DPDP · GDPR · CCPA/CPRA · ONE SEALED CONSENT LEDGER

Cryptographically Sealed Consent for Every Privacy Law

Replace black-box cookie banners with audit-ready, tamper-evident proof. One sub-12KB widget, region-aware notices in 22 languages, HMAC-SHA256 signed receipts sealed into Merkle roots, and signed webhooks that stream every decision to your own database. We store pseudonymous consent records only.

Supported privacy laws
DPDPFlagshipGDPRUK GDPRCCPA/CPRALGPDPDPAPIPEDA

Works with your stack

One script tag · Any framework
Google Consent ModeNative v2 Relay
Shopify PlusStorefront & Checkout
Webflow EnterpriseNo-Code CMS Embed
WordPress / WooZero Drag Plugin
ReactClient SDK & Hooks
Next.js App RouterServer & Edge Runtime
AWS Sovereign RegionMumbai ap-south-1
Cloudflare WorkersEdge Delivery
Twilio Segment CDPIdentity & Event Stream
Vercel Edge NetworkGlobal Edge Runtime
MATHEMATICALLY PROVABLE GUARANTEES

The guarantees behind every consent record

These are not marketing estimates—they are cryptographically enforced architectural properties of the platform. Click any metric to inspect the statutory verification trail.

TELEMETRY: SIGNATURE SCHEME
HMAC-SHA256 / KMS HSMS
DPDP §6(10) Burden of Proof
Deep dive technical specification
CONSENT LIFECYCLE & CHAIN OF CUSTODY

From banner click to audit-ready, tamper-evident proof

ConsentPlix intercepts tracking scripts before execution, captures unambiguous visitor decisions through itemized statutory notices, computes an HMAC-SHA256 signature across 11 canonical fields, and anchors the record into daily Merkle checkpoint roots. Every event yields a tamper-evident, independently verifiable audit receipt.

Script InterceptionPRE-TAG INGRESS

Zero-Delay Script Interception

0ms Main Thread Delay · Pre-GTM Execution

Sub-12KB autonomous SDK loads deterministically before Google Tag Manager and third-party ad pixels fire. Holds non-essential trackers in queue until affirmative consent is given.

GTM SCRIPTHELDAUTHORIZED
<script src="cp.min.js" data-site="cp_live_..." async></script>< 12 KB IIFE
Statutory Notice22 CONSTITUTIONAL LANGUAGES

Verifiable Statutory Notice

Zero Pre-Ticked Toggles · One-Click Revoke

Renders clear, itemized notice in English and all 22 Eighth Schedule Indian languages. Discloses the Grievance Redressal Officer with instant Section 6(4) withdrawal.

22 LANG
NO DARK PATTERNSCOMPLIANT
Cryptographic SignatureRFC 2104 · SHA-256

HMAC-SHA256 Signed Artifact

11 Canonical Fields · KMS Key Custody

Every consent grant, refusal, or revocation is canonicalized across 11 fields and signed in hardware HSMs. Produces an unforgeable receipt code for legal audit.

HASH9f83…d71b
BURDEN OF PROOF COMPLIANTHMAC VERIFIED
Merkle Root SealRFC 6962 · DAILY ANCHORING

Merkle Checkpoint Proof Vault

Immutable Append-Only · Zero Retroactive Rewrite

Daily cryptographic Merkle tree roots seal the consent vault. Any auditor or judge can mathematically verify that a specific receipt existed on a given date without leaking customer identity.

MERKLE ROOTBRANCHBRANCH
LATEST ROOT: 9a410c2d...8b31 · AWS AP-SOUTH-1SEALED
PLATFORM CAPABILITIES

Support every stage of compliance, from banner to audit.

Engineered to replace fragile client-side cookie banners with provable, mathematically sound consent infrastructure that stands up to regulatory scrutiny worldwide.

TAMPER-EVIDENT SPECIFICATION
DPDP · GDPR · CCPA
Court-Admissible Evidence

Signed consent receipts & tamper-evident ledger

Every consent event is normalized into an 11-field canonical JSON receipt, HMAC-SHA256 signed with KMS custody, and batched into verifiable Merkle tree roots.

