India's data privacy era is here. Be the firm that leads your clients through it. Join the truConsent Partner Program →

    Why truConsent

    India's DPDPA-native consent management platform.

    truConsent is the DPDPA-native consent management platform — built by founders, priced for India, ready for the Data Protection Board. Every workflow mapped to the DPDPA 2023. All 22 scheduled languages. India data residency by default.

    Why Data Fiduciaries pick us

    Six things you get on day one.

    DPDPA-native, not GDPR translated

    Every workflow mapped section-by-section to the DPDP Act 2023 — not retrofitted from GDPR. Native vocabulary throughout: Data Principal, Data Fiduciary, Data Processor.

    All 22 scheduled Indian languages

    Consent notices in all 22 Eighth Schedule languages. Comprehension is the standard, not just delivery.

    India data residency by default

    Data stays in India by default, not by configuration. Sub-processors named and documented before you sign.

    Seven integrated modules, one suite

    DPDP Navigator, Consent Engine, Rights Center, Compliance Center, Audits & Assessment Center, Data Processor Management, and Minimum Security Safeguards — deploy all or start with one.

    DPDP Navigator

    truScanner and truFinder map personal data across databases, code repos, logs, and API payloads — powered by truLM to surface exposures before a breach does.

    IITMIC Incubated, India-built

    Incubated at IITMIC. Recognised by iTNT and DSCI-NCoE. Recipient of the Emerging Changemakers Grant, sponsored by CITI.

    Recognition

    Backed by institutions that take privacy seriously.

    truConsent is recognised across India's leading technology and data security institutions — and selected for competitive grant funding.

    Incubated at

    IITMIC

    IIT Madras Incubation Cell

    IITMIC

    Acceleration of sorts by

    iTNT

    Tamilnadu Technology Hub

    iTNT

    Recognised by

    DSCI-NCoE

    Data Security Council of India — National Centre of Excellence

    DSCI-NCoE

    Grant Award

    Emerging Changemakers

    Sponsored by CITI · Awarded through IITMIC

    CITI

    Side by side

    truConsent vs. retrofitted GDPR suites.

    Indian Data Fiduciaries evaluating global CMPs often hit the same three walls — price, India-fit, and depth of DPDPA mapping. Here is the honest comparison.

    Topic
    truConsent
    Retrofitted GDPR suites
    Regulatory anchor
    DPDP Act 2023 + Draft DPDP Rules. Every workflow tagged to a section.
    GDPR / CCPA. DPDP added as a regional toggle.
    Vocabulary
    Data Principal · Data Fiduciary · Data Processor.
    Data Subject · Controller · Processor relabelled in the UI.
    Consent granularity
    Per-data-point, per-purpose, per-recipient, per-retention-window.
    Banner-level toggles by category.
    Discovery surface
    Code + data + logs + API payloads (truScanner + truFinder).
    Databases only — code is out of scope.
    Breach response
    AI drafts, humans review and send. Regulator-ready evidence pack.
    Fully automated workflows that draft and send — or no breach module at all.
    Pricing posture
    Transparent tiers, Founding-Client deal, no compliance tax.
    Hidden pricing, enterprise-only, sales-gated assets.
    Data residency
    India by default. Documented sub-processors.
    Global multi-region. India is a configuration switch.
    Founder access
    You can email the founders. They reply.
    Tiered support, sales rep gating, escalation paths.
    Capital posture
    Bootstrapped. No VC pressure on the roadmap.
    Venture-funded. Quarterly board pressure on growth metrics.

    Where we will not compromise

    Four lines we will not cross.

    1. 01

      No GDPR vocabulary.

      Not in copy, not in our API, not in our database column names. DPDP has its own words — we use them.

    2. 02

      No fully automated breach response.

      The seventy-two-hour clock is not a CI/CD pipeline. We make it cheaper, not unattended.

    3. 03

      No data leaving India by default.

      Residency is a default, not a setting you have to fight for.

    4. 04

      No hidden pricing for the Starter tier.

      A bootstrapped Data Fiduciary should be able to ship a DPDP-aligned programme without filing a procurement request.

    Security & Data Residency

    A consent platform is the system of record for the most sensitive thing your business holds — your users' wishes. We treat security as a precondition, not a feature.

    • India data residency by default; sub-processor list published in the DPA
    • Immutable audit logging with cryptographic receipts
    • Encrypted at rest (AES-256) and in transit (TLS 1.3)
    • Role-based access control with least-privilege enforcement
    • Public DPO contact display per DPDPA Section 30
    • 72-hour breach notification workflow built into the platform
    • ISO 27001 in progress; in-VPC scanners; signed event streams

    Transparency & Ownership

    Open before it's required.

    The Draft DPDP Rules place specific obligations on Consent Managers to disclose ownership, control, and the chain of accountability behind the platform. We're publishing this before those requirements come into force — because if we're asking Indian businesses to be transparent about how they handle their users' data, we should hold ourselves to the same standard first.

    Legal Owner

    Tangled Threads Technologies Private Limited

    An Indian private limited company incorporated and registered in Bangalore, Karnataka, India. Part of the TruHQ group alongside truVerify (KYC & identity) and truAgent.

    Shareholding & Control

    Yuvaraj R· Co-Founder
    48%
    Sairaam V· Co-Founder
    48%
    IIT Madras Incubation Cell (IITMIC)· Institutional Backer
    4%

    Entirely Indian-owned. No foreign private equity or venture capital. Founders are operationally in control. IITMIC's stake reflects incubation investment — not board-level control over commercial decisions.

    Conflict of Interest Disclosures — Schedule I, Part B, DPDP Rules 2025

    Per the obligations for Consent Managers, we disclose corporate interests exceeding 2% held by management:

    Sairaam V holds a 50% interest in CoBuild Technologies Private Limited, an IT services company. CoBuild does not operate in consent management or DPDPA compliance. There is no commercial relationship or client overlap that would create a conflict of interest in the management of consent records.

    Yuvaraj R holds an interest in Horizontal Thinkers Technologies Private Limited. A divestment of this interest is currently in progress. This disclosure will be updated on completion of the transfer.

    Chain of Accountability

    Data Principal

    truConsent (Consent Manager)

    Data Fiduciary

    truConsent operates data-blind — we manage the consent record and signal, not the personal data itself. The architecture makes reading personal data technically impossible for us as the Consent Manager.

    Change of Control

    Any transfer of majority ownership or effective control of Tangled Threads Technologies Private Limited requires prior approval from the Data Protection Board of India, per Rule 4(5) of the DPDP Rules 2025. We will not change hands without that approval and public disclosure.

    Consent Manager Registration

    We are preparing our full Consent Manager registration application against the Draft DPDP Rules. The moment the Data Protection Board opens registration, we are first in the queue. Until then, our consent architecture satisfies every operational requirement the Rules describe.

    Ready to Achieve DPDPA Compliance?

    Be among the first to implement comprehensive DPDPA compliance

    Newsletter

    Subscribe to our newsletter and stay updated on DPDPA compliance insights.

    By subscribing, you agree to receive updates from TruConsent.Unsubscribe anytime.
    Protected by reCAPTCHA

    Cookie Consent

    We use cookies to enhance your browsing experience, analyze site traffic, and personalize content. By clicking "Accept All", you consent to our use of cookies. You can manage your preferences or decline non-essential cookies by clicking "Decline".