Flow blueprint
Audit & DPDP evidence
Every event lands in one log, then fans out to export, feed, SIEM and the DPDP workflow. Tamper with a delivery and watch it fail.
Simulator Audit & DPDP evidence
1 · Trigger an event
2 · Change the conditions
Ready. Pick an event.
Example event: Export the quarter
- Sign-ins login.success
- Admin changes role.changed
- Provisioning scim.user.*
- Audit log one timeline
- Export CSV, by range
- Live feed watch it happen
- Your SIEM webhook or HEC
- DPDP workflow consent, grievance
- The person data principal
sign-ins, admin changes and provisioning in one timeline $ audit export --from 2026-07-01 --to 2026-09-30 --format csv rows: 18,402 ✓ audit.exported
- Export the quarter auditor, July to September
- Stream to the SIEM every event, as it happens
- Watch the live feed during an incident
- A person asks for their data DPDP access request
- A grievance is raised from an employee
All output on this page is simulated, with made-up names and values. Keys 1 to 5 run the events.
What you need
An auditor role named
Reads the log, changes nothing.
A SIEM endpoint
Webhook receiver or Splunk HEC.
Signature check in your receiver
HMAC-SHA256 over "<t>.<body>".
A grievance owner
Someone who answers requests.
Your own counsel
Check what DPDP and your sector require.
AuthMantra helps you produce evidence. What a law or regulator expects is a question for your own counsel.
Try Audit & DPDP evidence on your own people
Free for up to 10 people. Or book a consultation and we will walk through your setup.