SECURITY & DATA RESIDENCY

Consent records only. Resident in India.

ConsentPlix is engineered with a strict zero-customer-data policy. We store cryptographically sealed consent audit receipts in ap-south-1 (AWS Mumbai), ensuring complete sovereign data residency compliance.

DATA RESIDENCY
AWS ap-south-1 Mumbai

All consent telemetry, receipts, and hashes stay resident within Indian borders by default, meeting DPDP Act Section 8 compliance standards.

DATA MINIMIZATION
Zero Customer PII Stored

We never collect or retain customer names, emails, phone numbers, or passwords. Your customer data stays inside your own database.

AVAILABILITY SLA
99.99% Uptime Guarantee

Sub-12KB embed SDK served across 300+ global Anycast edge locations with zero latency impact on Google Core Web Vitals.

SYSTEM ARCHITECTURE

Sovereign, immutable cloud infrastructure.

Engineered from bare metal up to isolate consent compliance signals from identity storage.

EDGE INGESTION

Cloudflare Global Anycast Edge

Sub-12KB autonomous SDK served via 300+ point-of-presence global CDN edge locations. Resolves visitor jurisdiction in under 2ms without cross-border routing penalties.

Sub-15ms p99 Worldwide · Brotli Compressed
SOVEREIGN HOSTING

AWS Mumbai (ap-south-1) Primary Compute

All consent receipts, ledger hashes, and verification endpoints run in isolated multi-AZ clusters within India by default, strictly satisfying DPDP Act data residency standards.

Multi-AZ Redundancy · ISO 27001 Certified Tier-4 Datacenter
IMMUTABLE VAULT

Append-Only PostgreSQL with KMS HSMS

Database row-level security policies strictly prohibit UPDATE or DELETE operations. Cryptographic keys are anchored in hardware security modules (FIPS 140-2 Level 3).

HMAC-SHA256 Signatures · Hourly Merkle Checkpoints
PII-FREE SYNC

Real-Time Signed Webhook Stream

Webhooks deliver cryptographically signed consent states directly into your private data lake (Snowflake, BigQuery, Postgres), keeping all business intelligence in your own custody.

Ed25519 Webhook Signatures · 99.99% Guaranteed Delivery
EXPLICIT DATA BOUNDARY

Data minimization matrix.

We explicitly isolate consent state from customer personal identity. Your users’ PII never touches the ConsentPlix ledger.

What We Store (Consent Audit Only)

  • Pseudonymous Subject Token
    Anonymous cookie token (e.g. sub_8f9c2a...) isolated from identity.
  • Hashed & Salted IP Fingerprint
    Raw IP address is truncated, salted, and SHA-256 hashed at the edge; raw IP is immediately discarded from memory.
  • Canonical Purpose Matrix
    Itemized boolean consent grants (e.g. ad_storage: false, analytics: true).
  • Policy Hash & Timestamp
    Exact SHA-256 digest of the statutory notice rendered in visitor language.
  • HMAC-SHA256 Audit Signature
    Mathematical verification payload committing to the 11 canonical fields.

What We NEVER Store

  • Raw IP Addresses
    Never stored on disk, never passed to downstream logs, and never logged in analytics.
  • Names, Emails, or Phone Numbers
    Zero customer identity data is required to prove statutory consent validity.
  • Passwords, Tokens, or Credentials
    No customer session passwords or user authentication tokens are ever ingested.
  • Form Entries & Payment Data
    Checkout entries, shopping carts, credit cards, and form inputs never touch our SDK.
  • Browsing History or Cross-Site Profiles
    No behavioral ad trackers, fingerprinting pixels, or multi-site tracking graphs.
VERIFIABLE GUARANTEES

Cryptographic security & compliance controls.

Encryption at Rest
AES-256-GCM via AWS KMS HSMs
Encryption in Transit
TLS 1.3 Strict with HSTS & Forward Secrecy
Database Immutability
PostgreSQL strict append-only tables (Revoked UPDATE/DELETE)
Default Cloud Region
AWS Asia Pacific Mumbai (ap-south-1)
SLA Availability Warranty
99.99% monthly availability for SDK CDN & Ingestion
Audit Admissibility
Merkle inclusion proofs valid under Indian Evidence Act §65B
SOVEREIGN SECURITY AUDIT

Evaluate our security architecture on your own domains.

Book a 30-minute infrastructure walkthrough with a privacy engineer to inspect keys, CloudHSMs, and Mumbai residency controls.