Knowledge base
Methodology, scoring & frequently asked questions
Does a NiyamLens report mean an app is DPDP-compliant?
No. NiyamLens never issues a compliance certification — only an Observable Risk Score, a separate Evidence Confidence Score, and per-finding evidence. Treat it as a starting point for your own legal review.
How is the Observable Risk Score calculated?
A weighted, deterministic model across five dimensions: permission-purpose alignment (30%), notice & transparency (25%), rights & contactability (20%), third parties & SDKs (15%), and retention/other elevated signals (10%). Bands: 0–24 Low, 25–49 Moderate, 50–74 High, 75–100 Critical.
What happens when evidence is missing or a policy page can't be reached?
It's marked "Not Verified," which reduces the confidence score — it is never scored as a confirmed omission.
Does NiyamLens read my full policy document on a server?
On-device scans process locally. If cloud AI fallback is used (only when on-device analysis is unsupported), only a small pre-filtered excerpt around a relevant keyword is sent — never the full document, and never tied to your identity.