🛡️ Enterprise Data Intelligence — DPDP · GDPR · PDPA · UK GDPR · GCC PDPL

Mitrak Shield
PII Discovery That
Never Sleeps

Automate PII discovery, data misplacement detection & multi-jurisdiction compliance — DPDP India, GDPR Europe, UK GDPR, Singapore PDPA, and GCC PDPL. Built on 480+ ML algorithms. Not an audit. Not a consultant. An automation tool that runs 24/7 on your premises.

480+ ML Algorithms
5 Global Regulations
100% On-Premise
24 File Formats Parsed

Your Data Is Already Out of Control

Manual audits take weeks and miss 80% of misplaced data. Shield automates this — scanning continuously, not once a year.

📊

Sales Data with Finance Team

Revenue figures, customer pricing, and deal terms sitting in finance shared drives. Who approved this access?

📁

Balance Sheets with Sales Team

Confidential P&L, margin data, and financial projections accessible to sales reps who don't need them.

👤

Customer Data with HR

Customer Aadhaar, PAN, and bank details found in HR folders, onboarding drives, and training materials.

🏢

Vendor PII Everywhere

Vendor bank details, GST certificates, PAN copies scattered across procurement, accounts, and project folders.

₹250 Crore Fines Are Just the Beginning

RBI imposed 353 penalties totalling ₹54.78 Cr in FY2025 alone. Under DPDP, penalties go up to ₹250 Cr per violation.

Meta / WhatsApp

₹213 Cr

Privacy policy & data-sharing abuse

ICICI Bank

₹12 Cr

Multiple regulatory violations

Citibank

₹4 Cr

Compliance breaches

Kotak Mahindra Bank

₹4 Cr

Regulatory breaches

Reliance General Insurance

₹1 Cr

Unauthorized commission payouts

Bajaj Finance

PRODUCT BAN

eCOM & Insta EMI Card suspended by RBI

Beyond Fines — RBI Can:

Ban specific lending products
Impose complete lending freeze
Cancel NBFC license (CoR)
Place bank under supervision
Impose customer withdrawal limits
Force merger or acquisition
Remove CEO & board members
Initiate liquidation
Refer for CBI / ED investigation

The biggest fear for BFSI is NOT fines — it's lending bans, license cancellation, and business restrictions that destroy operations overnight.

One Platform. Five Jurisdictions.

Shield is built for global enterprises operating across India, Europe, UK, Singapore, and the GCC — with PII detection tuned to each region's regulatory requirements.

480+
ML Algorithms

Shield's PII detection engine is powered by 480+ purpose-built ML algorithms embedded directly inside each desktop agent. No cloud call. No API round-trip. Detection runs locally at machine speed — processing thousands of files per minute without ever exposing a single raw PII value. Every algorithm is tuned for a specific PII type, jurisdiction, and file format, combining regex pattern matching, structural validation (Verhoeff, Luhn, MOD-11), NLP entity recognition, and statistical anomaly detection.

Verhoeff Checksum Luhn Algorithm NLP Entity Recognition Context-Aware Classification Structural Validation Statistical Anomaly Detection OCR + Deep Scan Multi-Language Support
🇮🇳

India

DPDP Act 2023
  • Aadhaar (Verhoeff validated)
  • PAN, GSTIN, Passport
  • Bank Account & IFSC
  • UPI ID, Voter ID, DL
  • Biometric & Health data
  • EPF, ESI, CIN numbers
⚠ Penalty: Up to ₹250 Cr per violation
🇪🇺

Europe

GDPR
  • National ID numbers
  • IBAN & bank details
  • VAT / Tax IDs
  • Health & biometric data
  • IP addresses & cookies
  • Special category data
⚠ Penalty: Up to €20M or 4% global turnover
🇬🇧

United Kingdom

UK GDPR / DPA 2018
  • National Insurance No.
  • UK passport & driving licence
  • Bank sort code & account
  • NHS numbers
  • Racial & political data
  • Criminal record data
⚠ Penalty: Up to £17.5M or 4% global turnover
🇸🇬

Singapore

PDPA 2012 (Amended 2021)
  • NRIC / FIN numbers
  • Passport & work pass
  • Bank account & card data
  • Medical & health records
  • Contact & address info
  • Biometric identifiers
⚠ Penalty: Up to S$1M per breach
🌍

GCC / UAE / KSA

PDPL · UAE PDPL · DIFC
  • Emirates ID / Iqama
  • Passport & visa numbers
  • IBAN & bank details
  • Health & medical data
  • Biometric data
  • Trade licence numbers
⚠ Penalty: Up to AED 5M (UAE) / SAR 5M (KSA)

Whether your enterprise operates from Mumbai or Dubai, serves customers in London or Singapore, or processes data under multiple frameworks simultaneously — Shield's agent adapts its PII detection ruleset to the jurisdiction of your choice, without any additional configuration or cloud connectivity.

