DWG. VTS-003 REV. v2.0 SHEET 03 / 05 PLATFORM SPEC · 11 MODULES 2026
PDPA-specific · built for Singapore from the ground up

Every tool your DPO needs.
Nothing they don't.

Veritos brings policies, training, incidents, audits, vendors, and data mapping into one platform — structured around Singapore's PDPA, not generic compliance checklists.

PDPA-specific Multi-entity ready AI-powered Audit-ready by default Role-based access
C.01 Cluster 01 01module

Vera AI

Vera isn't a module — she's the intelligence layer underneath everything else. She shows up wherever you need her.

F.01.01 Vera AI Intelligence layer

Get a working compliance baseline on day one — not after a month of consultants.

Most compliance tools hand you a blank screen and wish you luck. Vera researches your company, maps your PDPA obligations, and generates a full compliance baseline — before you've had your first coffee.

What Vera does on Day 1

  • Researches your company and industry profile automatically
  • Selects applicable policy templates and generates customised drafts
  • Recommends controls matched to your risk profile
  • Bootstraps your ROPA with inferred data processing activities
  • Creates a prioritised task queue so your team knows exactly what to tackle next

What you get

  • A full compliance baseline — not a blank slate
  • Policies pre-tagged as AI-generated for your review
  • Controls linked to the right obligations
  • A task queue that tells your team exactly what to do next
  • No consultants required for setup

Vera flags everything as AI-generated so you stay in control of what gets published.

C.02 Cluster 02 04modules

Run the programme

The daily work of compliance: writing policies people actually acknowledge, training the team, maintaining controls, handling what lands in the DPO inbox.

F.02.01 Policy Management Lifecycle module

Policies that people actually read — and you can prove it.

Drafting is the easy part. Getting staff to acknowledge policies — and being able to show PDPC they did — is where most DPOs lose sleep. Veritos handles the whole lifecycle, from first draft to audit-ready evidence pack.

For DPOs and Admins

  • Draft from pre-built PDPA templates or generate with AI
  • Send for review and capture approver sign-off
  • Publish to all staff, specific teams, or custom groups
  • Auto-track acknowledgements with timestamps
  • Get notified when policies are overdue for review
  • Export audit packs in seconds

For Employees

  • One magic link — no account or login needed
  • Mobile-friendly reading on any device
  • One-click acknowledgement, instantly recorded
  • Automated reminders if they haven't acknowledged
Status flow · draft → review → approved → published → archived Version history Role-gated approvals
F.02.02 Training & Awareness Programme module

Build a privacy-aware team — and the records to prove you did.

Training is only useful if people actually complete it, and evidence of completion only matters if it's easy to export. Veritos handles both — with auto-reminders for the stragglers and one-click evidence exports when PDPC comes knocking. And if an incident happens, micro-training is auto-assigned to the people involved.

For DPOs

  • Assign training by role, department, or individual
  • Track completion rates and quiz scores
  • Set passing scores and mandatory completion
  • Auto-send reminders before deadlines
  • Export training evidence for audits

For Employees

  • Magic link access — no account needed
  • Mobile-friendly, 10-minute modules
  • Instant quiz feedback
  • Progress saved automatically
F.02.03 Controls Operational module

Compliance obligations don't run themselves. Controls make sure someone does.

A policy says what you'll do. A control makes sure you're actually doing it. Veritos gives you a library of 73 PDPA-aligned controls, tracks evidence, flags what's overdue, and keeps everything linked back to the obligations it covers.

Preventive · Detective · Corrective Recurring activities Evidence uploads Auto-generated tasks Linked to policies & ROPA
F.02.04 DPO Inbox Triage module

One inbox. Everything that lands on your desk, already sorted.

DSARs, vendor queries, incident reports, staff questions — they arrive from all directions and all need a different response. Vera classifies each item automatically so you know what it is before you open it, and converts anything into a task or incident in one click.

Auto-classification by AI One-click convert to task or incident Internal & external senders Full reply & activity log
C.03 Cluster 03 04modules

Handle the high-stakes moments

The times it matters most — when an incident hits, when an audit is looming, when a regulator asks where your vendors are, when someone needs to see their data. Every moment captured, timestamped, and audit-ready.

F.03.01 Incident Management 72-hour PDPC deadline

72 hours goes fast when you're panicking. Veritos slows it down.

The moment an incident is logged, the clock starts — and so does Veritos. Notifiability is assessed, PDPC draft notices are generated, and your remediation tasks are created automatically. You focus on the fix, not the paperwork.

