AI data governance · DPDP-native · Aegix AI Private Limited
Hansa Shield is a governance layer that sits in front of any AI model. It makes every use of personal data by AI lawful, minimized and provable — so your organisation can put AI to work and demonstrate, at every step, that it did so within the law.
The problem
Claims, underwriting, diagnoses, KYC and customer support increasingly run through AI models. The moment personal data enters a prompt, three obligations go unmet — and existing tools do not close the gap. Security tools block or redact but understand nothing about consent. Consent platforms manage the paperwork but never see the AI call.
Nothing verifies that the person agreed to this particular use of their data before the model sees it.
Whole records are pasted into prompts when a fraction of the data would have done the job.
When a regulator asks what happened, "we think we complied" is not evidence.
Gartner predicts that by 2027, more than 40% of AI-related data breaches will stem from the improper use of generative AI.
Gartner, 2025
Under the DPDP Act, the liability sits with your organisation — not with the AI vendor — with penalties of up to ₹250 crore.
How it works
Your application changes one setting: instead of calling the model directly, it calls Hansa Shield. Everything else stays as it is.
The request is received inline, before it reaches the model.
The purpose of the call is matched against the consent the person gave.
Indian identifiers and personal data are found and replaced. Raw data stays in memory.
A tamper-evident entry is written: what was found, what was masked, under which policy.
How Hansa Shield helps you meet your DPDP obligations
Across the AI layer, where the law now bites hardest.
Personal data is used by the AI only for the purpose the person consented to — purpose limitation, enforced on every call.
DPDP Act · Sections 5 & 6Personal data is masked before the model ever sees it, and raw data is never stored — only the masked version leaves your boundary.
DPDP Act · Section 8A tamper-evident, independently verifiable record of every AI decision — the proof you need if a breach must be reported or the Board asks.
DPDP Act · Section 8The assessment and audit evidence larger data-handlers are required to maintain, generated automatically and ready to show.
DPDP Act · Section 10Why Hansa Shield
Aadhaar, PAN, ABHA, GSTIN, UPI and voter ID recognised properly — format, checksum and context — rather than retrofitted from tools built for other jurisdictions.
A hash-chained ledger that an independent third party can verify, rather than a log file you are asked to take on trust.
Devanagari and other Indian scripts, Hinglish and code-mixed text — the cases where general-purpose detection quietly fails.
Deploy on-premises or in your own cloud, with India data residency. Raw personal data never leaves your network.
Where we are
We would rather tell you exactly where this stands than oversell it. If you are an insurer, hospital, bank or fintech thinking about DPDP and AI, we would like to talk — and we are looking for a small number of design partners.
Get in touch
Tell us how AI is being used in your organisation today, and we will tell you honestly whether we can help.