- ABAC
- Attribute-Based Access Control. Access is decided using trusted facts such as legal entity, region, function, case ownership or other approved attributes.
- Active pack
- A signed regulatory or country pack that has completed the required activation workflow and is currently available to runtime decisions.
- Administrator
- An authorized user who configures or operates TrustPlane. An administrator is not automatically authorized to approve every governed action.
- Air-gapped
- A deployment that is intentionally disconnected from the Internet or other external networks and uses controlled offline transfer/update procedures.
- API
- Application Programming Interface. A defined way for one software system to communicate with another.
- API key / service credential
- A credential used by a workload or integration. It should be protected like a password and limited to the minimum required permissions.
- Applicability
- The determination of whether a particular law, rule, obligation or pack component applies to a specific processing activity based on trusted facts.
- Application
- A website, mobile app, business system, API or other customer workload that TrustPlane governs, observes or integrates with.
- Assessment
- A structured review such as a DPIA, privacy impact assessment, risk assessment or control assessment that records evidence, findings, treatment and approval.
- Audit trail
- A time-ordered record of important actions, actors, decisions, versions and evidence used to reconstruct what happened.
- Authoritative state
- The server-side record TrustPlane treats as the source of truth for a governed decision or workflow.
- Backup
- A protected copy of data used for recovery. A backup is not considered proven until restoration has been tested.
- Browser
- The web browser used to access the TrustPlane interface. Exact supported versions are release-specific.
- CBOM
- Cryptographic Bill of Materials: evidence about cryptographic algorithms, keys, protocols, certificates and related use.
- CCPA
- California Consumer Privacy Act. California privacy requirements are amended by later legislation including the CPRA and implemented through regulations.
- Connector
- A governed integration between TrustPlane and an external system, service, data source, regulator interface or customer platform.
- Consent
- A person's affirmative permission for a defined processing purpose where consent is the applicable basis. The exact legal meaning depends on the governing law.
- Consent Manager
- Under India's DPDP framework, a person registered with the Data Protection Board who enables a Data Principal to give, manage, review and withdraw consent. TrustPlane may integrate with one; integration does not make TrustPlane a registered Consent Manager.
- Controller
- A common privacy-law term for an organization that determines the purposes and means of processing personal data. Different jurisdictions may use different terminology.
- Cookie
- A small piece of data stored by a website in a browser. Some cookies or similar technologies can be used for tracking, analytics, preferences or authentication.
- Country pack
- A signed, versioned TrustPlane content package containing country-specific rules, mappings, templates, evidence requirements, reports and related semantics.
- CPRA
- California Privacy Rights Act of 2020, which amended the CCPA and expanded California privacy rights and regulatory structures.
- Data breach
- A security incident involving unauthorized or accidental access, disclosure, alteration, loss, destruction or other compromise of personal data, as defined by applicable law.
- Data Fiduciary
- The term used by India's DPDP Act for the person that determines the purpose and means of processing personal data.
- Data Principal
- The term used by India's DPDP Act for the individual to whom personal data relates, subject to the Act's specific definitions for children and persons with disabilities.
- Data Processor / Processor
- A person or organization that processes personal data on behalf of another party, subject to the terminology and requirements of the applicable law.
- Data Protection Officer (DPO)
- A designated privacy/data-protection role required or appointed in defined circumstances under applicable law or customer governance.
- DecisionProof
- A TrustPlane-generated scoped proof recording an authoritative processing decision for a particular subject, purpose, data scope, action and controlling state.
- Deployment profile
- The supported architecture used to run TrustPlane, for example standard single-site, high availability, disaster recovery or air-gapped.
- Diagnostic pack
- A customer-triggered, privacy-minimized package of technical evidence used to troubleshoot a TrustPlane environment without requiring routine live remote access.
- DNS
- Domain Name System. It translates names such as portal.example.com into the network addresses systems use to connect.
- DPIA
- Data Protection Impact Assessment. A structured assessment used to evaluate privacy risks for processing that may create higher risk.
- DR
- Disaster Recovery. The process and architecture used to recover or move service after a serious site or system failure.
- DSAR / rights request
- A request by an individual to exercise a privacy right. The available rights and terminology depend on the applicable law.
- EBOM
- Evidence Bill of Materials or another BOM dimension supplied through an approved evidence source. TrustPlane treats BOM inputs as evidence, not automatic legal truth.
- Entitlement
- The signed commercial permission defining which product capabilities, country packs, options or periods a deployment is permitted to use.
- Evidence
- Records, documents, approvals, logs, source facts and system results used to support a control, workflow or report conclusion.
- Evidence lineage
- The ability to trace a reported or derived result back to the source evidence, version, actor and transformation that produced it.
- Fencing
- A safety control that prevents a stale or isolated database/site from continuing to write after it has lost authority.
- FQDN
- Fully Qualified Domain Name. The complete DNS name used to identify a host or service.
- GDPR
- General Data Protection Regulation. In the EU this is Regulation (EU) 2016/679; UK data protection law uses the UK GDPR together with other UK legislation.
- Guardian authority
- Verified authority for a parent or lawful guardian to act for an eligible child or protected person, bounded to the relevant subject and purpose.
- HA
- High Availability. A deployment design using redundant components so service can continue after certain failures.
- HBOM
- Hardware Bill of Materials: evidence describing relevant hardware or firmware components and trust/lifecycle information.
- HSM
- Hardware Security Module. A specialized security system used to protect and perform operations with cryptographic keys.
- HTTPS
- HTTP protected by TLS encryption. It is the normal secure protocol used to access the TrustPlane web interface and APIs.
