A privacy policy may say personal data can be deleted.
But:
- Can the organisation find every relevant copy?
- Does deletion propagate to connected systems?
- Are backups handled according to policy?
- Is there evidence that the request was executed?
TRACE
Engineering Assurance
Where controls become evidence.
TRACE ENGINEERING ASSURANCE
Map the public-facing engineering evidence of your organisation in under 60 seconds.
See what TRACE can observe, what supports DPDP readiness, and what still requires verification from inside your systems.
Learn how TRACE worksWHAT HAPPENS NEXT
01
TRACE inspects publicly observable website, DNS, TLS, privacy and data-collection signals.
02
See Surface Assurance and DPDP Public Evidence Coverage.
03
Complete Internal Readiness and request an Engineering Audit where internal controls need proof.
01 / THE ENGINEERING GAP
Governance describes intent. Engineering determines whether that intent is actually implemented. TRACE focuses on the engineering reality underneath compliance — not the policy binder.
A privacy policy may say personal data can be deleted.
But:
A security policy may require access restrictions.
But:
A retention policy may specify deletion after a period.
But:
TRACE focuses on the engineering reality underneath compliance. The examples above illustrate the class of questions an assessment examines. They are not a claim that every check is already automated in the product today.
02 / HOW ORGANISATIONS BEGIN
TRACE is not something an organisation needs to purchase on day one. 7Unit first establishes whether engineering controls can be proved — then deploys TRACE where continuous assurance is valuable.
01
7Unit performs an Engineering Assurance Assessment across the organisation’s relevant digital systems.
02
Controls are technically examined against the applicable privacy, security and compliance requirements.
03
Engineering gaps are prioritised and can be fixed by the customer’s team, partners or 7Unit.
04
TRACE is configured around the organisation’s actual systems, controls, principals, assets and evidence requirements.
05
TRACE continuously collects evidence, monitors control state and supports ongoing assurance.
03 / ENGINEERING ASSURANCE
Engineering Assurance verifies whether production systems, applications, integrations and operational controls actually implement the privacy, security and compliance obligations an organisation has committed to — and generates evidence to demonstrate what was observed.
01
Understand systems, data, vendors, infrastructure and business processes.
02
Identify where personal and sensitive information enters, moves, resides and leaves.
03
Test whether relevant engineering and operational controls behave as expected.
04
Capture observations, configuration, attestations and technical evidence with provenance.
05
Turn identified gaps into actionable engineering work.
06
Use TRACE to maintain visibility and evidence as systems change.
04 / WHAT TRACE DOES
Policies describe what should happen. TRACE helps prove what your systems actually do — by holding principals, surfaces, rights activity and evidence in one operating layer.
Evidence Ledger
The ledger is append-oriented. Each record carries provenance, a timestamp and enough context to show what was observed, configured or attested — and to export that trail for review.
TRACE records evidence with provenance. It does not claim cryptographic immutability.
An evidence-backed view of a data principal and associated privacy activity — identity associations, consent history, notices, processing relationships, rights activity and evidence exports.
Understand observable digital surfaces and the systems that interact with personal information. Surface findings are evidence-backed rather than merely questionnaire-driven.
Track principal rights operationally — request intake, execution across relevant systems, and the evidence that a right was actioned. TRACE does not replace legal interpretation of those rights.
Production intelligence is being introduced through a Connector Framework, Integration Registry, Connector Health, a Connector Capability Model and custom API execution. Production connectors are being progressively introduced.
Named systems indicate the architecture direction for evidence-backed connector execution. They are not presented as generally available production connectors.
05 / EVIDENCE PHILOSOPHY
TRACE should never convert an assumption into a technical fact. Status is only as strong as the kind of evidence behind it.
TRACE or the engineering assessment directly observed the state.
A required control or expected behaviour has been configured in TRACE.
A responsible person or organisation has formally asserted something that cannot yet be technically observed.
This is how TRACE stays distinct from compliance dashboards that show green status based purely on questionnaires.
06 / ASSURANCE FRAMEWORKS
Organisations often operate against overlapping privacy, security and compliance requirements. TRACE’s assurance architecture is being designed so the same engineering evidence can support multiple regulatory and assurance frameworks instead of forcing organisations to duplicate evidence across separate compliance programmes.
Current focus
Architecture direction
Architecture direction
Architecture direction
Architecture direction
Architecture direction
India DPDP is the current primary regulatory focus. The other frameworks describe the architecture direction for assurance expansion — not a claim that those packs are fully implemented today, and not a claim of certification coverage.
07 / CREDIBILITY
Certification and legal interpretation remain the responsibility of qualified auditors, assessors, legal professionals and certification bodies. TRACE does not replace ISO consultants, auditors, legal counsel, DPOs or certification bodies.
TRACE provides something different: engineering visibility and evidence showing whether relevant digital controls appear to be implemented and operating.
08 / FROM THE FIELD
Privacy and security gaps rarely appear as missing policies alone. They show up in how real systems move data, enforce authority and produce evidence.
FIELD INSIGHT · HEALTHCARE
Patient information rarely stays inside a single healthcare application. The harder assurance problem is proving how data, access and controls behave as information moves between registration, clinical, communication, billing and third-party systems.
Read insight →FIELD INSIGHT · EDTECH
Consent becomes an engineering problem when organisations need to demonstrate who authorised processing, what notice applied, whose data was covered and how that authority propagated through downstream systems.
Read insight →09 / WHY 7UNIT
Most compliance programmes eventually produce technical requirements. Traditional consultants can identify some of these issues. 7Unit is an engineering company, so it can continue into implementation.
Assess. Prove. Fix. Continuously verify.
PRODUCT LADDER
Surface Assessment
What can the internet already reveal?
Engineering Audit
What do the internal systems actually do?
TRACE OS
Can the organisation continuously prove it?
10 / START HERE
7Unit will review the relevant systems, data flows and engineering controls, identify evidence gaps and provide a prioritised remediation roadmap.
Learn about the assessmentTRACE is an Engineering Assurance platform built by 7Unit. It verifies whether relevant digital controls appear to be implemented and operating, and collects evidence that can support privacy, security and compliance assurance. This assessment is a technical and operational readiness product built by the 7Unit engineering team, not a legal opinion or statutory certification. It does not constitute legal advice or representation. It does not guarantee compliance, security, or certification.