HMAC-SHA256 SignaturesMerkle Tree RootsCourt-Admissible Export
ARCHITECTURAL SPECIFICATIONRequest a walkthrough
Zero Main-Thread Drag

Sub-12KB widget + Google Consent Mode v2

Zero runtime dependencies. Intercepts non-essential scripts before GTM loads, automatically relays ad_storage and analytics_storage signals to Google tag containers.

Sub-12KB Gzipped IIFEZero Main Thread DragGoogle Consent Mode v2
ARCHITECTURAL SPECIFICATIONRequest a walkthrough
Dynamic Rule Dispatch

Region-aware notices & geolocation engine

Edge CDN detects visitor jurisdiction automatically. European visitors receive granular GDPR opt-ins; California visitors see "Do Not Sell" opt-outs; Indian users receive DPDP notices in their language.

Edge IP Resolution22 Indian LanguagesZero Cross-Border Drag
ARCHITECTURAL SPECIFICATIONRequest a walkthrough
Automated Rights Intake

Data subject rights portal with SLA clocks

Hosted citizen intake portal featuring statutory countdown timers, automated identity verification, and conflict-of-law holds for banking, PMLA, and tax audit compliance.

72h Urgent SLA ClocksAutomated VerificationConflict-of-Law Holds
ARCHITECTURAL SPECIFICATIONRequest a walkthrough
Continuous Audit Engine

Tracker scanner & cookie catalog

Headless browser crawls your web properties on a scheduled cadence, detecting newly added marketing pixels, unclassified cookies, or rogue tags that violate policy.

Automated Drift Detection50,000+ Tag FingerprintsInstant Slack Alerts
ARCHITECTURAL SPECIFICATIONRequest a walkthrough
Zero Customer PII Storage

Signed webhooks — keep your own copy

We store cryptographic consent records only. HMAC-SHA256 signed webhooks stream every grant, refusal, and revocation directly into your own data warehouse in real time.

Zero Customer PII StoredReal-Time Signed StreamYour Private Cloud / DB
ARCHITECTURAL SPECIFICATIONRequest a walkthrough
GLOBAL PRIVACY REGIMES

Unified statutory compliance for every major privacy law

From India’s DPDP mandate to Europe’s GDPR and California’s CCPA opt-out rules, our lightweight SDK enforces region-specific consent standards at the edge, compiling every decision into a single verifiable ledger.

REGION-AWARE NOTICE DISPATCH
Flagship Mandate · Section 6
AUDIT-READY

India DPDP Act 2023

Unambiguous, affirmative notice presentation across all 22 Eighth Schedule official languages. Verifiable 1-click consent withdrawal mechanism, zero dark patterns, and a built-in grievance and rights request workflow.

22 LANGDPDP §6(1)
PRIOR EXPLICIT OPT-IN REQUIREDDPDP Specs
European Union · Art. 7
TCF 2.2 SIGNALS

EU GDPR & ePrivacy

Granular purpose categorization, automatic client-side script interception before any cookie execution, and built-in Google Consent Mode v2 signal dispatch.

HELDTCF 2.2
SCRIPT INTERCEPTOR ACTIVEGDPR Specs
California, USAGPC DETECT

CCPA / CPRA

Automatic Global Privacy Control (GPC) signal detection, itemized "Do Not Sell or Share My Info" opt-out receipts with an audit-ready evidence trail.

GPC opt-outSIGNAL: ON
OPT-OUT FRAMEWORKDetails
United KingdomICO RULES

UK GDPR / PECR

Explicit cookie consent aligned with UK Information Commissioner’s Office guidance. Purpose switchboards and non-essential tracker quarantine.

STRICT ICO COMPLIANCEDetails
Brazil · Latin AmericaANPD ART. 7

Brazil LGPD

National Data Protection Authority (ANPD) governance, legal basis attribution (Art. 7), Portuguese notices, and designated DPO receipt logging.

ANPD Art. 7DPO: ASSIGNEDPROOF: VERIFIED
LEGAL BASIS ANCHOREDDetails
Region-aware notice resolution

One Autonomous SDK. Every Country Served Automatically.

You deploy one sub-12KB script. When a visitor arrives from Mumbai, Berlin, California, London, or São Paulo, region detection selects and renders the exact statutory notice required by local privacy regulators.

P99 < 15MS
ONE-TAG INTEGRATION

One script tag. Full statutory enforcement.

