Skip to content

MVP and roadmap

The MVP closes one full operating loop for a bank/fintech pilot. It is not a set of mock screens.

Now — 30-day research/documentation milestone

Section titled “Now — 30-day research/documentation milestone”
IDMoSCoWOutcomeComplexity
R-001Mustverified DPDP ledger, corrigendum diff and open-notification watchM
R-002Mustbanking/fintech source and retention conflict reviewL
R-003Mustsigned schema for legal configuration/controlsM
R-004Mustthreat model, API, data and connector contracts reviewedL
R-005Shouldtwo pilot discovery interviews per target segmentM

Critical path: authoritative sources → data/control schema → customer applicability → workflow/API implementation → connector/evidence tests.

Must:

  • tenant/entity/role onboarding with OIDC, MFA and maker-checker;
  • applicability registry with curated DPDP + banking/fintech pack;
  • purpose/notice/version management;
  • consent grant/deny/withdraw REST API and generic signed webhook;
  • Principal rights/grievance portal with existing-account identity and manual fallback;
  • retention rules, holds and manual/API deletion tasks;
  • breach case with independent DPDP/CERT-In/customer clocks;
  • processor/vendor/contract/subprocessor register;
  • append-only audit/evidence and signed export manifest;
  • PostgreSQL metadata connector plus generic webhook/task adapter;
  • Docker Compose evaluation and secure Kubernetes pilot deployment.

Should: English plus one translation workflow, SAML, SCIM dry-run, Jira/ServiceNow task adapter, SIEM intake. Could: mobile SDK alpha, evidence WORM export. Won’t in MVP: statutory Consent Manager operations, automated erasure queries, all sector packs, air-gapped production.

Two design partners; one regulated finance and one SaaS/ITES or healthcare organisation. Add dedicated/VPC deployment, SAML/SCIM, KMS, backup/restore, two customer system connectors, translation, vendor evidence room, policy simulation, independent penetration test and accessibility audit. Exit criteria:

  • more than 95% synthetic end-to-end task completion inside pilot SLO;
  • no critical/high unresolved security issue;
  • restore plus tombstone replay proven;
  • every pilot control has owner/evidence/exception;
  • customer can export and exit without vendor intervention beyond documented support.

Managed SaaS and customer VPC GA; on-prem Kubernetes supported; LTS policy; signed/SBOM releases; banking and SaaS packs verified, insurance/health beta; partner implementation kit; audited security programme; upgrade/rollback and schema migration proven; connector SDK with capability permissions.

CM-01 legal-entity/governance readiness (Now); CM-02 monitor Board standards and application (13 Nov 2026 gate); CM-03 no-read routing prototype (Next); CM-04 independent certification only against published standards; CM-05 production registration and operational launch only after Board approval. Kill the statutory track if conflicts, capital/governance or missing standards make independent operation non-viable; enterprise consent tooling continues.

Each backlog item contains ID, problem, persona, legal/control mapping, scope, non-goals, dependencies, UX, data/API/events, security/privacy, Given/When/Then acceptance, evidence, metrics, rollout/migration and S|M|L|XL.

IDProblem/personaScope and dependenciesAcceptance/evidenceSize
MVP-01secure tenant for ownerOIDC/MFA/entity/roles; platform authcross-tenant tests; approval logL
MVP-02approved applicability for legalDPDP + finance pack; source schemasigned version and diffL
MVP-03notice/purpose for privacyversions/review/publishunknown version rejected; hashL
MVP-04proof/withdrawal for developer/PrincipalAPI, receipt, webhook retryidempotent partial reconciliationXL
MVP-05requests/grievance for DPOportal, identity, tasks/messagesno auto-refusal; case packXL
MVP-06retention for records ownerrules/hold/manual deletionpartial certificate honestL
MVP-07breach for commanderclocks/templates/timelineseverity cannot reset clockL
MVP-08processors for vendor ownerregister/contracts/subprocessorscountry change reopens reviewM
MVP-09evidence for auditoraudit events/manifest/exporttamper test fails closedL
MVP-10connectors for system ownerPostgreSQL metadata + generic taskno sample crosses boundaryXL
MVP-11finance sector packsources/config/testsentity class requiredL
MVP-12self-hosting for CISOCompose/K8s/KMS/backuprestore and isolation testXL

Ranges are planning estimates, not commitments: product 1–2; India privacy counsel/research 1–2; privacy/security architect 1; backend 3–5; frontend 2–3; connector/platform 2–3; SRE 1–2; QA/ security automation 2; content/accessibility 1; developer relations/community 1; sector SMEs fractional. A 90-day MVP is roughly 10–15 cross-functional FTE with design partners and counsel.

RiskMitigationKill/pause criterion
law/standards changesigned versioned configcannot identify active source/effective date
integration sprawltwo adapters + local agentraw PII must centralise for core workflow
false compliance claimsclaims policy/reviewsales cannot accept boundary
weak tenant isolationnegative tests/per-tenant keysunresolved cross-tenant finding
sector conflictdeep packs/counselno customer can approve retention/incident map
CM conflicts/standardsseparate track/entityno credible registration/certification path
enterprise procurementApache core, secure self-hostno design partner can pass security review

Compliance certification, penalty prediction, automated legal refusal, biometric identity vault, adtech identity graph, covert monitoring, blockchain ledger, unlimited connector catalogue before SDK maturity and source-available licensing presented as open source.