Configured personal-data patterns
Aadhaar, PAN, government identifiers, financial identifiers, contact information, credentials and other approved patterns can be included without displaying an actual personal-data value.
Kestryl Cockpit · How it works · Powered by Kestryl PIIScan
Enterprise sources feed a customer-controlled extraction scope. Kestryl PIIScan discovers and validates personal-data findings and executes supported remediation. The Cockpit turns those findings into review, ownership, approval, DPDP operations and operating evidence.
What powers the Cockpit
Kestryl PIIScan identifies personal-data patterns across structured enterprise records and supported documents and attachments. Detection rules can recognise defined personal-data fingerprints and formats, providing the data reality that feeds the Cockpit’s review, ownership, remediation and evidence workflows.
Aadhaar, PAN, government identifiers, financial identifiers, contact information, credentials and other approved patterns can be included without displaying an actual personal-data value.
Validators, confidence controls and deterministic fingerprints make the detection context reviewable and repeatable.
Kestryl Cockpit governs extraction, review, approval and remediation workflows across structured data and documents. Kestryl executes supported field and document remediation, with role-separated approvals and an attributable evidence trail.
The operating distinction
Kestryl finds and acts on the data. The Cockpit governs the workflow.
Customer-controlled architecture
Enterprise sources feed a customer-controlled data and extraction scope. Kestryl PIIScan performs discovery, fingerprint detection, validation and supported remediation. Kestryl Cockpit for DPDP governs review, ownership, attestation, retention, requests, erasure, breach, remediation, evidence and responses. The resulting operating evidence records the finding, decision, owner, approval, action, exception, disposition and audit history.
Kestryl is designed to operate within the customer-controlled environment — on-premises, in the customer data center, or within the customer’s cloud environment. Source systems and sensitive source data remain within the customer’s security boundary while Kestryl performs discovery, review and governed actions against the approved scope.
Integrates with Salesforce Privacy Center or equivalent privacy platforms, depending on deployment, to exchange relevant consent, privacy and workflow evidence. Kestryl does not require Salesforce Privacy Center. Where another privacy or consent-management platform is in place, the deployment can integrate with the appropriate equivalent platform.
The product model
The executive journey
Each stage preserves the operating context that came before it. A finding carries its fingerprint and source context into review; a decision carries its reviewer and reason into approval; an approved action carries its owner, execution status, exception and disposition into the evidence record.
Retention model
Source personal data remains within the customer-controlled environment. The Cockpit retains the evidence, decisions and disposition logs required for the operating record. Retention of those records is configurable.
Security-control support
Kestryl deployments are designed around encryption at rest and in transit, controlled access, audit logging and customer-controlled data handling. The deployment architecture is intended to support the evidence required for enterprise security-control review.
The Cockpit is designed to work from record identifiers, counts, decisions and evidence metadata rather than creating another unnecessary persistent repository of personal data.
See the cockpit on your own systems
A working session with privacy, security and data leaders maps the current scope, operating responsibilities and evidence gaps using representative data.