Consent records only. Resident in India.
ConsentPlix is engineered with a strict zero-customer-data policy. We store cryptographically sealed consent audit receipts in ap-south-1 (AWS Mumbai), ensuring complete sovereign data residency compliance.
All consent telemetry, receipts, and hashes stay resident within Indian borders by default, meeting DPDP Act Section 8 compliance standards.
We never collect or retain customer names, emails, phone numbers, or passwords. Your customer data stays inside your own database.
Sub-12KB embed SDK served across 300+ global Anycast edge locations with zero latency impact on Google Core Web Vitals.
Sovereign, immutable cloud infrastructure.
Engineered from bare metal up to isolate consent compliance signals from identity storage.
Cloudflare Global Anycast Edge
Sub-12KB autonomous SDK served via 300+ point-of-presence global CDN edge locations. Resolves visitor jurisdiction in under 2ms without cross-border routing penalties.
AWS Mumbai (ap-south-1) Primary Compute
All consent receipts, ledger hashes, and verification endpoints run in isolated multi-AZ clusters within India by default, strictly satisfying DPDP Act data residency standards.
Append-Only PostgreSQL with KMS HSMS
Database row-level security policies strictly prohibit UPDATE or DELETE operations. Cryptographic keys are anchored in hardware security modules (FIPS 140-2 Level 3).
Real-Time Signed Webhook Stream
Webhooks deliver cryptographically signed consent states directly into your private data lake (Snowflake, BigQuery, Postgres), keeping all business intelligence in your own custody.
Data minimization matrix.
We explicitly isolate consent state from customer personal identity. Your users’ PII never touches the ConsentPlix ledger.
What We Store (Consent Audit Only)
- Pseudonymous Subject TokenAnonymous cookie token (e.g. sub_8f9c2a...) isolated from identity.
- Hashed & Salted IP FingerprintRaw IP address is truncated, salted, and SHA-256 hashed at the edge; raw IP is immediately discarded from memory.
- Canonical Purpose MatrixItemized boolean consent grants (e.g. ad_storage: false, analytics: true).
- Policy Hash & TimestampExact SHA-256 digest of the statutory notice rendered in visitor language.
- HMAC-SHA256 Audit SignatureMathematical verification payload committing to the 11 canonical fields.
What We NEVER Store
- Raw IP AddressesNever stored on disk, never passed to downstream logs, and never logged in analytics.
- Names, Emails, or Phone NumbersZero customer identity data is required to prove statutory consent validity.
- Passwords, Tokens, or CredentialsNo customer session passwords or user authentication tokens are ever ingested.
- Form Entries & Payment DataCheckout entries, shopping carts, credit cards, and form inputs never touch our SDK.
- Browsing History or Cross-Site ProfilesNo behavioral ad trackers, fingerprinting pixels, or multi-site tracking graphs.
Cryptographic security & compliance controls.
Evaluate our security architecture on your own domains.
Book a 30-minute infrastructure walkthrough with a privacy engineer to inspect keys, CloudHSMs, and Mumbai residency controls.