Security & trust

Built so trust is the default, not an afterthought.

DPDPA.support handles personal data for your data principals, so its security model is deliberate and conservative. Members never type an email, every session belongs to a single site, credentials are kept securely out of reach, and erasure is a documented processing freeze, not a quiet delete.

Identity

The email is never typed. It is resolved.

A data principal proves who they are through their site membership, not by typing an address into a box. Identity is resolved server-side, countersigned, and an OTP is sent only to that resolved inbox.

Member identity, resolved

On the My Data page the member is auto-resolved from their verified login, the identity is confirmed server-side and cryptographically countersigned, so the address is never typed or user-supplied.

OTP only to that inbox

A one-time passcode is then sent only to the resolved inbox for step-up. Guests who are not members see a members-only message, there is no email input field to abuse.

Sessions & secrets

Scoped to one site. Kept out of reach.

Per-site sessions

Each sign-in creates a secure session tied to one specific site and set to expire. A session created on one site cannot be reused on any other, a stolen session simply does not open a door.

Securely isolated credentials

Access keys, fiduciary IDs, policy IDs and the DPO email are kept securely on the server side, per site. Never in code, never in the browser, the page a visitor sees holds nothing sensitive.

Verified consent events

Every consent event carries a cryptographic signature that is checked the moment it arrives, so the system of record only accepts events it can prove are genuine.

Failure & disclosure

When something fails, your principals see plain words, not our plumbing.

Defense-in-depth extends to error handling and to the emails we send on a fiduciary's behalf. Detail goes to private logs; people see generic, brand-voiced text.

Sanitized error messages

Full technical detail is kept in private logs. The person sees plain, brand-voiced text, and the interface strips out any internal system names, so nothing about how the platform is built ever leaks to a data principal.

Honest email deliverability

The From mailbox stays dpo@cynorsense.com so SPF and DKIM remain intact; the fiduciary appears as the display name and Reply-To, and the body discloses that we act as a processor on the fiduciary's behalf.

Erasure

Erasure is a processing freeze, with a legal hold.

Under §12, processing genuinely stops the moment a principal asks, but the record is preserved as compliance proof under a documented §8(7) legal hold, then purged with proof when the retention clock expires.

Processing stops

Consents are withdrawn, marketing consent is revoked, email subscriptions are unsubscribed, and marketing labels are stripped. Withdrawal flows both ways, pushed back to your site site so marketing actually stops.

Held under §8(7)

Data is retained storage-only under a documented legal hold with a retention clock (books and tax law). The frozen state itself is the compliance proof an authority may demand.

Purged with proof

A durable record is written the moment data is frozen; once the retention clock expires the hold is purged automatically, the purge is logged as proof, and the record is marked purged.

Trust posture

Honest about where we stand.

We describe our posture as audit-ready, assessed in-house by CynorSense's ISO 27001 Lead Auditors. We do not claim certifications we do not hold, and DPDPA.support is not a Board-registered Consent Manager, it is the fiduciary's own compliance platform.

ISO 27001-ready

Information Security Management practices assessed audit-ready in-house, described honestly, not badged as a certificate we have not earned.

SOC 2 Type 2-ready

Built toward the Trust Services Criteria. "Ready" means prepared for assessment, we will not imply a report exists before it does.

DPO-led

Run under a named Data Protection Officer at dpo@cynorsense.com, a real, reachable point of contact.

Read the policies. Then install with confidence.

Our Security Statement, Data Processing Addendum and Incident Response plan are published in full. Review them, then install DPDPA.support on your website.