We Don't Just Find PII. We Put a Process in Place.

Shield automates the entire DPDP compliance lifecycle — discover, classify, prioritize, assign, track, escalate, and audit.

1

Scan

Auto-detect PII across all files

2

Classify

40+ types mapped to DPDP tiers

3

Check

Right data in right folders?

4

Notify

Grouped alerts, not 200 emails

5

Survey

Employee action with deadlines

6

Escalate

Auto-escalation + audit trail

Shield runs silently at 0.1% CPU. No manual file selection. No spreadsheet tracking. No weekly audit meetings. Your compliance team gets a dashboard — not a workload.

Three Modules. One Platform.

Automated. Continuous. Not a consultant.

Module 1

Shield Discovery

PII Detection & DPDP Mapping

480+ ML algorithms embedded in every agent for PII detection — Verhoeff checksum, Luhn validation, NLP entity recognition, and structural pattern matching. Covers 40+ Indian PII types plus GDPR, UK GDPR, Singapore PDPA, and GCC PDPL data classes. Scans 24 file formats deep inside every cell, paragraph, and attachment. DPDP 5-tier priority classification (P1–P5).

Module 2

Shield Access Intelligence

Data Misplacement Detection

Finds data where it shouldn't be. Finance data in sales folders? Customer PII with HR? Balance sheets on shared drives? Shield flags every access violation with department mapping.

Folder Compliance Workflow

Smart Scanning → Grouped Alerts → Employee Surveys → Auto-Escalation

Compliance Check

After every scan, Shield checks each PII file against folder rules. Files inside designated folders are marked compliant with time-box tracking. Files outside trigger notifications.

Smart Grouped Alerts

Notifications grouped by category, not individual files. 200 Excel files with Aadhaar on Desktop? Admin sees ONE alert — not 200 separate emails.

Employee Survey

Admin sends unique survey link. Employee picks: "I moved it" (which folder?) | "I'll move later" (reason + deadline) | "Needs to stay" (business justification + expiry).

Smart Re-Scan Detection

If employee says "I moved it" but next scan finds the SAME file still there — a strict second survey triggers automatically. First time: friendly. Second time: escalated.

Escalation Engine

First offense — gentle reminder. Second — strict warning + admin alert. Repeated violations — compliance dashboard flag + management escalation. All automatic.

Complete Audit Trail

Every survey response stored: who responded, when, what action they chose, what reason, what deadline. Audit-ready evidence for DPDP compliance reviews.

Department-Based Misplacement Detection

Right data. Right department. Automatically enforced.

Department Owns This Data Violation Example
HR Aadhaar, PAN, Employee records, Salary, DOB Finance agent has Aadhaar files → VIOLATION
Finance Bank accounts, Credit cards, GST, Invoices, Balance sheets Sales agent has balance sheets → VIOLATION
Sales Customer emails, Mobile numbers, Addresses HR agent has customer database → VIOLATION
IT Employee IDs, System credentials, Access logs Sales agent has system credentials → VIOLATION
Legal Board resolutions, Contracts, Director PII Operations has board minutes → VIOLATION

40+ Indian PII Types — Plus Global GDPR, UK, PDPA & GCC Classes

P1

Critical

Aadhaar (Verhoeff validated), PAN, Bank Account, IFSC, UPI ID, Credit/Debit Card, Biometric

P2

High

Passport, Voter ID, Driving License, GSTIN, Health Records, Insurance Policy, ITR

P3

Moderate

Name+DOB, Email, Mobile, Address, Employee ID+Salary, CIN/DIN

P4

Low

Gender+Age, Caste/Religion, Vehicle Registration, Ration Card, Education, License Numbers

