Why Data Fiduciaries pick us
Six things you get on day one.
DPDPA-native, not GDPR translated
Every workflow mapped section-by-section to the DPDP Act 2023 — not retrofitted from GDPR. Native vocabulary throughout: Data Principal, Data Fiduciary, Data Processor.
All 22 scheduled Indian languages
Consent notices in all 22 Eighth Schedule languages. Comprehension is the standard, not just delivery.
India data residency by default
Data stays in India by default, not by configuration. Sub-processors named and documented before you sign.
Seven integrated modules, one suite
DPDP Navigator, Consent Engine, Rights Center, Compliance Center, Audits & Assessment Center, Data Processor Management, and Minimum Security Safeguards — deploy all or start with one.
DPDP Navigator
truScanner and truFinder map personal data across databases, code repos, logs, and API payloads — powered by truLM to surface exposures before a breach does.
IITMIC Incubated, India-built
Incubated at IITMIC. Recognised by iTNT and DSCI-NCoE. Recipient of the Emerging Changemakers Grant, sponsored by CITI.
Recognition
Backed by institutions that take privacy seriously.
truConsent is recognised across India's leading technology and data security institutions — and selected for competitive grant funding.
Incubated at
IITMIC
IIT Madras Incubation Cell

Acceleration of sorts by
iTNT
Tamilnadu Technology Hub

Recognised by
DSCI-NCoE
Data Security Council of India — National Centre of Excellence

Grant Award
Emerging Changemakers
Sponsored by CITI · Awarded through IITMIC

Side by side
truConsent vs. retrofitted GDPR suites.
Indian Data Fiduciaries evaluating global CMPs often hit the same three walls — price, India-fit, and depth of DPDPA mapping. Here is the honest comparison.
Where we will not compromise
Four lines we will not cross.
- 01
No GDPR vocabulary.
Not in copy, not in our API, not in our database column names. DPDP has its own words — we use them.
- 02
No fully automated breach response.
The seventy-two-hour clock is not a CI/CD pipeline. We make it cheaper, not unattended.
- 03
No data leaving India by default.
Residency is a default, not a setting you have to fight for.
- 04
No hidden pricing for the Starter tier.
A bootstrapped Data Fiduciary should be able to ship a DPDP-aligned programme without filing a procurement request.
Security & Data Residency
A consent platform is the system of record for the most sensitive thing your business holds — your users' wishes. We treat security as a precondition, not a feature.
- India data residency by default; sub-processor list published in the DPA
- Immutable audit logging with cryptographic receipts
- Encrypted at rest (AES-256) and in transit (TLS 1.3)
- Role-based access control with least-privilege enforcement
- Public DPO contact display per DPDPA Section 30
- 72-hour breach notification workflow built into the platform
- ISO 27001 in progress; in-VPC scanners; signed event streams
Transparency & Ownership
Open before it's required.
The Draft DPDP Rules place specific obligations on Consent Managers to disclose ownership, control, and the chain of accountability behind the platform. We're publishing this before those requirements come into force — because if we're asking Indian businesses to be transparent about how they handle their users' data, we should hold ourselves to the same standard first.
Legal Owner
Tangled Threads Technologies Private Limited
An Indian private limited company incorporated and registered in Bangalore, Karnataka, India. Part of the TruHQ group alongside truVerify (KYC & identity) and truAgent.
Shareholding & Control
Entirely Indian-owned. No foreign private equity or venture capital. Founders are operationally in control. IITMIC's stake reflects incubation investment — not board-level control over commercial decisions.
Conflict of Interest Disclosures — Schedule I, Part B, DPDP Rules 2025
Per the obligations for Consent Managers, we disclose corporate interests exceeding 2% held by management:
Sairaam V holds a 50% interest in CoBuild Technologies Private Limited, an IT services company. CoBuild does not operate in consent management or DPDPA compliance. There is no commercial relationship or client overlap that would create a conflict of interest in the management of consent records.
Yuvaraj R holds an interest in Horizontal Thinkers Technologies Private Limited. A divestment of this interest is currently in progress. This disclosure will be updated on completion of the transfer.
Chain of Accountability
Data Principal
↓
truConsent (Consent Manager)
↓
Data Fiduciary
truConsent operates data-blind — we manage the consent record and signal, not the personal data itself. The architecture makes reading personal data technically impossible for us as the Consent Manager.
Change of Control
Any transfer of majority ownership or effective control of Tangled Threads Technologies Private Limited requires prior approval from the Data Protection Board of India, per Rule 4(5) of the DPDP Rules 2025. We will not change hands without that approval and public disclosure.
Consent Manager Registration
We are preparing our full Consent Manager registration application against the Draft DPDP Rules. The moment the Data Protection Board opens registration, we are first in the queue. Until then, our consent architecture satisfies every operational requirement the Rules describe.