Where the guarantee lives
Auditability and erasure are both product features, by design. Every conversation the agent handles is recorded, decision by decision. Every sensitive action your team takes is written to a log the application can only append to — the database role cannot update or delete it — with every entry linked to the one before it, and deliberately not sealed against the erasure the DPDP Act requires. Actions we take on your account, and actions the system takes on its own, land in a separate tamper-evident ledger. And every erasure request is itself recorded on its own compliance log — requested, due, executed and by whom — a record that survives the erasure with the person's identity removed.
Two action ledgers · one compliance log · built under India's DPDP ActNo clock ever scrubs. An erasure waits out its grace window and then a person executes it — and an outstanding balance or an open order blocks it, at the request and again at the execution.
What that means for you
Actions we take on your account are recorded in a tamper-evident ledger held by the platform; your own team's actions on every order are in your console's history. An erasure can be asked for and carried out, and the asking and the carrying out both leave a record.
Tamper-evident means an alteration becomes visible, not that it becomes impossible. On a machine where someone holds the keys, detection is the honest limit — and we would rather say so than claim otherwise.
Privacy, consent and deletion →