For enterprise · regulated categories

Compliance-first AI for brands that can’t afford to be wrong.

Regulated categories — pharma-adjacent wellness, beauty with allergen labels, food with regulatory packaging — cannot tolerate AI drift on a single frame. Drishti’s verification stack and append-only audit log are the answer. Ship imagery you can defend in a regulator’s inbox.

  • DPDP + GDPR aligned
  • 7-year append-only audit log
  • BYOK · AWS KMS envelope encryption
  • On-prem verifier option
Why enterprise picks Drishti

Generic AI tools optimise for ease of use. We optimise for evidence.

Four guarantees · written into the code

When the InfoSec team and procurement desk arrive at the demo, these are the four answers we lead with. Each is verifiable — in our architecture, in our database triggers, in our deployment topology.

Regulation

DPDP + GDPR aligned

Drishti maps cleanly to the Digital Personal Data Protection Act, 2023 and EU GDPR. Explicit purpose-bound consent at signup, Article 17 erasure cascade, Article 20 portability export, scoped audit retention, and a designated DPO role at the database level.

Full posture
Evidence

Append-only audit log

audit_log refuses UPDATE and DELETE at the database trigger level. Engineers, admins, and the DBA cannot silently rewrite history. Seven-year retention, immutable at the row, exportable in JSON or CSV for compliance audits and litigation hold.

Audit reference
Cryptography

BYOK envelope encryption

Bring your own Gemini API key. The key never sits decrypted at rest. AES-256-GCM envelope encryption with the data key wrapped by your own AWS KMS CMK, unwrapped only inside the generation worker and discarded on completion. Rotation supported without re-encryption.

Key handling
Deployment

On-prem verifier option

For SOC 2 / HIPAA-adjacent buyers, the eight-stage verification stack — Pixaris orchestration, DINOv2, SAM-2, PaddleOCR, ΔE-2000, the Gemini judge — can be deployed inside the customer’s own VPC. Generation can stay in the Drishti tenant or move on-prem too.

Discuss deployment
What Enterprise includes

Everything House offers, plus the six things procurement asks for.

In contrast to House · six differentiators

The Enterprise tier is the answer when your procurement desk has a questionnaire, your security team has a posture, and your legal team has a redlined DPA template. Each item below is delivered by default — not as an add-on.

Volume credits, custom pricing

No monthly ceiling. Per-mode credit cost held constant; total volume sized to your launch calendar. Annual contracts with locked rates for 1, 2, or 3 years.

SSO via Workspace / Okta / Azure AD

OIDC integration with Google Workspace, Okta, Azure AD, OneLogin, JumpCloud, or any custom IdP that speaks OIDC. SCIM provisioning de-provisions seats the moment HR offboards the employee.

SAML 2.0 + SCIM provisioning

Full SAML 2.0 for IdPs that prefer it. SCIM 2.0 push and pull for automated user lifecycle. Group-to-role mapping persisted on the workspace, audited on every change.

DPA + InfoSec questionnaire in 5 days

Data Processing Agreement, sub-processor list, vendor security questionnaire (CAIQ / SIG Lite / custom) returned within five business days of the procurement intake. No back-and-forth on standard clauses.

Quarterly fidelity audit + report

Every quarter our creative-quality team samples 100 randomly-selected gens from your workspaces, runs them through an independent verifier, and ships a fidelity drift report — with thresholds and per-vault recommendations.

Dedicated CSM + Slack Connect

A named CSM at a 1:3 account ratio, staffed IST business hours, with a shared Slack Connect channel. Direct phone line for P0 escalation. Quarterly business review with creative output audit and ROI summary.

The compliance posture

Three things the procurement desk already knows to ask.

Pulled from /security · long-form there

Drishti operates as a designated Data Fiduciary under the Digital Personal Data Protection Act, 2023. Every workspace has a scoped consent log, a thirty-day right-to-erasure workflow, and a notified Data Protection Officer role enforced at the database. The audit log is immutable — BEFORE UPDATE/DELETE triggers raise an exception so nobody, not even the DBA, can rewrite history.

