OrbCyber
HomeAbout
Services
AI SecurityGovern AI use, secure GenAICloud SecurityAWS, Azure, GCP hardeningVendor Risk (TPRM)Third-party assuranceOperational ResilienceBCM, DR, impact toleranceIS GRCISO, SOC 2, NIST, PCI, GDPR
DPDPA
End-to-End ComplianceDPDP Act 2023 & Rules 2025DPDPA for HealthcarePatient data, clinical trials, health recordsDPDPA for Banking & FinanceKYC, transaction data, RBI alignmentDPDPA for EducationStudent records, EdTech, parental consent
Platform
Consent ManagementConsent artefacts & evidenceAgentic GRCGovernance, Risk & ComplianceAgentic Third-Party RiskThird-Party Risk ManagementOperational ResilienceBusiness continuity & impact tolerance
IndustriesInsightsContact
Book a Call
  1. Home
  2. /
  3. Platform
  4. /
  5. OrbCyber Consent
Early accessConsent Management Platform

Consent you can prove, not just collect

OrbCyber Consent captures itemised notice, granular purpose-level consent and one-click withdrawal, and stores each one as a tamper-evident artefact you can produce years later, in the language the data principal actually chose.

Request early accessSee how it works
Built in India, hosted in IndiaAll 22 Eighth Schedule languagesDeploys in weeks, not quarters
Consent artefactWhat we store
Account & service deliveryLegitimate use · Sec. 7
Product analyticsConsent · Sec. 6
Marketing communicationWithdrawn 12 Aug 2026
Third-party enrichmentNever granted
Artefact IDcns_7f3a91d4c6
Notice versionv4 · mr-IN
IntegritySHA-256 verified
Notice languages
22
Every Eighth Schedule language, plus English
Withdrawal
One click
As easy as giving it, as Sec. 6(4) requires
Audit trail
Tamper-evident
Hash-chained records, exportable on demand
Data residency
India
Or your own cloud, under your keys

Built for

DPDP Act 2023DPDP Rules 2025GDPRISO 27001SOC 2IAB TCF-ready
The problem

A cookie banner records a click. The DPDP Act asks you to produce something far harder: proof of what a specific person was told, in which language, on which version of the notice, for which purpose, and what they did about it afterwards.

Two years later

That is when the question usually arrives: from an enterprise customer's security review, from due diligence, or from the Board. Most consent tools cannot answer it, because they stored a boolean instead of an artefact.

OrbCyber Consent is built the other way round. Every capture writes an immutable record: the notice text served, its version and language, the purposes offered, what was accepted and refused, the timestamp, and a hash that proves none of it was edited since. Withdrawal writes a new record rather than erasing the old one, so the history stays intact.

How it works

Five steps from purposes to proof

Most teams are live on a first domain inside four weeks. The long pole is agreeing your purpose list, not the integration.

Step 01

Map purposes

Define every purpose you process for, and which are consent-based versus legitimate uses under Sec. 7.

Week 1
Step 02

Build notices

Compose itemised notices in the notice builder, then publish translations across the languages you serve.

Week 1–2
Step 03

Embed

Drop in the web SDK, mobile SDK or server API. Offline and call-centre capture use the same record format.

Week 2–3
Step 04

Capture & enforce

Consent state is queryable at runtime, so downstream systems can check before they process rather than after.

Week 3–4
Step 05

Prove

Export any artefact, run coverage reports, and answer a rights request or an audit from a single console.

Ongoing
Capabilities

What the platform does

Everything below ships in the core product. Nothing here is a paid add-on.

Sec. 5Notice

Itemised notice builder

Compose notices that list each purpose and the personal data it needs, in plain language, with version control so you always know which text a given person actually saw.

  • Versioned notice templates
  • Purpose-level itemisation
  • Preview across web, app and offline
  • Change history with effective dates
Sec. 5(3)Languages

Multilingual delivery

Serve the notice in English or any of the twenty-two languages in the Eighth Schedule, with the served language recorded on the artefact itself.

  • Translation workspace with reviewer sign-off
  • Language detection and manual override
  • Per-language version tracking
  • Right-to-left and Indic script support
CoreEvidence

Tamper-evident consent artefacts

The heart of the product. Each capture writes an immutable, hash-chained record (notice version, language, purposes, decision, timestamp, source) that can be exported and independently verified.

  • Hash-chained, append-only record store
  • Full artefact export as JSON or signed PDF
  • Independent integrity verification
  • Configurable retention aligned to your schedule
Sec. 6Capture

Granular purpose-level consent

No bundled "I agree". Each purpose is accepted or refused on its own, and refusing one never blocks a service that does not need it.