- Idempotency
- A property that lets the same safe operation be retried without creating duplicate authoritative effects.
- IdP
- Identity Provider. The customer system used to authenticate users, often through enterprise Single Sign-On.
- Immutable evidence
- Evidence designed so its integrity and history can be verified and unauthorized rewriting is prevented or detectable. Storage-level immutability/WORM must only be claimed when actually configured and evidenced.
- Incident
- A security, privacy or operational event that is tracked through investigation, obligations, actions, evidence and closure.
- Jurisdiction
- A country, state, region or other legal territory whose rules may apply to processing depending on the facts.
- KMS
- Key Management Service. A service used to create, protect, rotate and use cryptographic keys.
- Legal entity
- The specific company or organization within the customer group that performs or controls the relevant processing activity.
- Legal hold
- A governed requirement to preserve defined information that would otherwise be deleted or expire, subject to applicable law and customer authorization.
- mTLS
- Mutual TLS. Both sides of a network connection authenticate using certificates.
- Notice
- Information presented to an individual about personal-data processing. TrustPlane preserves the approved version, language and context shown.
- NTP
- Network Time Protocol. It keeps system clocks synchronized so security, evidence and deadline calculations use reliable time.
- OIDC
- OpenID Connect. A common identity/federation protocol used for Single Sign-On.
- Pack manifest
- The signed description of a pack's identity, version, compatibility, dependencies and included content/capabilities.
- Personal data
- Information relating to an identified or identifiable individual, subject to the definition in the applicable law.
- PII
- Personally Identifiable Information. A commonly used security/privacy term; legal definitions differ by jurisdiction, so TrustPlane uses the active legal/pack semantics where a legal decision is required.
- PITR
- Point-In-Time Recovery. Restoring a database to a selected time using backups plus transaction/WAL history.
- PostgreSQL
- The database used by TrustPlane as its sole authoritative governed transactional store in the current architecture.
- PQC
- Post-Quantum Cryptography. Cryptographic methods designed to resist attacks from sufficiently capable quantum computers.
- Processing
- Operations performed on personal data, such as collection, storage, use, disclosure, combination, restriction, erasure or destruction, subject to the applicable legal definition.
- Purpose
- The specific reason personal data is processed. TrustPlane can bind notices, consent, authority and evidence to purpose and data scope.
- QBOM
- Quantum Bill of Materials: evidence used to identify quantum-vulnerable cryptography and migration/readiness context.
- Quorum
- The minimum coordinated agreement required before a distributed/HA system can safely perform an authority-sensitive action such as database leadership.
- RBAC
- Role-Based Access Control. Access is granted according to approved user or service roles.
- Regulator acknowledgement
- Evidence that a regulator or external authority has acknowledged a submission or communication. Sending a message is not the same as receiving acknowledgement.
- Regulatory pack
- A signed, versioned TrustPlane package containing legal/regulatory semantics, rules, mappings, templates or evidence requirements. Country packs are one type.
- Release BOM
- The release-specific Bill of Materials/support document that defines the exact supported software/platform versions and release-qualified resource/sizing values for a TrustPlane build.
- Retention
- The governed period or conditions under which data/evidence is kept before deletion, archival or another disposition.
- RoPA
- Record of Processing Activities. A structured inventory of processing activities, purposes, data, recipients, systems and other required context.
- SAML
- Security Assertion Markup Language. A common enterprise Single Sign-On/federation protocol.
- SBOM
- Software Bill of Materials: an inventory/evidence representation of software components, versions, suppliers, dependencies and related information.
- Sector overlay
- Signed content that adds sector-specific requirements or workflows over a country/regulatory baseline without creating a separate product fork.
- Significant Data Fiduciary (SDF)
- A Data Fiduciary or class of Data Fiduciaries notified under India's DPDP Act for additional obligations. TrustPlane supports associated workflows; it does not itself designate a customer as an SDF.
- Single Sign-On (SSO)
- A login method that lets users authenticate through the customer's central identity provider rather than a separate password for each application.
- SMTP
- A standard protocol used for sending email through an approved customer mail relay/service.
- Source of truth
- The system that owns the authoritative version of a given fact. TrustPlane is authoritative for its governed privacy state; external business systems remain authoritative for their own business data.
- Subprocessor
- A downstream processor engaged by another processor, subject to the governing contract and applicable law.
- TLS
- Transport Layer Security. Encryption and authentication used to protect network connections.
- Tracker
- A web or application technology that can observe user activity or behavior, often for analytics, advertising, personalization or similar purposes.
- Transactional outbox
- A reliability pattern that records an external action/event in the same database transaction as the governing state change so retries do not lose or duplicate authority-sensitive work.
- Transfer
- Making personal data available across an organizational or geographic boundary. Whether a transfer is restricted or permitted depends on the applicable law and facts.
- Trusted fact
- A value obtained from an approved authoritative source and accepted for use in a governed decision.
- Unknown / Partial / Stale
- Explicit evidence states. Unknown means a required fact is not known; Partial means only some scope is covered; Stale means the observation is outside the expected freshness window.
- VIP
- Virtual IP address. A network address commonly used to expose a highly available service/load balancer.
- WAL
- Write-Ahead Log. PostgreSQL transaction history used for durability, replication and point-in-time recovery.
- Withdrawal
- A person's revocation of previously given consent where the applicable law and processing basis allow withdrawal.
- WORM
- Write Once Read Many. A storage mode intended to prevent modification/deletion for a defined period. TrustPlane only treats storage as WORM/immutable when the actual storage configuration proves it.
- xBOM
- An umbrella term for Bills of Materials such as SBOM, CBOM, QBOM, AIBOM, HBOM and related evidence formats.