The governance surface, in full.
Consent is where most tools stop, and it is roughly a quarter of the actual obligation. This is the whole surface Shastra is being built to cover.
Visibility first.
You cannot govern data you cannot see, which is why discovery comes before policy.
Data inventory
A live record of what personal data exists and where it lives.
Discovery
Finding personal data across connected systems rather than relying on memory.
Purpose mapping
Why each category of data is held, tied to a stated purpose.
Flow visibility
Where data moves: internally, to vendors, across borders.
Policy that lives in the system.
Consent lifecycle
Granular, per-purpose consent with history and withdrawal that is as easy as granting.
Consent notices
Notices generated from the purposes actually configured, not written separately.
Retention & deletion
Retention periods expressed as policy rather than as a reminder in somebody’s calendar.
Sharing controls
Which third parties receive what, under which basis.
The work that has deadlines.
Data principal rights
Access, correction and erasure requests with owners and statutory clocks.
Breach workflow
Incident capture against the notification deadline, with the record built as you go.
Vendor register
Every processor that touches personal data, and whether the paperwork exists.
Documentation
Processing records and privacy notices derived from configured reality.
Evidence as a by-product.
An evidence chain runs from request, to identity, to data, to purpose, to policy, to decision, to a stored record.
Scope, stated honestly.
Shastra is in pre-registration. Everything on this page is what the platform is being built to do, not a feature list you can use today.
More detail
When capabilities ship, this page will change tense and the product status in the header will change with it.
Shastra is pre-launch.
Pre-registration is open, and no pricing is published while the product is still being built.
Related: the DPDP Act explained · the Compliance Copilot