P5

Minimal

Standalone Names, Phone Numbers, Generic IDs, Public Information

24 File Formats: Excel, PDF, Word, CSV, TSV, Tally XML, SAP Exports, JSON, Emails (.eml/.msg), Text, Logs, PPTX, SQL, DB, ZIP, RAR, MBOX and more

Shield vs Everything Else

What Matters Manual Audit Global DLP Tools Cloud Scanners Mitrak Shield
Indian PII Coverage5-108-1510-2040+ types
Aadhaar ChecksumSome✓ Verhoeff
Data Misplacement Detection✓ Built-in
Vendor Compliance Check✓ Automated
100% On-PremiseMostly✗ Cloud✓ Always
DPDP + GDPR + PDPA MappingGDPR onlyPartial✓ All 5 Jurisdictions
Indian Formats (Tally/GST)Manual✓ Built-in
Time to First ScanWeeksWeeks-MonthsDays✓ Minutes
Daily Auto Scanning✓ Incremental
Typical CostHigh (team)Very HighPer-GB✓ Flat license

Runs Inside Your Infrastructure

Raw PII never leaves the employee's machine. Server runs as a sealed Docker container on YOUR infrastructure.

Desktop Agent scans all local drives, network & USB using read-only permissions. Only metadata (file names, PII types, counts) is transmitted via TLS 1.3 to the Shield Server running in a sealed Docker container. The Web Dashboard shows only aggregated scores — no individual PII values are ever displayed.

🔐

Zero PII Transmission

Raw data stays on agent

🇮🇳

India Data Residency

All servers in India

🐳

Docker Containerized

Sealed binary, no code access

🔒

AES-256 At Rest

DB encrypted on server

🔗

TLS 1.3 In Transit

All API calls encrypted

📖

Read-Only Agent

Never modifies source files

👥

Role-Based Access

Admin / DPO / Auditor levels

Two Ways to Deploy. Zero Excuses.

Agent-Based or Network-Based — you choose. Or use both together.

Option A

Agent-Based Scanning

Lightweight EXE installed on each machine. Scans locally using 0.1% CPU.

  • Full visibility — Desktop, Downloads, USB, personal folders
  • Works offline — queues results, sends when back online
  • 24 file formats — Excel, PDF, Word, CSV, emails, ZIP, SAP
  • Windows OCR — built-in for scanned PDFs
  • Silent deploy — push via GPO / SCCM / Intune
Best for: Laptops, desktops, remote/WFH machines, endpoints where misplaced PII hides in personal folders
Option B

Network-Based Scanning

No agent installed — scans remotely via WinRM. Zero install on endpoints.

  • Zero install — only WinRM enabled via GPO (one-time)
  • Code protected — PII detection runs on server, not endpoints
  • Batch scanning — 20-50 machines per batch, configurable threads
  • Off-hours mode — schedule scans at night, zero business impact
  • File servers too — scans NAS, shared drives, SharePoint directly
Best for: File servers, NAS, shared drives, kiosks, or when IT policy prohibits installing software on endpoints

Recommended: Hybrid Deployment

Agent on all laptops & desktops (catches personal folders, USB, offline work) + Network scan on file servers & NAS (no agent needed) = 100% coverage across your entire organization.

DPDP Act — 84% Coverage Built

19 Modules. 83 Gap Items. Shield covers Sections 4-16, Rules 17-21 of the DPDP Act.

70

Fully Built (84%)

7

Partially Built (9%)

6

Remaining (7%)

83

Total Gap Items

M1: Data Discovery

S.4, S.8

5/7

M2: Processing (RoPA)

S.4, S.8

5/5

M3: Privacy Notices

S.5

4/6

M4: Consent Capture

S.6

5/5

M5: Legitimate Use

S.7

3/3

M6: Rights Management

S.11-14

4/4

M7: Grievance Redressal

S.8(9)

3/3

M8: Security Safeguards

S.8(5)

2/5

M9: Breach Management

S.8(6)

4/5

M10: Children's Data

S.9

4/4

M11: Retention & Erasure

S.8(7)

3/3

M12: Cross-Border

S.16

5/5

M13: Vendor Governance

S.8(2)

4/5

M14: SDF / PIA

S.10

4/5

M15: Regulatory Proceedings

S.27-33

5/5

M16: Compliance Reporting

Rule 17

4/4

M17: Records & Archival

Rule 19

2/3

M18: Enforcement

Rule 20

3/4

M19: Appeals Management

Rule 21

3/4

Enterprise-Ready. Audit-Proven.

