Getting Started

Introduction to Neostra

Neostra is a modular, multi-tenant privacy compliance platform that automates global regulations including India's DPDPA 2023, the EU's GDPR, and California's CCPA.

Overview

Neostra is a unified privacy compliance platform built to automate regulatory adherence across jurisdictions. It manages the full lifecycle of data subject requests, consent collection, data discovery, and compliance assessments from a single multi-tenant platform.

The system is built as a microservices architecture with Java/Spring Boot backends, Vue.js frontends, and a combination of MongoDB and PostgreSQL databases — deployed on Google Kubernetes Engine.

Platform Architecture

Neostra consists of 9 backend services, 2 frontend applications, and a CDN-hosted consent widget:

Technology Stack

LayerTechnology
BackendJava 17, Spring Boot 3.x, Python 3 (scanner)
FrontendVue 3, Vuetify 3, Pinia, TypeScript
Consent WidgetSvelte 5, Vite, UMD/ES modules
Primary DatabaseMongoDB 6+ (core platform, governance)
Event StorePostgreSQL 14+ (consent ledger, data discovery)
MessagingGoogle Cloud Pub/Sub
Object StorageGoogle Cloud Storage, AWS S3
AuthenticationJWT + BCrypt + TOTP 2FA
InfrastructureGoogle Kubernetes Engine, Docker, Cloud Build
PII DetectionMicrosoft Presidio, custom regex patterns
Cookie ScanningSelenium Grid + Chromium

Supported Regulations

India's Digital Personal Data Protection Act. Neostra provides a readiness scanner with compliance scoring, automated DSAR handling per DPDPA timelines, and consent management aligned with DPDPA requirements.

Privacy Rights by Regulation

Neostra maps data subject rights across all supported regulations, ensuring each right type is handled through the appropriate module and workflow.

RightDescriptionNeostra Module
AccessRight to obtain confirmation and summary of personal data being processedDSAR
CorrectionRight to correct inaccurate or misleading personal dataDSAR
ErasureRight to have personal data erased when no longer necessaryDSAR
Grievance RedressalRight to have grievances addressed by the Data FiduciaryDSAR + Governance
NominationRight to nominate another individual to exercise rights in case of death or incapacityDSAR
Revoke ConsentRight to withdraw consent with the same ease as it was givenConsent Management
Minors (Under 18)Verifiable parental consent required before processing children's dataConsent Management

Who Uses Neostra

Next Steps

Was this page helpful?

Last updated 1 week ago

Built with Documentation.AI