Platform · Architecture and deployment

One platform. Eleven capabilities. Your infrastructure.

AutoCops is a single integrated workspace for every DPDP control — deployable to your own GCP region, your own KMS keys, your own VPC. The platform is open, inspectable, and built so you can leave cleanly if you ever want to. Below is exactly how it works.

Four architecture principles

How the platform is built

01

Single workspace

Eleven capability modules — consent, cookies, DSR, breach, DPIA, vendor risk, grievance, notices, controls, training, executive dashboard — all live behind one login, share a single audit trail, and roll up into one compliance posture.

02

India-resident by default

Deployed to your own GCP, AWS, or Azure region in asia-south1 (Mumbai). Personal data of Indian Data Principals never leaves the country. No shared multi-tenant cluster you'd be on.

03

Open architecture

Every record is exportable. Every workflow is inspectable. Every API is documented. Customer data stays the customer's data. We earn renewals by being useful, not by holding your data hostage.

04

Hot-patch infrastructure

When the DPDP Rules change or the Data Protection Board issues guidance, we ship updates in days, not quarters. Customers receive rule changes via in-place hot-patch — no scheduled maintenance windows.

The 11 capability modules

Every DPDP control, one workspace

All eleven modules ship in every deployment. You enable the ones you need now and turn the others on later as your programme matures.

Under the hood

The technical stack

No black boxes. Here's exactly what runs the platform — and yes, your security team is welcome to ask follow-up questions.

LayerTechnologyPurpose
FrontendReact + TypeScript + ViteOperator-facing application UI
APIFastAPI (Python 3.11+)REST API + business logic
Data storeElasticsearchDocuments, audit logs, analytics
AuthUsername + password + TOTP MFA, HMAC-SHA256 sessionsIdentity and session management
EncryptionAES-256 at rest, TLS 1.2+ in transit, Cloud KMS for keysData protection
AuditHash-chained ledger (SHA-256)Tamper-evident audit trail
DeploymentDocker + Kubernetes (GKE/EKS/AKS)Container orchestration
ObservabilityOpenTelemetry, vendor-agnosticMetrics, traces, logs

Deployment

Three ways to run AutoCops

Same software, three operational models. Pick the one that fits your security and ops posture.

Recommended for Indian enterprises

Self-hosted on your GCP

  • Deployed to your own GCP project in asia-south1
  • Your KMS keys, your VPC, your IAM
  • No shared multi-tenant cluster
  • Full data residency in India
  • Operated by your team, supported by ours

Recommended for SMBs and growing teams

Managed single-tenant

  • Dedicated AutoCops-hosted instance just for you
  • Single-tenant database, single-tenant compute
  • All data still in asia-south1 (Mumbai)
  • Operated and supported by AutoCops
  • Faster to set up than self-hosted

For air-gapped environments

On-premises

  • Deployed to your own data centre or private cloud
  • Air-gap support — no outbound calls required
  • Manual update channel (no automatic updates)
  • All data physically on-premises
  • Audited by your own team

Integrations

Connects to what you already run

AutoCops connects to the systems your team is already using. For anything that isn't natively supported, the generic REST/GraphQL connector handles it.

Databases

PostgreSQLMSSQLOracleMongoDBElasticsearch

Identity

Active DirectoryOktaGoogle WorkspaceMicrosoft Entra ID

CRM

HubSpotSalesforceZohoPipedrive

Communications

Email (SMTP)SMS gatewaysWebhooksWhatsApp Business API

Storage

GCSS3Azure BlobLocal filesystem

Generic

REST APIGraphQLCSV importManual operator workflow

Security architecture

The full security story is in the Trust Center

Encryption at rest and in transit, hash-chained audit ledger, MFA-mandatory authentication, network isolation, quarterly pen tests, ISO 27001 certification in progress, SOC 2 Type II audit scheduled — and the full sub-processor list. Read the long-form version below.

See it on your data

Book a 30-minute platform walkthrough

Our compliance engineering team will demo any module live on your environment. Bring your security questions — we like the technical ones.