Most platforms tell you a column contains an Aadhaar number. Vaultdef tells you how it knows.
The evidence ladder
Every classification records which of three tests applied, so a reviewer can see which verdicts to trust and which to check.
Rung 1
The number's own arithmetic clears — Aadhaar, GSTIN, payment card. The value proves itself.
Aadhaar,ConfidenceCustomer Aadhaar,Rung 2
The structure is correct and the column name corroborates it — PAN, IFSC, UPI VPA, voter ID, driving licence, vehicle registration, email, telephone.
PANFormat validCustomer PANRung 3
The heading suggests personal data and no sampled value confirmed it. Shown to the reviewer, and deliberately not escalated to "sensitive" on the strength of a heading.
Aadhaar, noSample matchSensitiveA reviewer sees the rung, not just the label — so a checksum-cleared Aadhaar and a suggestively named column are never presented with the same confidence.
Built for this law
Not positioning — behaviour. Each of these is something you can watch happen in the working demo. Rest on a line to open it.
The road to May 2027
From a fundamental right to dated obligations. Rest on a milestone for the detail. Orientation, not legal advice — the Act, explained →
Puttaswamy: the Supreme Court holds privacy a fundamental right.
Nine judges, unanimous. K.S. Puttaswamy v. Union of India reads privacy into Article 21 — the constitutional floor every later statute stands on.
The DPDP Act 2023 receives assent — India's first comprehensive data-protection law.
Assented 11 August 2023 after six years of drafts: consent-first duties for Data Fiduciaries, rights for Data Principals, and a Board to enforce both.
The draft DPDP Rules are published for public consultation.
Published 3 January 2025 — notice formats, breach timelines, children's verification and Consent Manager obligations take concrete shape.
The DPDP Rules 2025 are notified on 13 November; the clocks start.
The Board can act from day one. The phased clocks — 12 months for Consent Managers, 18 for the substantive duties — all start together.
Rule 4 takes effect: the registered Consent Manager framework switches on from 13 November 2026.
From this date fiduciaries must accept, signature-verify and honour decisions arriving through any Board-registered Consent Manager.
Notice, consent, safeguards, breach reporting and rights obligations bind every fiduciary from 13 May 2027.
Enforceable end to end, with Schedule penalties reaching ₹250 crore per instance. What remains of the runway is the project plan.
Why we
The Act reaches any company that processes the digital personal data of people in India. Orientation, not legal advice.
If you process the digital personal data of people in India — customers, employees or candidates — you are a Data Fiduciary. The duties attach to the processing, not to the size of the company.
The Act's Schedule provides penalties that reach ₹250 crore per instance for failing to take reasonable security safeguards — set to change behaviour, not to be absorbed as a cost.
Breach notice owed to the Board and to every affected individual, rights requests answered on statutory time, and a six-hour CERT-In window sitting alongside the Act.
When the Board asks, a policy document is not an answer. What survives is a record — signed receipts, ledger entries, certified electronic records.