Data source: live Supabase (50 consent artifacts)
Live read from the Supabase `certinal` schema.
DPDP Compliance Overview
50 consent artifacts captured across 4 languages, read live from Supabase.
Recent consent artifacts
View full registry →| Patient | Purpose | Decision | Modality | Lang | Assurance | Hash | Captured |
|---|---|---|---|---|---|---|---|
| Priya S*** | Share prescription with pharmacy | granted | inline form | EN | L1 · Mobile OTP | 0371a7e1…1c36 | 1 May, 03:13 pm |
| Priya S*** | Medicine order & dispensing | granted | inline form | EN | L1 · Mobile OTP | e4684441…758b | 1 May, 03:13 pm |
| Priya S*** | Share address with courier partner | granted | inline form | EN | L1 · Mobile OTP | 083e9f4b…057d | 1 May, 03:13 pm |
| Priya S*** | Treatment | granted | inline form | EN | L1 · Mobile OTP | 9c68a11e…a3c3 | 1 May, 03:12 pm |
| Priya S*** | Lab test referral | granted | inline form | EN | L1 · Mobile OTP | c17e9b34…14b1 | 1 May, 03:12 pm |
| Priya S*** | Share prescription with pharmacy | granted | inline form | EN | L1 · Mobile OTP | 77633bee…89cb | 1 May, 03:12 pm |
| Priya S*** | Recording of consultation | granted | inline form | EN | L1 · Mobile OTP | 5f3c9f6a…3138 | 1 May, 03:12 pm |
| Priya S*** | Health tips & seasonal alerts | granted | web self serve | EN | L1 · Mobile OTP | 01020304…1f20 | 30 Apr, 03:08 pm |
DPDP readiness · 49% - how it is computed
Weighted controls, recomputed from the registry on every load. 0/25 sampled signatures re-verified cryptographically just now (11 of the sample carry seed placeholders, not pipeline signatures).27 of 40 granted artifacts have a recorded identity method at or above the purpose's required assurance level.
50 of 50 artifacts record the capture language; 13 of 13 purposes declare a retention period.
Hindi/Tamil/Telugu consent copy in this prototype is machine-translated - production requires certified translations reviewed by counsel.
4 of 21 granted high-risk artifacts carry a teach-back score.
0 of 25 sampled signatures re-verified with HMAC-SHA256 constant-time compare at page render. 11 carry a seed placeholder rather than a pipeline signature, so there is nothing to verify - not a tamper detection. 14 carry a well-formed HMAC that does not match this deployment's signing key.
Signing uses the public demo HMAC secret (mock mode). Production requires per-hospital asymmetric PKI (P-256 ECDSA, public key published on the hospital record). This prototype signs with symmetric HMAC-SHA256 only. Control capped at 60%.
Withdrawal endpoint is implemented and audit-logged, but no withdrawal has been exercised in this dataset yet (scored 70%).
1 open incident; 1 past the 72h intimation deadline without DPB notification.
Breach-drill cadence is not tracked in this prototype and is excluded from the score.
No control can claim a capability the codebase does not have: demo-key signing and heuristic-graded teach-backs are capped and labeled above.
Consent volume by language
Decisions by purpose
System health · honest mode report
Each light is derived from getSystemStatus() - never asserted. Hover any tile for the full detail.
Production requires per-hospital asymmetric PKI (P-256 ECDSA, public key published on the hospital record). This prototype signs with symmetric HMAC-SHA256 only.