Trust · Security
PDPL compliance
The Personal Data Protection Law sets the rules for how personal data is collected, processed and stored. Edrak is designed so that work done on the platform stays inside those rules, wherever you operate.
Compliance cannot be a document you write after the fact. On Edrak, residency, purpose limits, masking and audit are properties of the platform, applied to every mission as it runs.
Obligation, met in the platform.
How the law's core requirements map to controls that are already part of how Edrak runs.
01
Residency
Data and inference run on infrastructure in the jurisdiction you designate. Transfers outside it happen only where the law permits and you approve.
02
Purpose limitation
Missions carry a defined objective. Retrieval and processing stay scoped to it, so personal data collected for one purpose is not quietly reused for another.
03
Minimization & masking
Masking applies before a model sees the data. People and agents retrieve only what their permissions allow, and only what the task needs.
04
Data subject rights
Access, correction and deletion requests need to find the data first. Foundry's indexed, permissioned record makes personal data locatable and actionable.
05
Retention
Retention windows are set per source and per classification. What expires is removed from retrieval, not just hidden from view.
06
Accountability
The immutable audit log records what was accessed, by whom, under which authority. When the regulator asks, the evidence is the record of the work itself.
Where it runs
Deployment options per engagement
- In-jurisdiction infrastructure
- Processing stays on infrastructure inside the jurisdiction you designate, for engagements that require it.
- In-boundary models
- Open-weight models run inside your boundary, so restricted personal data never reaches an external API.
- Sovereign & air-gapped
- Fully isolated deployment for government and regulated environments, on request.
Edrak provides the controls described here; legal responsibility for PDPL compliance rests with each organization as controller of its data. Alignment details are confirmed per engagement with your compliance team.
PDPL is one lens on the same posture.
The controls behind it — residency, permissions, masking, audit — are the platform's defaults.
Security overview →