DPDP Audit Workbench

Run a DPDP audit that holds up.

A methodology-driven workbench for independent auditors to conduct, evidence, and report Digital Personal Data Protection audits under India's DPDP Act, 2023 and DPDP Rules, 2025. Evidence is SHA-256 hashed into an append-only ledger, and four report artifacts are generated from that one dataset, with no duplicate entry and no version drift.

Not a legal certification. This is a product-generated audit instrument. Values that depend on a Gazette notification are held as versioned parameters and must be closed by a qualified compliance reviewer before live use.
The audit workflow

Seven steps, one ledger, four reports.

The workbench never alters client systems. Every read is least-privilege, and every action an auditor takes is logged to the ledger with identity, timestamp, and rationale.

01

Engagement setup

Client, audit period, significant data fiduciary status, and scope. The control-library version is stamped onto the engagement at the start.

02

Evidence intake

Upload the client's exports. Each artifact is SHA-256 hashed, timestamped, attributed to the uploader, and locked into the evidence ledger.

03

Control engine

The engine proposes Pass, Fail, Needs Review, or Not Applicable per control from the tagged evidence. Phased controls outside their in-force window are auto-marked Not Applicable.

04

Auditor review

The named auditor confirms, overrides with a required rationale, or marks Needs Review. The auditor's judgment always sits above the engine's proposal.

05

Findings

Narrative findings are drafted from failed controls with severity and an evidence reference, ready for the auditor to refine.

06

Sign-off

The lead auditor signs off per module or per engagement. Sign-off is cryptographically recorded against the ledger head and freezes that section.

The evidence ledger

Append-only, and provably never rewritten.

Each entry hashes the previous entry's hash together with its own payload. Altering any historical entry breaks every hash that follows it. Anyone holding the export can recompute the chain to confirm the trail was never edited after sign-off.

SHA-256 chainedTamper detectableRead-only client accessCryptographic sign-off
214
CONTROLS TESTED
6
FINDINGS
1
CRITICAL
100%
LEDGER SEALED
engagementsigned off
opinioncompliant, with findings
working papersgenerated
findings registerexported CSV
ledgerverified
Four artifacts, one dataset

No duplicate entry. No version drift.

Every report is a projection of the same engagement data, SHA-256 sealed and carrying a persistent verification reference back to the ledger.

Audit report

The formal deliverable

Opinion-led, fixed structure, ready to hand to the client's board or regulator.

Working papers

Full evidentiary backing

Control by control, drawn directly from the ledger, for the file a reviewer can trace.

Executive summary

The leadership view

Risk rollup and top findings, sized for a five-minute read.

Run your first engagement offline.

Open the zero-install demo workbench in a browser, no server, no network, no client data leaves your machine.

The platform

Explore the rest of the platform