Automated on creation

  • Unique incident ID (INC-YYYY-NNN)
  • 72-hour countdown to PDPC notification deadline
  • AI notifiability assessment — PDPC guidelines, not guesswork
  • Remediation task generation
  • Document drafts: PDPC notice, individual notice, internal brief

Always tracked

  • Full evidence trail with file attachments
  • Timeline entries with actor and timestamp
  • PDPC notification status
  • Individual notification records
  • Post-incident review and lessons learned

Notifiability follows PDPC guidelines: sensitive data + unencrypted + risk of misuse, or 500+ individuals affected. Manual override available with documented reasoning.

F.03.02 Audit & Compliance Assessment Six-domain framework

Stop dreading audits. Start running them.

A PDPA audit shouldn't take weeks to prepare for. Veritos structures it across six compliance domains, lets Vera review your answers, and produces a scored report with findings and remediation tasks — ready to show PDPC or your board.

Six audit domains

  • Governance
  • Data inventory
  • Consent collection
  • Protection and security
  • Retention and disposal
  • Breach and vendor management

What the AI review does

  • Reviews completed domain answers
  • Creates findings with severity ratings
  • Suggests remediation steps
  • Generates tasks assigned to the right owners
  • Produces full report and executive summary

Scoring · Yes = full points · Partial = half · No = zero · Domain ≥80% = Low risk · 60–79% = Medium · <60% = High · Finalisation freezes a snapshot

F.03.03 Vendor Management Third-party module

Your vendors are processing personal data. Do you know which ones haven't signed a DPA?

Third-party risk is one of the most common gaps PDPC finds. Veritos keeps every vendor that touches personal data on a short leash — DPA status, cross-border transfers, risk scores, and review dates all in one place.

Tracked per vendor

  • Personal data processing and data categories
  • Cross-border transfer and sub-processor status
  • DPA status (In Place / Missing / Pending)
  • Security certifications and contract dates
  • Automated risk scoring (Low / Medium / High)
  • Next review date, auto-calculated by frequency

Managed in platform

  • Upload DPAs, contracts, and SCC documents
  • Offboard vendors with data return confirmation
  • Full vendor document history
  • Linked to ROPA and audit evidence
F.03.04 Data Mapping (ROPA) Inventory module

Your data flows, mapped — not scattered across three spreadsheets.

PDPA requires you to document what personal data you collect, why, and where it goes. Veritos builds your ROPA from day one — Vera bootstraps the starting point, your team keeps it current, and every entry links to the policies and controls that govern it.

Per processing activity

  • Data subjects and categories
  • Purpose and legal basis
  • Storage systems and retention periods
  • Sharing — vendor transfers, overseas transfers
  • Access controls and encryption status
  • Linked policies and controls

Why it matters

  • PDPA requires documented data inventories
  • Demonstrates accountability to PDPC
  • Surfaces where high-risk data flows are ungoverned
  • Evidence-ready for audits and investigations
C.04 Cluster 04 02modules

Scale and access

Compliance doesn't happen in isolation. When the right people need the right access, and when you're managing more than one entity, the platform scales without fragmenting.

F.04.01 Role-Based Access Control Access module

The right access for every person in your team.

Five roles, precisely scoped. Users can hold multiple roles simultaneously. Permissions are additive — no workarounds needed when someone wears more than one hat.

Roles

  • Company Admin — full platform control
  • DPO — compliance operations and all modules
  • Approver — policy approvals and risk acceptance
  • Employee — tasks, training, incident reporting
  • Auditor — read-only audit access

How it works

  • Multi-role assignment — one person, multiple hats
  • Module visibility controlled by role
  • Tier-gating prevents out-of-plan access
  • Row-level security at database level (Supabase RLS)
F.04.02 Portfolio View For external DPOs

Managing compliance for 10 clients is a different job. Veritos treats it that way.

The Portfolio layer is built for external DPOs and consultants who can't afford to drop the ball on any one client. See every entity's compliance health at a glance — and drill into any one of them in a single click. Read-only by design, so client data stays protected.

Portfolio dashboard shows

  • Compliance scores per entity
  • At-risk entities and urgent alerts
  • Cross-entity incident status
  • Training completion by entity
  • Overdue tasks and upcoming deadlines

Built for external DPOs

  • Aggregate view across all managed entities
  • Entity-level drill-down in one click
  • Read-only — client data stays in their workspace
  • Entity ranking by compliance score and trend

See the full platform in 15 minutes.

No slides, no sales pitch — just the product. Or skip the demo and start a free trial yourself: most teams have their compliance baseline running by end of day one.

Free 30-day trial · No credit card required · Setup in under a day