Proof of compliance,
on demand.
Praman is a sovereign, continuous compliance-assurance platform for AI and data-centre workloads in India. Watch your data flows, measure them against DPDP and CERT-In, and export tamper-evident, regulator-ready proof.
Advisory by design — Praman observes, verdicts and logs. It never blocks traffic or auto-sends notifications.
A live posture board, not a slideware promise.
One platform, mapped to every department
Compliance is a team sport. Praman gives each function the view, the controls and the evidence it owns.
Data Protection Officers
Run the DPDP programme from a single source of truth.
Explore →Legal & Compliance
Turn a moving regulatory target into a versioned, auditable library.
Explore →Security & CISO
Beat the CERT-In six-hour clock — and prove your logs are in India.
Explore →Data-Centre & Cloud Operators
Prove sovereignty for every workload you host.
Explore →AI & ML Engineering
Stop personal data leaking into foreign model APIs.
Explore →Internal Audit & Risk
Evidence no one — including the operator — can backdate.
Explore →Built for India's data-centre economy
India's infrastructure capex is surging and tenants now demand in-region proof. Praman is engineered for the operators, clouds and regulated enterprises building on sovereign ground.
Data centres & colocation
Carry compliance weight for every enterprise you host. Praman maps each facility, cluster and tenant workload and produces residency evidence your tenants can rely on.
- Per-tenant Audit Packs
- Facility & rack-level asset registry
- In-India log-retention checks (180 days)
Sovereign & GovCloud
When the mandate is in-country by law, a compliance tool on foreign cloud is itself non-compliant. Praman runs entirely in-region with one docker compose up.
- 100% self-hostable
- No foreign dependency
- Jurisdiction-classified egress
AI & GPU clouds
The headline AI risk is personal data leaving India inside a prompt to a foreign model API. Praman registers pipelines and model endpoints and flags that egress before it becomes a violation.
- PII-in-prompt detection
- Foreign-model-API verdicts
- Pipeline & endpoint registry
BFSI & fintech
Layer RBI and SEBI obligations over the DPDP + CERT-In baseline. Because rules are versioned data, sectoral overlays ship without a software release.
- Law-as-data overlays
- Cross-border transfer monitoring
- Tamper-evident audit trail
Healthcare & life sciences
Sensitive personal data demands the strictest handling, retention discipline and breach readiness. Praman tracks consent, purpose and storage limitation per dataset.
- Sensitive-data classification
- Consent & retention clocks
- Two-tier breach workflow
Managed services & SIs
Run assurance across a portfolio of client estates from one multi-tenant console, and hand each client defensible evidence on demand.
- Multi-tenant by construction
- Scoped evidence export
- Continuous posture scoring
Sovereign Compliance for India's Data-Centre Industry
A practical field guide to DPDP and CERT-In for operators and regulated enterprises — what the law requires, why AI broke the old tooling, and a 90-day path to defensible compliance.
Watch, measure, and prove
Eight modules, one continuous assurance engine — every status traceable to immutable evidence.
Compliance Posture
A live readiness score, open obligations, a countdown to DPDP enforcement, and recent evidence — at a glance.
Assets & Data Map
A registry of systems, pipelines and flows, rendered as a jurisdiction-coloured graph.
Rule Engine
DPDP and CERT-In obligations as versioned data, each evaluated against your live state with its citation.
PII Classifier
In-region detection of Aadhaar, PAN, phone and email — never sent to a foreign API.
Egress Monitor
Every outbound flow classified by jurisdiction and controller, with the foreign-model-API risk called out.
Breach Workflow
Two-tier DPDP notification and the CERT-In 6-hour clock, with editable drafts and full audit logging.
Tamper-Evident Audit Trail
An append-only, hash-chained log with one-click integrity verification.
Audit Pack Export
A regulator-ready PDF plus JSON evidence, carrying its own integrity certificate.
From data flows to defensible proof
Watch
Register assets, workloads and data flows — by hand, CSV, or ingest. Personal data is classified in-region.
Measure
The rule engine evaluates your live state against versioned DPDP and CERT-In obligations, each with its citation.
Prove
Every result writes to a tamper-evident log. Export a regulator-ready Audit Pack with an integrity certificate.
Make sense of Indian data law
The DPDP Act 2023: a practical compliance guide
What the Digital Personal Data Protection Act requires, who it binds, the 2027 enforcement timeline, and how to build a defensible programme.
CERT-In 6-hour incident reporting, explained
The CERT-In directions require reportable cyber incidents to be reported within six hours. Here is what that means in practice and how to never miss the window.
Cross-border data transfer under the DPDP Act
India uses a negative-list model for transfers abroad. Here is how it works, why foreign model APIs are the new risk, and how to stay on the right side of it.
Be ready well before May 2027.
See how Praman turns DPDP and CERT-In obligations into a live posture and tamper-evident proof.