger questions.
- Can a consent record be edited or deleted after it is written?
- No record is edited in place. Changes such as a withdrawal are appended as new entries, and any tampering with a stored entry breaks its signature and Merkle inclusion proof.
- Does the ledger store personal data?
- It stores pseudonymous consent records: a subject identifier, purposes, timestamps and notice hashes. Names, emails and other direct identifiers are not required.
- Which regulations is the ledger designed to support?
- It provides evidence of consent for India DPDP, EU GDPR and UK GDPR, CCPA/CPRA, LGPD, PDPA and PIPEDA programmes. Your legal team decides how that evidence is used.
- How does an auditor verify a receipt?
- Each exported receipt includes its signature and Merkle inclusion proof. The receipt verifier recomputes the path to the sealed root, so verification does not depend on trusting our dashboard.
Works with the rest of ConsentPlix.
See sealed receipts generated on your own site.
The cryptographic ledger is included on every plan, from Starter at ₹399 per month. Book a 30-minute technical walkthrough to inspect proofs in action.