  • Per-purpose accept and refuse
  • No pre-ticked defaults
  • Conditional purpose dependencies
  • Consent expiry and re-consent prompts
Sec. 6(4)Withdrawal

One-click withdrawal & preference centre

A hosted preference centre where a data principal can review everything they have granted and withdraw any of it in a single action, with consequences shown before they confirm.

  • Self-service preference centre
  • Withdrawal in one action, no dark patterns
  • Downstream propagation to connected systems
  • Consequence disclosure before confirmation
Sec. 11–14Rights

Rights request intake & grievance desk

Access, correction, erasure and nomination requests arrive through the same interface, with identity verification, SLA clocks and a complete response log.

  • Rights request intake and routing
  • Identity verification without over-collection
  • SLA tracking and escalation
  • Grievance redressal workflow
Sec. 9Children

Children's data & parental consent

Where under-18 users can reach your product, route them through age assurance and verifiable parental consent, and suppress tracking and behavioural advertising automatically.

  • Age assurance and self-declaration flows
  • Verifiable parental consent, DigiLocker-ready
  • Automatic ad-tech and tracking suppression
  • Guardian linkage and revocation
Sec. 8(7)Retention

Retention triggers & erasure signals

When consent is withdrawn or a retention window closes, the platform emits an erasure signal your systems can act on, and records that it did.

  • Purpose-linked retention windows
  • Webhook and queue-based erasure signals
  • Pre-erasure notification to data principals
  • Deletion acknowledgement tracking
IntegrateDevelopers

SDKs, APIs & runtime enforcement

Query consent state before you process, not after. Web and mobile SDKs, a server API, and webhooks that keep your warehouse and CRM in step.

  • JavaScript, Android, iOS and React Native SDKs
  • REST API with signed webhooks
  • Runtime consent-check endpoint
  • Connectors for CRM, CDP and warehouse
OperateReporting

Coverage dashboards & audit export

See consent coverage by purpose, product and geography, spot the surfaces still capturing nothing, and export an audit bundle without engineering help.

  • Coverage and withdrawal-rate dashboards
  • Gap alerts for uninstrumented surfaces
  • One-click audit bundle export
  • Scheduled reports to the DPO
SecureArchitecture

Security & data residency

Built by a security firm, so the safeguards under Sec. 8(5) are part of the product rather than a checklist beside it.

  • AES-256 at rest, TLS 1.3 in transit
  • India-region hosting, or your own cloud
  • SSO, SCIM and role-based access
  • Immutable access logs retained 12 months+
DeployOptions

SaaS, private cloud or self-hosted

Regulated sectors can run the whole platform inside their own boundary, with OrbCyber operating it or handing over the keys entirely.

  • Multi-tenant SaaS on India region
  • Single-tenant private cloud
  • Self-hosted with your own KMS
  • Air-gapped deployment on request
Clause coverage

What each capability satisfies

The platform is not a compliance guarantee (no software is). It is the evidence layer under the clauses below, and this is exactly which ones.

Sec. 5
Notice must itemise the personal data and the purpose, in clear and plain language
Notice builder
Sec. 5(3)
Notice available in English or any language in the Eighth Schedule to the Constitution
Multilingual delivery
Sec. 6(1)
Consent must be free, specific, informed, unconditional and unambiguous, limited to the stated purpose
Granular capture
Sec. 6(4)
Withdrawal must be as easy as giving consent in the first place
Preference centre
Sec. 6(6)
On withdrawal, processing must cease within a reasonable time
Erasure signals
Sec. 9
Verifiable parental consent for children, with no tracking or behavioural advertising
Children's flows
Sec. 11–14
Rights of access, correction, erasure, grievance redressal and nomination
Rights intake
Sec. 8(5)
Reasonable security safeguards over the consent record itself
Platform security

Clause references are to the Digital Personal Data Protection Act, 2023 and the DPDP Rules, 2025. Software supports compliance; it does not deliver it on its own. Organisational measures, contracts and security controls sit alongside. This page is general information and not legal advice.

Important distinction

A consent platform is not a Consent Manager

These two terms are used interchangeably across the market, and they are not the same thing. Buying the wrong one, or believing you have registered when you have not, is a live risk.

Consent management platform

What OrbCyber Consent is.

  • Software licensed to you, the data fiduciary
  • Captures and stores consent for your own products
  • No registration with the Data Protection Board required
  • You remain the data fiduciary throughout
  • Available now, in early access

Statutory Consent Manager

A regulated intermediary under Section 2(g) and Rule 4.

