Privacy by architecture,
not by policy.
How Anshap protects what your people share with Noa, what leadership can and cannot see, and where your data lives.
How we earn the right to be in your employees' conversations.
DPDP Act 2023 native
Anshap is built to comply with India's Digital Personal Data Protection Act 2023. Consent, data principal rights, breach notification, and data fiduciary obligations are part of how the platform is engineered — not an afterthought.
Hosted in India by default
All conversational data, user records, and cohort analytics are stored within Indian data centres. No cross-border data transfer for default deployments. For multinational clients, regional residency options are configurable per cohort.
End-to-end at the architecture level
There is no pathway inside the product to attribute a cohort signal to a specific person. Cohort minimum thresholds are enforced before any reporting — smaller cohorts roll up to the next valid cohort. This is structural, not a setting.
RCI-reviewed framework
Every interaction pattern, escalation criterion, and clinical signal in Noa is reviewed against frameworks set by Rehabilitation Council of India registered psychologists. Our advisory practitioners review changes before deployment.
What stays personal. What becomes signal. Where the line is.
What a person says to Noa
- Raw conversation text
- Identifying metadata
- Step-up consent state
- Personal goals
- Emotional state details
WALL
What leadership sees
- Cohort risk index movement
- Theme density across groups
- Engagement trends
- Escalation demand patterns
- Care-path completion rates
The wall is enforced in code. There is no admin setting, no role, no internal tool that can attribute a cohort signal back to an individual. Audit logs are available to your DPO on request.
Where we are. Where we're going.
- DPDP Act 2023Compliant by architecture
- Data residency in IndiaAWS Mumbai region
- Cohort anonymisationMinimum-threshold enforcement
- RCI clinical reviewQuarterly cycle
- Audit loggingAvailable to client DPO
- ○ISO/IEC 27001Information security management
- ○SOC 2 Type IISecurity & availability controls
- ○HIPAA-aligned controlsFor US-deploying multinationals
- ○Penetration testingAnnual third-party engagement
- ○Bug bounty programmeCoordinated disclosure
Direct line to our DPO.
Security questionnaires, data processing addendums, audit log requests, breach disclosures, sub-processor lists — all handled directly. Response within 1 business day.