Kestryl · Cockpit for USA

Know where personal data travels. Show how each decision was carried through.

Kestryl Cockpit for USA brings state-level privacy work into one operating view. Locate personal data across the systems in scope, follow requests and opt-outs into known copies, and assemble evidence your legal and leadership teams can review.

GENERALLY AVAILABLE · FIFTY-STATE VIEW · TEN PRIVACY CONTROL OUTCOMES

The business problem

A decision at the source is not the end of the work.

A customer record can sit in a CRM, a warehouse, a marketing platform, and a shared document. Changing it in one place does not establish what happened in the others. The leadership question is not simply whether a request was closed, but whether the organization can explain the scope of its answer.

Kestryl Cockpit for USA puts that follow-through in one place: the state associated with a record, the requirement approved by counsel, the person responsible, the action taken, and the evidence still missing.

What you get

Three outcomes worth taking to the board.

i

See exposure by state

Bring records, sensitive categories, open requests, and unresolved state assignments into one view. The basis for each assignment stays visible; uncertainty is not presented as certainty.

ii

Follow decisions into copies

Trace requests and recorded opt-outs across the downstream relationships in scope. Show where follow-through is evidenced and where a copy still needs attention.

iii

Keep a reviewable record

Bring decisions, approvals, actions, and open issues together by run, request, state, or matter. Give counsel a record to assess rather than a status color to interpret.

The operating journey

DiscoverReviewApproveAct where supportedCheck known copiesEvidence

Coverage

Start with the systems your business already uses.

Connect Salesforce and nine other enterprise systems through Informatica IDMC, with attachment retrieval bringing supported documents into scope alongside the records that reference them. Agree the sources, access permissions, and document relationships before making a coverage claim.

SalesforceCustomer relationships
SAP S/4HANA / ECCEnterprise operations
SAP SuccessFactorsPeople and HR
SAP AribaSuppliers and purchasing
Oracle E-Business SuiteEnterprise operations
Oracle NetSuiteFinance and operations
Microsoft Dynamics 365Customer and business operations
ServiceNowService workflows
WorkdayPeople and finance
SharePoint OnlineShared business documents

Connection capability is not automatic access to every field or attachment. Coverage depends on the permissions, extraction scope, and relationships established for your deployment.

For the public U.S. enforcement baseline, the evidence library contains 50 state entries, 132 verified cases, and 132 official source URLs. Review the U.S. Privacy Enforcement Evidence before setting the operating scope.

The operating brief

Ten outcomes. Named ownership. Visible exceptions.

The cockpit connects privacy work that would otherwise be spread across teams. Each outcome has a defined scope and a visible boundary, so leadership can distinguish completed work from a decision still required.

No.Business outcomeWhat the cockpit brings together
01Know what you holdInventory personal data in the connected systems and documents within scope.
02Find sensitive dataBring candidate sensitive categories and potential minors’ records into human review.
03Track known copiesFollow the downstream relationships your team supplies or imports from its data catalog.
04Scope a rights requestLocate records and linked documents using the identifiers provided for the individual.
05Check deletion follow-throughCompare system-of-record confirmations with follow-up findings across known copies.
06Check opt-out follow-throughCompare recorded preferences with permissions still present in downstream data.
07Understand provenanceRecord marketing sources, vendor relationships, and customer-declared broker status.
08Scope an incidentOrganize affected records by state and category to support the response team.
09Make retention accountableAssociate retention decisions with a purpose, an owner, a review date, and exceptions.
10Assemble reviewable evidenceBring findings, decisions, actions, and outstanding issues together by state or matter.

These are product outcomes, not ten legal certifications. Customer counsel determines applicability, required deadlines, exceptions, and whether the evidence is sufficient.

Approved action

Protect the value. Preserve the decision.

Discovery is the starting point. Action follows review, a recorded approval, and the applicable hold checks. Choose the treatment that fits the approved purpose.

i

Mask

Replace an approved value with a protected representation in the working data or supported document copy.

ii

Vault

Replace the value while retaining an encrypted original for authorized restoration. Recovery depends on the key and the retained vault record.

iii

Strip

Remove the approved value from the working output without a vault-based recovery path. This is not erasure from every source or backup.

Mask, Vault, and Strip apply to approved structured working data and supported document copies. The document scope includes Word, Excel, PowerPoint, OpenDocument, email, archives, and supported text and data formats, subject to the limits of each format.

Supported document actions produce a separate cleansed copy. Original files are not overwritten. PDFs, scanned pages, images, and legacy Word .doc files remain discovery-only; audio and video handling is limited to supported metadata and tags.

What changed, and where
A cleansed document copy is not an erased original. Actions in the source business system remain a separate step, with separate confirmation and follow-up review. Read Kestryl’s data-handling boundaries.

Control

Legal judgment stays with the people accountable for it.

  • State contextRecord the basis for assigning a state and keep unresolved records visible. An address or phone signal informs review; it does not decide legal applicability.
  • Current rulesUse cited, counsel-approved legal settings. Preserve the version used for each request and evidence pack when those settings change.
  • Known copiesUse relationships declared by your team or imported from the available data catalog. The scanner does not independently discover every downstream copy.
  • Human reviewTreat sensitive-category and age inferences as candidates. Consent status comes from your consent system, not from a detected pattern.
  • Clear authorityYour team approves actions, manages holds, determines reportability, and sends notices. The cockpit coordinates the record and supports review.

Deploy with purpose

Begin with a business question, not another dashboard.

Choose the sources, the requests or obligations you need to manage, and the evidence your reviewers expect to receive. Establish that scope with your privacy, security, and data leaders, then expand the operating model as additional systems are brought under control.

Why Pacific Data Integrators

Put the integration and the evidence in the same conversation.

Kestryl Cockpit for USA combines Informatica-based data integration with Kestryl discovery, approved action, and evidence workflows. Where Salesforce is in scope, Salesforce Privacy Center remains part of the source-system process; the cockpit brings its confirmations into the wider review.

For organizations operating in both regions, the USA and DPDP cockpits belong to the same product family. Their legal settings and regional workflows remain distinct.

FAQ

Questions a buyer should ask.

Is Kestryl Cockpit for USA available today?

Yes. Kestryl Cockpit for USA is generally available. Deployment planning confirms the source systems, document access, state-law settings, approved actions, and evidence requirements for your organization.

Does a fifty-state view mean every law applies to our business?

No. It is an operating view, not a legal determination. The cockpit records the basis for associating records with a state and keeps unresolved records visible. Your counsel decides which requirements apply, including exceptions and holds.

Can it act on records and documents?

Yes. Approved Mask, Vault, and Strip actions cover structured working data and supported document copies. Word, Excel, PowerPoint, OpenDocument, email, archives, and supported text and data formats are in scope, subject to format limits. PDFs, scanned pages, images, and legacy .doc files are discovery-only. Originals are not overwritten.

Does a cockpit action remove data from the original business system?

Not by itself. The USA workflow acts on approved working data and supported document copies. Deletion or correction in Salesforce or another source system must be executed there and verified separately. Source files, backups, and unknown copies are not erased by a cockpit action.

Does the cockpit receive opt-out signals or send breach notices?

No. Your consent tools receive signals and maintain consent status; the cockpit checks the recorded result across known copies. Your incident team and counsel decide reportability and send notices. The cockpit organizes the affected scope, deadlines, and supporting evidence.

Can the cockpit guarantee compliance?

No. It helps your teams organize work and evidence across the systems in scope. Legal applicability, the adequacy of controls, approval of actions, and acceptance of the evidence remain with the customer, counsel, and the relevant reviewing authorities.