NLNiyamLens

Knowledge base

Methodology, scoring & frequently asked questions

Does a NiyamLens report mean an app is DPDP-compliant?

No. NiyamLens never issues a compliance certification — only an Observable Risk Score, a separate Evidence Confidence Score, and per-finding evidence. Treat it as a starting point for your own legal review.

How is the Observable Risk Score calculated?

A weighted, deterministic model across five dimensions: permission-purpose alignment (30%), notice & transparency (25%), rights & contactability (20%), third parties & SDKs (15%), and retention/other elevated signals (10%). Bands: 0–24 Low, 25–49 Moderate, 50–74 High, 75–100 Critical.

What happens when evidence is missing or a policy page can't be reached?

It's marked "Not Verified," which reduces the confidence score — it is never scored as a confirmed omission.

Does NiyamLens read my full policy document on a server?

On-device scans process locally. If cloud AI fallback is used (only when on-device analysis is unsupported), only a small pre-filtered excerpt around a relevant keyword is sent — never the full document, and never tied to your identity.