  • Must be registered with the Data Protection Board
  • Gives data principals one interface across many fiduciaries
  • Must be a company incorporated in India
  • Net worth of not less than two crore rupees
  • Must keep routed personal data unreadable to itself
  • Consent records retained at least seven years
  • Cannot be fiduciary or processor for the same principal
  • Framework live from 13 November 2026

Almost no business needs to become a registered Consent Manager. It is a role for intermediaries, not for companies managing their own users' consent. If you are considering the application, our DPDP team can assess eligibility against Part A of the First Schedule before you commit.

Why OrbCyber Consent

Built by the people who audit this

We did not start with a banner and add compliance. We started with the evidence an auditor asks for and built backwards.

01

Evidence-first

Every capture is an artefact, not a flag. Designed to be produced under scrutiny two years later, not just to render a dialog.

02

Security as product

We are a cybersecurity firm. Encryption, key management, access control and immutable logging are core engineering, not a trust page.

03

Indian by design

Built in India, hosted in India, with all twenty-two Eighth Schedule languages and DPDP semantics rather than a retrofitted GDPR model.

04

Consulting behind it

The same team that runs DPDP gap assessments and ISO 27001 audits. If the platform is the wrong answer for you, we will say so.

FAQ

Frequently asked questions

What prospective customers ask us most often about the platform.

Is OrbCyber Consent generally available?

It is in early access. We are onboarding a limited number of design partners ahead of the 13 May 2027 deadline, which means direct access to the engineering team, influence over the roadmap, and preferential licence terms locked for the first three years. Tell us your stack and volumes and we will say honestly whether you are a fit for this phase or better served at general availability.

Does using your platform make us DPDP compliant?

No, and be careful of anyone who says otherwise. The platform gives you the notice, consent and evidence layer, a substantial part of the Act, but not all of it. Security safeguards under Section 8(5), retention and erasure in your own systems, processor contracts, breach response and governance all sit outside a consent tool. That is what our DPDP consulting practice covers.

Are you a registered Consent Manager?

No. OrbCyber Consent is a consent management platform licensed to data fiduciaries, which is a different thing from the statutory Consent Manager role under Section 2(g) and Rule 4. That role requires registration with the Data Protection Board, incorporation in India, a minimum net worth of two crore rupees, and an obligation to keep routed data unreadable to yourself. The framework comes into force on 13 November 2026. We will say clearly on this page if that ever changes for us.

Can we host it ourselves?

Yes. Enterprise licences support single-tenant private cloud, fully self-hosted deployment inside your own boundary with your own KMS, and air-gapped installation on request. BFSI and healthcare customers usually take one of these. SaaS runs on India-region infrastructure by default.

How long does implementation take?

Most teams are live on a first domain within four weeks. The integration itself is typically a few days of engineering; what takes the time is agreeing your purpose list and drafting notices that survive legal review. If you have already completed a RoPA with us, that work is done and deployment is faster.

We already use a global consent tool. Why switch?

You may not need to. If your existing platform captures purpose-level consent, records notice version and language, and can export a verifiable artefact, it may be adequate. Three things commonly fall short for DPDP: Eighth Schedule language coverage, verifiable parental consent under Section 9, and evidence that withdrawal actually propagated downstream. We will assess your current tool against those honestly before proposing a replacement.

What happens to our data if we leave?

You export the full artefact store in open JSON with hashes intact, so the records remain independently verifiable outside our platform. There is no proprietary lock on your consent evidence. It is your compliance record, not our asset. Export is available at any time on every tier.

Keep exploring

Related

The platform covers consent. These cover everything around it.

DPDP Compliance Services

Gap assessment, RoPA, Section 8(5) safeguards, breach readiness and DPO-as-a-Service.

Explore the services →

IS GRC

ISO 27001, SOC 2, NIST, PCI DSS, GDPR: readiness through certification on a unified control library.

Explore →

Vendor Risk (TPRM)

Continuous third-party assurance: the processor side of your consent obligations.

Explore →
Early access

See it on your own consent flows

A 30-minute working session. Bring one product surface and we will show you the artefact it would produce, using your purposes and your notice text.

Request early accessSee DPDP services
OrbCyber

Enabling Secure, Resilient Operations.

ISO 27001SOC 2PCI DSSGDPRNISTCIS
Services
AI SecurityCloud SecurityVendor Risk (TPRM)Operational ResilienceIS GRCDPDPA ComplianceConsent Management
Company
AboutPlatformIndustriesInsightsContact
Contact
+91 92840 22343Contact@orbcyber.com

Pune, India

© 2026 OrbCyber Technologies. All rights reserved. · Powered by MovinnzaHeadquartered in Pune · Serving India & Middle East