BFSI-Approved compliance and security certifications.

Completed

VAPT Certified

Vulnerability Assessment & Penetration Testing by CERT-In empanelled auditor

Completed

DPDP Self-Declaration

Privacy Impact Assessment. Zero data exfiltration. Zero cloud dependency.

Certified

Data Localization

100% on-premise processing. Zero offshore transmission. RBI/IRDAI compliant.

Completed

Secure SDLC

OWASP Top 10 compliant. Code review & dependency scanning documented.

Documented

BCP/DR Documented

Read-only guarantee. Scan state recovery. Graceful degradation.

Published

SBOM Published

Full dependency inventory. CVE scan completed. License compliance verified.

In Progress

ISO 27001

Information Security Management System Certification

Planned

SOC 2 Type II

Security, Availability, Confidentiality, Privacy. CPA-audited controls.

Trusted by 34+ Enterprise Clients

Client Revenue Tenure Industry / Detail
Muthoot Finance₹27,542 CrNewIndia's #1 gold NBFC. 5,000+ branches, 29 states.
Chambal Fertilisers₹16,800 CrNewK.K. Birla Group. Largest pvt urea plant.
MedPlus Health₹6,538 Cr2+ YrsIndia's 2nd largest pharmacy. 4,900+ stores.
Page Industries (Jockey)₹4,600 CrNewExclusive Jockey licensee India. 100,000+ retail outlets.
Apparel Group$3.5 Bn2+ YrsDubai HQ. 2,300+ stores, 85+ brands, 14 countries.
Bata India₹3,500 CrNewIndia's largest footwear retailer. 1,800+ stores.
USV Pharma₹3,000 Cr6 Mths#1 anti-diabetic. WHO-GMP & USFDA approved.
Sumitomo Chemical₹2,940 Cr6 MthsJapan's Sumitomo subsidiary. Crop protection.
Lux Industries₹2,873 Cr4 MthsIndia's largest innerwear. 700,000+ touchpoints.
VIP Industries₹2,190 Cr6 MthsAsia's #1 luggage maker. 9,000+ outlets.
Mafatlal Industries₹2,140 Cr6 Mths120-year textile legacy. BSE listed.
EIH (Oberoi Hotels)₹2,100 Cr1+ YrOberoi & Trident chains. 32 luxury hotels.
Safari Industries₹1,995 Cr2+ YrsLeading luggage brand. BSE/NSE.
Hero Cycles₹1,840 CrNewWorld's largest cycle maker. 70+ countries.
GM Modular₹1,750 CrNewIndia's #1 modular switches. Red Dot Award.
Silver Pumps₹1,610 Cr6 MthsIndia's largest pump plant. 10M units/yr.
Munjal Auto₹1,200 Cr3 MthsHero Group. Auto components for 2W/4W OEMs.
Keventer Agro₹1,080 Cr1.5+ YrsLargest dairy in East India. 125-yr legacy.
Aspire Systems₹1,020 CrNewGlobal IT services. 4,000+ employees.
V-Trans Logistics₹800 CrNewExpress logistics. Pan-India hub network.
Servify₹787 CrNewDevice lifecycle platform. Apple/Samsung partner.
Celio Fashion₹600 CrNewFrench menswear. 200+ stores India.
Nuberg Engineering₹580 CrNewGlobal EPC. 60+ chemical plants in 32+ countries.
Indian Terrain₹345 Cr3+ YrsPremium menswear. 200+ outlets.

Industries: Retail, Manufacturing, BFSI, Pharma, Logistics, E-commerce, Hospitality, Agriculture, EPC — across India, UAE, KSA & Kenya

Not a Replacement for Auditors

The Automation Layer That Makes Audits 10× Faster

100% Files Scanned

What EY/Deloitte do manually in 4-8 weeks with sample-based coverage (10-20% of files), Shield does automatically in minutes with 100% coverage — every cell, every page, every attachment.

Ready to Discover What's Hiding in Your Files?

Misplaced data. Hidden PII. Uncertified vendors. Shield finds them all — 100% on your premises. 15 minutes to set up.

[email protected] mitrak.ai CEO: Manzoor Ahmed