MVP and roadmap
The MVP closes one full operating loop for a bank/fintech pilot. It is not a set of mock screens.
Now — 30-day research/documentation milestone
Section titled “Now — 30-day research/documentation milestone”| ID | MoSCoW | Outcome | Complexity |
|---|---|---|---|
| R-001 | Must | verified DPDP ledger, corrigendum diff and open-notification watch | M |
| R-002 | Must | banking/fintech source and retention conflict review | L |
| R-003 | Must | signed schema for legal configuration/controls | M |
| R-004 | Must | threat model, API, data and connector contracts reviewed | L |
| R-005 | Should | two pilot discovery interviews per target segment | M |
Critical path: authoritative sources → data/control schema → customer applicability → workflow/API implementation → connector/evidence tests.
Next — 90-day engineering MVP
Section titled “Next — 90-day engineering MVP”Must:
- tenant/entity/role onboarding with OIDC, MFA and maker-checker;
- applicability registry with curated DPDP + banking/fintech pack;
- purpose/notice/version management;
- consent grant/deny/withdraw REST API and generic signed webhook;
- Principal rights/grievance portal with existing-account identity and manual fallback;
- retention rules, holds and manual/API deletion tasks;
- breach case with independent DPDP/CERT-In/customer clocks;
- processor/vendor/contract/subprocessor register;
- append-only audit/evidence and signed export manifest;
- PostgreSQL metadata connector plus generic webhook/task adapter;
- Docker Compose evaluation and secure Kubernetes pilot deployment.
Should: English plus one translation workflow, SAML, SCIM dry-run, Jira/ServiceNow task adapter, SIEM intake. Could: mobile SDK alpha, evidence WORM export. Won’t in MVP: statutory Consent Manager operations, automated erasure queries, all sector packs, air-gapped production.
Six-month enterprise pilot
Section titled “Six-month enterprise pilot”Two design partners; one regulated finance and one SaaS/ITES or healthcare organisation. Add dedicated/VPC deployment, SAML/SCIM, KMS, backup/restore, two customer system connectors, translation, vendor evidence room, policy simulation, independent penetration test and accessibility audit. Exit criteria:
- more than 95% synthetic end-to-end task completion inside pilot SLO;
- no critical/high unresolved security issue;
- restore plus tombstone replay proven;
- every pilot control has owner/evidence/exception;
- customer can export and exit without vendor intervention beyond documented support.
Twelve-month production
Section titled “Twelve-month production”Managed SaaS and customer VPC GA; on-prem Kubernetes supported; LTS policy; signed/SBOM releases; banking and SaaS packs verified, insurance/health beta; partner implementation kit; audited security programme; upgrade/rollback and schema migration proven; connector SDK with capability permissions.
Separate Consent Manager track
Section titled “Separate Consent Manager track”CM-01 legal-entity/governance readiness (Now); CM-02 monitor Board standards and application
(13 Nov 2026 gate); CM-03 no-read routing prototype (Next); CM-04 independent certification
only against published standards; CM-05 production registration and operational launch only
after Board approval. Kill the statutory track if conflicts, capital/governance or missing standards
make independent operation non-viable; enterprise consent tooling continues.
Roadmap item contract
Section titled “Roadmap item contract”Each backlog item contains ID, problem, persona, legal/control mapping, scope, non-goals,
dependencies, UX, data/API/events, security/privacy, Given/When/Then acceptance, evidence, metrics,
rollout/migration and S|M|L|XL.
MVP epics
Section titled “MVP epics”| ID | Problem/persona | Scope and dependencies | Acceptance/evidence | Size |
|---|---|---|---|---|
| MVP-01 | secure tenant for owner | OIDC/MFA/entity/roles; platform auth | cross-tenant tests; approval log | L |
| MVP-02 | approved applicability for legal | DPDP + finance pack; source schema | signed version and diff | L |
| MVP-03 | notice/purpose for privacy | versions/review/publish | unknown version rejected; hash | L |
| MVP-04 | proof/withdrawal for developer/Principal | API, receipt, webhook retry | idempotent partial reconciliation | XL |
| MVP-05 | requests/grievance for DPO | portal, identity, tasks/messages | no auto-refusal; case pack | XL |
| MVP-06 | retention for records owner | rules/hold/manual deletion | partial certificate honest | L |
| MVP-07 | breach for commander | clocks/templates/timeline | severity cannot reset clock | L |
| MVP-08 | processors for vendor owner | register/contracts/subprocessors | country change reopens review | M |
| MVP-09 | evidence for auditor | audit events/manifest/export | tamper test fails closed | L |
| MVP-10 | connectors for system owner | PostgreSQL metadata + generic task | no sample crosses boundary | XL |
| MVP-11 | finance sector pack | sources/config/tests | entity class required | L |
| MVP-12 | self-hosting for CISO | Compose/K8s/KMS/backup | restore and isolation test | XL |
Staffing estimates
Section titled “Staffing estimates”Ranges are planning estimates, not commitments: product 1–2; India privacy counsel/research 1–2; privacy/security architect 1; backend 3–5; frontend 2–3; connector/platform 2–3; SRE 1–2; QA/ security automation 2; content/accessibility 1; developer relations/community 1; sector SMEs fractional. A 90-day MVP is roughly 10–15 cross-functional FTE with design partners and counsel.
Major risks and kill criteria
Section titled “Major risks and kill criteria”| Risk | Mitigation | Kill/pause criterion |
|---|---|---|
| law/standards change | signed versioned config | cannot identify active source/effective date |
| integration sprawl | two adapters + local agent | raw PII must centralise for core workflow |
| false compliance claims | claims policy/review | sales cannot accept boundary |
| weak tenant isolation | negative tests/per-tenant keys | unresolved cross-tenant finding |
| sector conflict | deep packs/counsel | no customer can approve retention/incident map |
| CM conflicts/standards | separate track/entity | no credible registration/certification path |
| enterprise procurement | Apache core, secure self-host | no design partner can pass security review |
Not planned
Section titled “Not planned”Compliance certification, penalty prediction, automated legal refusal, biometric identity vault, adtech identity graph, covert monitoring, blockchain ledger, unlimited connector catalogue before SDK maturity and source-available licensing presented as open source.