Module 01 · Consent Management

Consent you can defend.

Regulators don't ask whether you showed a banner. They ask what was consented to, when, and under which notice. Neostra answers with a ledger, not a spreadsheet.

yourcompany.in
Capabilities

Everything consent requires.

DPDPA opt-in banner
Purpose-level, opt-in consent with granular choices, not a dark-pattern accept wall. IAB TCF v2.3 supported for ad-tech.
Cookie & tracker crawler
Scans your site, detects and classifies the cookies and scripts already running, before your users do.
Consent ledger
Every decision recorded to a SHA-256 hash-chained, tamper-evident ledger with 7-year retention.
Preference center
Users manage channels, purposes and languages themselves; withdrawals propagate automatically.
Consent analytics
Accept, reject and withdrawal rates by geography, brand and banner version.
Autoblocking SDK
A lightweight JS SDK that blocks non-consented scripts until a lawful choice is recorded.
The consent ledger

Tamper-evident by design.

Each consent record carries a SHA-256 hash of the one before it. Change any record and the chain breaks visibly. Seven-year retention, exportable for audit. Proof, not assertion.

Consent granted: marketing, analytics
record #48,201 · notice v2.4 · en-IN
prev: 0x8f2a → 0x93bc
Consent withdrawn: marketing
record #48,202 · preference center
prev: 0x93bc → 0x41d9
Notice updated: v2.5 published
record #48,203 · re-consent triggered
prev: 0x41d9 → 0xc7e1
How it works

Live in days, not quarters.

1
Crawl & classify
Point the crawler at your domains. It inventories every cookie and tracker and drafts your first notice.
2
Configure & brand
Set purposes, languages and look-and-feel from the dashboard, no code. Paste one script tag to go live.
3
Record & prove
Every choice lands in the ledger. Export the chain for auditors or the Data Protection Board at any time.
Next module: Privacy Rights (DSAR) →

Put a defensible banner live this week.