Skip to content
// compliance · meity · stqc · dpdp

Compliant by design,
not by patch.

The clocks are running. The STQC bar on uncertified surveillance cameras went live on 1 April 2026 (the 16 January 2026 MeitY office memorandum removed the grace periods), and DPDP Act enforcement follows on 13 May 2027. Atlas leads with operational compliance: local compute, signed updates, access-controlled logs, and Indian data residency as defaults.

§ 0 — the clocks

The regulatory window, already open.

  1. 16 Jan 2026in force
    MeitY office memorandum

    Grace periods for uncertified surveillance cameras removed.

  2. 1 Apr 2026in force
    STQC bar live

    Uncertified cameras barred on new government deployments.

  3. 13 May 2027upcoming
    DPDP Act enforcement

    Data-protection duties and penalties come into force.

Atlas is built for the far end of this timeline, not patched onto the near end: on-device, India-resident, audited from day one.

// the clock you’re racing

Loading time remaining until DPDP Act enforcement.

Counting down to DPDP Act enforcement on 13 May 2027. Atlas is built for the far end of this timeline.

§ I — the directive in plain language

The 2026 surveillance directives ask three questions of every camera at every gate in India.

Where does the inference run? If the answer is a foreign cloud, the gate fails the audit.

Where does the data live? If the answer is anywhere outside India, the gate fails the audit.

Can you prove the recording wasn't tampered with? If the answer is "we trust our vendor," the gate fails the audit.

Atlas answers on the box · in India · cryptographically.

§ II — how Atlas aligns
  • aligned
    Data residency in India

    Inference, storage, and any optional sync stay within Indian borders. No cross-border processing.

  • aligned
    DPDP Act 2023

    Purpose-limited capture, in-app consent surface for residents, defined retention windows.

  • aligned
    STQC-aligned, signed updates

    Software and model updates ship as signed releases the box can verify and roll back at the gate.

  • aligned
    Complete, access-controlled audit log

    Every event is recorded with role-based access and encryption at rest, and is exportable per gate.

  • aligned
    Encrypted at rest + in transit

    Personal data (owner details from VAHAN) is encrypted at rest in the Indian-region backend; the dashboard and all optional sync are served over TLS 1.3.

  • aligned
    Role-based access control

    Operator, guard, reviewer, and admin roles, each scoped to its own site, with a separate segregated reviewer login.

  • aligned
    Signed, rollback-able model updates

    Local OTA with versioned signatures. Bad model? Roll back at the gate, not over the cloud.

  • aligned
    Operator override + retention

    30-day retention default; configurable per society. Operator override is itself logged.

  • aligned
    Independent security review

    Atlas commits to an independent security review before general availability, with the report shared with deployment partners under NDA.

§ III — frequently asked

Need a one-page compliance brief?
We have it ready.