The compliance layer for India's sovereign-data era.
Every Indian company that touches personal data must prove DPDP & CERT-In compliance by May 2027. Praman turns that obligation into a live, tamper-evident, regulator-ready product — sovereign by construction.
A time-boxed, regulation-forced market
The law just turned on
DPDP Rules were notified Nov 2025 with full compliance due 13 May 2027. CERT-In directions already bind every ICT operator. Compliance shifted from optional to board-level and time-boxed.
AI broke the old tools
Personal data now leaks into foreign LLM prompts — a cross-border transfer the consent-banner generation of tools cannot even see. The risk surface moved to infrastructure and AI pipelines.
Sovereignty is a hard requirement
India's data-centre capex is surging and tenants demand in-region proof. A compliance tool hosted on foreign cloud is itself non-compliant — structurally excluding most incumbents.
Every Data Fiduciary in India must be compliant by 13 May 2027. That deadline is our demand curve.
A large market, opening on a deadline
Top-down estimate, ₹ crore. For discussion — validate in diligence.
Why this is hard to copy
Infra & AI layer, not consent banners
Jurisdiction/egress monitoring, in-pipeline PII detection and retention enforcement on real systems — the gap incumbents skipped.
Sovereign by construction
No component needs a foreign-hosted service. One docker compose up runs the whole platform in-region — a requirement competitors can't retrofit.
Tamper-evident evidence
Hash-chained, append-only audit log the database itself refuses to alter. Auditor- and cyber-insurer-grade proof, not screenshots.
Law-as-data
Obligations are versioned data, not code. New rules (RBI/SEBI overlays) ship without a release — defensible against a moving regulatory target.
Land free, expand through operators
B2B SaaS with a self-host land motion and operator-led expansion. Free Community installs seed adoption; managed Growth and multi-tenant Enterprise convert to recurring revenue.
Shipped, sovereign, and verifiable today
Product shipped
Full assurance engine live and verified end-to-end against real Postgres — 11 DPDP+CERT-In obligations, tamper-evident log, one-click Audit Pack.
Sovereign deployment proven
Entire stack runs in-region with a single docker compose up; integrity chain verifies clean across every event.
Design-partner motion
In active conversation with sovereign-cloud operators and regulated enterprises as launch design partners.
The path to the deadline
MVP GA · self-host + managed · first design partners
Ledger anchoring · RBI/SEBI obligation overlays · SSO · SOC 2 / ISO 27001 path
Auto-discovery connectors · multi-tenant operator console · scheduled assurance & alerting at scale
Continuous-controls-monitoring expansion · partner marketplace · pan-India operator footprint
≈ $0.72M · 18-month runway to revenue traction
- ▹Convert design partners to paying Growth/Enterprise logos
- ▹Achieve SOC 2 Type I and ISO 27001 readiness
- ▹Ship RBI/SEBI overlays and the multi-tenant operator console
- ▹Establish a repeatable operator-led GTM ahead of the May 2027 deadline
hello@praman.zyvark.in
Forward-looking figures are management estimates for discussion and are not audited or guaranteed. Praman provides compliance tooling, not legal advice.