GenMedhaGenMedha

Governance & Security

Built for Boards. Built for Compliance. Built for Sleep.

Every GenMedha deployment includes governance architecture — not as an add-on after an audit. Oversight is Layer 5 of the Medha Protocol, designed in from day one.

Who asked, what the AI did, what it changed

Audit Logs

A practical audit trail captures the input, the model's output, the human decision, and the timestamp — stored in a format your compliance team can export without calling engineering.

  • Every AI action logged: trigger, input, output, approver, and downstream changes
  • Exportable trails for DPDP, GDPR, and sector-specific regulatory reviews
  • Weekly accuracy and override reports for operational review
  • No black-box deployments — full visibility into model decisions
Your intern and your CFO see different things

Role-Based Access Control

Permissions are scoped to roles, workflows, and data sensitivity tiers — so AI capabilities match what each team member is authorized to do in your existing systems.

  • Role-scoped access to AI tools, dashboards, and approval queues
  • Segregation between operators, supervisors, and compliance reviewers
  • Integration with existing identity providers and SSO
  • Configurable permission tiers per workflow, not global defaults
Autonomy is earned, not assumed

Human-in-the-Loop

Every high-stakes action gets an approval checkpoint. We design three tiers: auto-approve for low-risk, queue-for-review for medium-risk, and hard-block for named-approver actions.

  • Checkpoints on refunds, account changes, regulatory filings, and policy exceptions
  • One-click override on every AI-suggested action
  • Escalation paths with full context attached — no cold handoffs
  • Configurable thresholds per workflow, department, and risk tier
DPDP, GDPR, PDPL — built into the architecture

Compliance Frameworks

Regulators and enterprise buyers ask the same question: can you show what the AI did, who approved it, and what data it used? We build demonstrable accountability from day one.

  • Data residency awareness for India, UAE, UK/EU, and US deployments
  • Encryption at rest and in transit on all AI data flows
  • No training on client data without explicit written consent
  • Compliance tagging and retention policies aligned to your jurisdiction
You see everything the AI does

Observability

Full observability means you know what the AI is doing, why it's doing it, and how it's performing — in real time, not after a quarterly review.

  • Live dashboards for accuracy, latency, cost, and escalation rates
  • Drift detection and anomaly alerts on model behavior
  • Per-workflow success metrics tied to business outcomes
  • Evaluation frameworks that run continuously, not just at launch
Revert in minutes, not days

Rollback

Every AI deployment should have a rollback plan executable in minutes. Feature flags, cached fallbacks, and runbooks that don't require an engineer on call.

  • One-click revert to human-only routing on any workflow
  • Feature flags to disable AI actions without taking down host applications
  • Cached fallback to last known-good model version
  • Quarterly rollback drills — if it takes more than five minutes, we fix it

Compliance Frameworks We Design For

Architecture decisions that satisfy regulators and enterprise procurement — not checkbox compliance after the fact.

India

India DPDP Act

Data processing transparency, consent management, and breach notification readiness for Indian deployments.

  • Purpose-limited data processing with documented legal basis
  • Consent capture and withdrawal workflows where required
  • Data principal rights request handling (access, correction, erasure)
UK / EU

GDPR

Accountability, data minimization, and demonstrable compliance for European operations and cross-border data flows.

  • Data processing impact assessments for high-risk AI workflows
  • Right to explanation support via audit trail exports
  • Cross-border transfer safeguards and residency options
UAE

UAE PDPL

Personal data protection compliance for UAE-based operations and regional data residency requirements.

  • UAE data residency options for sensitive workloads
  • Processing records aligned to PDPL accountability requirements
  • Breach notification procedures with defined escalation paths

Additional Assurances

No training on client data without explicit written consent
Documentation and knowledge transfer — your team owns the system
Governance setup begins in the Discovery Sprint, not after production
24/7 critical issue response included in retainer engagements

Need a Governance Review?

We audit existing or planned AI systems against DPDP, GDPR, and industry frameworks.

Book Your AI Strategy Call
💬