Paste the sub-12KB autonomous SDK before your tag managers. The engine initializes Consent Mode v2 synchronously, handles multilingual rendering, and starts streaming HMAC-signed receipts immediately.

01

Paste script in HTML <head>

Embed the sub-12KB bundle prior to Google Tag Manager or marketing pixels to ensure deterministic tracking control.

02

Configure Consent Mode v2 Defaults

Consent keys initialize to denied automatically. Tracking tags remain blocked until the visitor grants affirmative consent.

03

Verify Tamper-Evident Receipt

Every granted or revoked decision streams a signed HMAC-SHA256 receipt verifiable at your unique ledger URL.

RAW CI BUDGET < 12,288 BYTES~4 KB GZIPPED
index.html (prior to <head> close)
<!-- 1. ConsentPlix Autonomous Interceptor (Sub-12KB) -->
<script
  src="https://cdn.consentplix.com/v1/consent.min.js"
  data-site-id="cp_live_9a7b21"
  data-region-auto="true"
  data-audit-stream="enabled"
  async
></script>

<!-- 2. Your Existing Google Tag Manager (Held deterministically) -->
<script>(function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start':
new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0],
j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src=
'https://www.googletagmanager.com/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f);
})(window,document,'script','dataLayer','GTM-XXXXXXX');</script>
NEED NPM OR REACT HOOKS?Request developer sandbox
TRANSPARENT PRICING · NO HIDDEN FEES

Predictable pricing for audit-ready consent proof.

Every plan includes the sub-12KB autonomous SDK, cryptographically signed consent receipts, Merkle-sealed ledger proofs, and sovereign hosting in AWS Mumbai (ap-south-1).

1 MONTH FREE TRIAL
Essential compliance

Starter

For early-stage products, single SaaS apps and creators getting DPDP-ready with single-domain sovereign compliance.

₹399/ month + GST
Billed monthly · 1 Month Free Trial
Included Capabilities
  • 1 production domain
  • 1 month free trial included
  • Sub-12KB autonomous widget and SDK
  • Signed consent receipts on append-only ledger
  • Daily Merkle root cryptographic sealing
  • DPDP notice templates in 5 Indian languages
  • Google Consent Mode v2 signals
  • Monthly tracker scan (up to 500 pages)
  • Hosted sovereign in AWS Mumbai (ap-south-1)
1 MONTH FREE TRIALMOST POPULAR · AUDIT READY
Full audit readiness

Growth

For scaling platforms, multi-brand e-commerce and mid-market teams operating up to 10 domains across all 22 Indian languages.

₹999/ month + GST
Billed monthly · 1 Month Free Trial
Included Capabilities
  • Up to 10 production domains
  • 1 month free trial included
  • Everything in Starter included
  • Statutory notices in all 22 scheduled languages
  • Hourly Merkle root cryptographic sealing
  • Cross-domain consent synchronization
  • Geolocation rules (DPDP, GDPR, CCPA, LGPD, PDPA)
  • White-label rights portal with 72h SLA countdown
  • Weekly automated cookie & tracker audit scan
  • Data Processing Agreement (DPA) included
Significant Data Fiduciaries

Enterprise

For banks, BFSI, insurers, telecom and enterprise fiduciaries needing dedicated KMS custody, custom retention, and DPBI audit dossiers.

Custom
Tailored volume pricing · Dedicated tenancy
Included Capabilities
  • Everything in Growth included
  • Unlimited domains and subdomains
  • Customer-managed keys (AWS KMS / CloudHSM)
  • Custom statutory retention & conflict-of-law holds
  • Daily continuous tracker scanning with alerting
  • Receipt export to your private S3 / GCS bucket
  • Dedicated tenant VPC and custom residency options
  • Negotiated enterprise DPA & dedicated privacy engineer
GST @ 18% with full B2B Input Tax Credit invoices under SAC 998313 (India).Compare full feature matrix
EDITORIAL & PRIVACY ENGINEERING

Latest Insights & Technical Architecture

Authoritative briefings on DPDP Act enforcement, cryptographic ledger design, and autonomous SDK performance from our engineering team.

ENTERPRISE READINESS

Ready to deploy provable consent infrastructure?

Deploy in minutes with our sub-12KB SDK or schedule a customized technical consultation with our privacy engineering team.