How it worksPlatformPricingLog inSign up
DPDP enforcement begins May 2027

Know exactly where you stand on DPDP.

Privra scans your AWS infrastructure, audits your consent flows with a real browser, and generates the documentation the DPDP Act requires — in minutes, not months.

₹2L/year · No demo call · No per-seat charges · Cancel anytime

₹250 Cr
Maximum penalty for security failures
~80%
Indian companies haven't updated privacy frameworks
<20 min
Time to your first compliance score with Privra

Your compliance dashboard,
live in minutes.

Connect your AWS account and product URL. See your score, findings, and evidence within 20 minutes.

app.privra.in/dashboard

Real-time compliance score with DPDP section breakdown

app.privra.in/findings

Severity-rated findings with one-click remediation

app.privra.in/consent-audit

Browser agent captures evidence from your live product

trust.privra.in/your-company

Public Trust Center your customers can verify

DPDP isn't optional.
It's the law.

The Digital Personal Data Protection Act applies to every company processing personal data in India. Here's what you're required to do — and what most startups haven't started.

Consent & notice before collecting data

Every data collection point needs a clear, specific notice with a proper consent mechanism. Pre-ticked checkboxes and bundled consent are illegal.

DPDP Section 5 & 6

Reasonable security safeguards

Encryption at rest, access controls, audit trails, MFA — the Board will assess whether your infrastructure meets the "reasonable" standard.

DPDP Section 8(5)

Breach notification to Board + individuals

If personal data is breached, you must notify the Data Protection Board and every affected individual. Without monitoring, you won't even know it happened.

DPDP Section 8(6)

Data retention & erasure obligations

You must erase personal data when it's no longer needed. Most startups retain everything indefinitely — that's now a violation.

DPDP Section 8(7)

Penalty exposure under DPDP

Each obligation carries its own penalty ceiling. Non-compliance isn't a slap on the wrist.

Security safeguard failures₹250 Cr
Breach notification failure₹200 Cr
Children's data violations₹200 Cr
Any other DPDP violation₹50 Cr

Connect. Scan. Comply.

Three steps. Under 20 minutes. No consultants, no demo calls, no ₹20L invoices.

012 minutes

Connect your infrastructure

Paste your AWS IAM Role ARN and Razorpay API key. Read-only access only — we never modify your systems. One CloudFormation template, done.

0215 minutes

AI agents scan everything

Our agents scan your AWS infrastructure for security gaps, visit your live product to audit consent flows, and map where personal data actually lives.

03Continuous

Get compliant, stay compliant

See your DPDP score, fix issues with step-by-step guidance, generate every required policy, and get a public Trust Center — all from your dashboard.

What Privra checks.

Automated scans across infrastructure, consent, data mapping, documentation, and compliance reasoning. Every check maps to a specific DPDP obligation.

🔒

Infrastructure Security

Connects to your AWS account via read-only IAM role. Runs 20+ deterministic checks across S3, RDS, IAM, CloudTrail, KMS, and VPC — all mapped to Section 8(5) security safeguards.

S3 encryptionIAM MFACloudTrailRDS securityKey rotation

Consent & Privacy Auditor

A browser agent that visits your live product, navigates your signup flow, and audits your consent experience from a user's perspective. Finds pre-ticked boxes, dark patterns, and missing notices.

Signup auditPrivacy policyLanguage accessWithdrawal ease
🗂️

Data Mapping & Retention

Discovers where personal data actually lives across your AWS and Razorpay systems, maps how it flows between services, assesses retention policies, and verifies you can erase a user's data on request.

Data inventoryRetention policiesErasure pathsData flow mapping
📄

Policy & Documentation

Generates every DPDP-required document customized to your actual data practices — then cross-references against scan findings to ensure your policies match reality.

Privacy policyConsent noticesBreach templatesDPAs
🧠

Compliance Intelligence

The brain. Orchestrates all agents, calculates your weighted compliance score, identifies cross-domain gaps, and generates your DPDP Readiness Report with evidence.

Cross-domain reasoningScoring engineReadiness report

Everything you need.
Nothing you don't.

📊

Compliance Dashboard

Real-time DPDP score with section-by-section breakdown, severity-rated findings, and step-by-step remediation.

The first thing your CTO opens Monday morning.

📋

Policy Documents

All 6 DPDP-required policies — privacy policy, consent notices, breach templates, retention policy, DPAs, grievance SOP.

The documents enterprise procurement asks for.

🌐

Trust Center

Public-facing compliance page at trust.privra.in showing your policies, scan status, and DPO contact info.

The public page your customers check before signing.

📸

Evidence Screenshots

Timestamped visual evidence from every scan — infrastructure configs, consent flow screenshots, policy checks.

Visual proof for investors, auditors, and board reporting.

📈

Continuous Monitoring

Daily automated re-scans with drift detection. If something breaks, you'll know before the Board does.

Know before your customers notice.

📑

Readiness Report

Comprehensive PDF with executive summary, section-by-section analysis, evidence, and remediation roadmap.

The PDF that closes the compliance conversation.

We scan your infrastructure.
We don't touch your data.

Privra connects via read-only IAM roles. We never store credentials, never modify resources, and never access customer data.

Read-only access

Privra connects via a scoped IAM role with SecurityAudit permissions. We cannot create, modify, or delete any resource in your AWS account.

No credentials stored

We use STS AssumeRole for temporary session tokens. Your AWS access keys never touch our servers. Razorpay keys are encrypted at rest with AES-256.

Your data stays yours

Scan findings and evidence are stored in your isolated Privra workspace. We don't aggregate, share, or train on your compliance data.

Encrypted evidence

All screenshots, scan results, and policy documents are encrypted in transit (TLS 1.3) and at rest. Evidence is tamper-evident with timestamps.

Transparent. No surprises.

No demo calls. No per-seat charges. No hidden fees. The price is on the page because we respect your time.

Most popular
Privra Platform
₹2L /year
₹16,667/month effective · Billed annually
  • Full AWS + Razorpay infrastructure scanning
  • Browser-based consent flow audit with evidence
  • DPDP compliance score with section breakdown
  • All 6 AI-generated policy documents
  • Public Trust Center page
  • DPDP Readiness Report included
  • Daily monitoring + weekly digest emails
  • Unlimited team members
Start free scan →
Standalone Assessment
₹75K one-time
Full scan + Readiness Report. No subscription.
Get assessed

Compare

Sprinto DPDP₹7–8.5L/yr
Manual consulting₹20L+ one-time
Hiring a DPO₹9–18L/yr
Privra₹2L/yr

Be ready before the questionnaire arrives.

Know your compliance gaps before your next customer, investor, or auditor asks.