For the India–EU customer overlap, Article 20 portability ships your generations, brand vaults, and metadata as a structured ZIP within twenty-four hours. Article 17 erasure cascades through Cloudflare R2 and Postgres in a single transaction. Cookie and analytics consent matches EU expectations — no dark patterns, no pre-ticked boxes.

Every tenant table runs Postgres Row-Level Security with FORCE enabled, so cross-tenant queries are impossible by construction. The audit log keeps prev/next JSONB snapshots on every change, retained for seven years to satisfy Indian and EU financial-records statutes. Encrypted backups in ap-south-1, lifecycle-policied, key-rotated quarterly.

DPDP-aligned
Data fiduciary register · DPO role · 30-day erasure
GDPR-ready
Article 17 + 20 cascade · EU sub-processor map
C2PA + IPTC
Signed manifest · AI disclosure on every frame

Not third-party certifications. Drishti-attested postures based on architecture and process. SOC 2 Type II audit underway — reach out if you need to see the scoping memo.

Industry fit

Why these categories, specifically.

Four categories · regulated by default

Each strip below explains why Drishti’s particular guarantees — the OCR gate, the audit log, the compliance overlay, the data-residency options — matter to that category in a way they would not to a generic D2C brand.

  • Category
    Listed beauty & wellness

    Public-company beauty and wellness brands ship hundreds of SKUs across multiple geographies, each with its own allergen, ingredient, and claim regulations. A wrong allergen pictogram on a generated pack is a recall event. Drishti’s OCR Levenshtein gate refuses to ship any frame where the label text drifts more than 0.5 from the source — it’s the only guarantee that scales.

  • Category
    Premium food + spice (regulatory)

    Indian food and spice brands face FSSAI logo, MRP, and country-of-origin requirements (Legal Metrology Rule 6(10A)) on every pack. The compliance overlay mode renders these blocks with verified placement and verified text before the verifier signs the frame. Festival catalogues — Diwali, Holi, Onam, Pongal, Eid, Christmas — carry locked palettes per region.

  • Category
    Luxury fashion & jewelry

    Luxury jewellery houses care about archive-fidelity and on-model diversity. The brand-trained Gemini overlay (₹4 lakh/yr per brand) fine-tunes on your archive — Mughal miniature on white, Art Deco gold gradients, Vermeer chiaroscuro — to a 95%+ fidelity baseline. On-model apparel mode renders India-default model diversity by default; one toggle for global.

  • Category
    Multi-region D2C (>3 markets)

    Brands shipping to more than three countries hit a data-residency wall. Drishti supports India-only, EU-only, or US-only options for generation, storage, and backups; multi-region tenants run a primary in ap-south-1 with sub-processor replication policies signed per region. DPA addenda per region available off the shelf.

Pharma-adjacent and HIPAA workloads — on-prem verifier requiredListed-company InfoSec reviews — 5-day SLA on questionnairesMulti-region residency — India / EU / US, signed sub-processors per region
Enterprise pricing

Custom pricing. Predictable per-credit cost.

Annual-only · locked for 1–3 year terms
Drishti · Enterprise
For listed brands and regulated categories
Starting at
₹2,49,999
/ month · $2,990+ excl. tax
  • Volume credits · custom annual contract (1–3 year terms)
  • SSO via Google Workspace / Okta / Azure AD / any OIDC IdP
  • SAML 2.0 + SCIM provisioning · group-to-role mapping
  • BYOK envelope encryption · AWS KMS CMK, rotation supported
  • Append-only audit log · 7-year retention · CSV / JSON export
  • On-prem verifier deployment · customer VPC · same fidelity contract
  • DPA + InfoSec questionnaire returned in 5 business days
  • Dedicated CSM (1:3 ratio) · Slack Connect · QBR + fidelity audit
Book a callReview the security postureMSA · custom DPA · vendor questionnaires

When a wrong logo is unacceptable, generic AI isn’t.

Verified before ship, signed with C2PA, retained for seven years. That’s the contract enterprises sign with Drishti.