Institutional Agreements & Master Services Framework
Effective Date: August 10, 2026 · Last Updated: August 10, 2026
- 99.99% API Verification Uptime SLA — Guaranteed for all institutional enclave deployments.
- GeM & Purchase Order Procurement — Procure via Government e-Marketplace tenders, Pro-Forma Tax Invoices, or direct POs.
- DPDP Act Data Processor Guarantee — DISHA acts strictly as a Data Processor; the Institution retains full Data Fiduciary status.
- Zero Data Ownership Claims — All institutional records remain the exclusive intellectual property of the Institution.
01Scope & Master Institutional Framework
This Institutional Agreement ("Agreement" or "Framework") governs large-scale, multi-tenant deployments of the DISHA 4.0 Human-Centric Operating System (HCOS) across accredited higher education institutions, state and central educational boards, government ministries, public sector undertakings (PSUs), and enterprise research consortiums ("Institutional Partner" or "Institution").
This Framework sits above individual user licenses and establishes the legal, cryptographic, operational, and governance terms under which DISHA 4.0 infrastructure, .dhc hyper-containers, custom ZK-SAD circuit pipelines, and dedicated verification enclaves are provisioned.
02Institutional Enclaves & Federated Node Architecture
- Dedicated Hardware Security Module (HSM) Enclaves: Institutions may elect to deploy isolated regional enclaves. Raw payload processing occurs exclusively inside the Institution's designated enclave or on-premise infrastructure.
- Federated Node Network: Educational boards and state departments are granted rights to operate dedicated DISHA 4.0 verification nodes, participating in consensus verification without exposing student or citizen PII.
- Custom ZK-SAD Circuit Authorization: DISHA grants the Institution non-exclusive, non-transferable rights to compile, test, and execute custom zero-knowledge verification circuits tailored to institutional credentials.
03Data Sovereignty, DPDP Act Compliance & Zero-Trust Verification
- Absolute Data Autonomy: All institutional records encrypted into
.dhchyper-containers remain the sole and exclusive intellectual property of the Institution. - Compliance with Digital Personal Data Protection (DPDP) Act:
- DISHA acts strictly as a Data Processor / Technical Enabler. The Institution retains the legal status of Data Fiduciary.
- The Platform's Zero-Knowledge architecture ensures that third-party verifiers can authenticate institutional records without transferring raw personal data across public networks.
- Local Encryption & Key Management: Master root keys (
Argon2idKDF parameters) remain locked within the Institution's Key Management System (KMS).
04Custom Enterprise Procurement, Tax & Billing Schedules
4.1 Custom Invoice Billing & Government Procurement
Institutions may procure services via official Pro-Forma Tax Invoices, direct Purchase Orders (PO), GeM (Government e-Marketplace) tenders, or custom annual master agreements. All fees are quoted in Indian Rupees (₹ INR), itemizing applicable Goods and Services Tax (GST at 18% or specialized public-institution concessionary rates).
4.2 Dedicated Volume Add-Ons & Multi-Seat Tiering
Institutional contracts combine custom base infrastructure tiers with bulk seat packs, high-throughput API bandwidth packs, and multi-year audit ledger vaults (up to 25-year guaranteed retention).
4.3 Tax Exemption Certificate Handling
Accredited educational bodies or non-profit research labs eligible for GST exemptions or reduced tax brackets may submit valid GST exemption certificates during onboarding for tax adjustment.
05Service Level Agreements (SLA) & Critical Support
- Availability SLA: Institutional Enterprise enclaves are backed by a guaranteed 99.99% API verification uptime SLA.
- Dedicated Technical Account Management (TAM): Institutions are assigned a dedicated Cryptographic Systems Engineer and 24/7 priority incident response.
- SLA Credits: In the event of system downtime exceeding allowable limits, service credits are automatically applied against the subsequent billing or renewal cycle.
06Audit, Governance & User Provisioning Controls
- Immutable System Audits: All administrative actions — including user provisioning, role-based access control (RBAC) modifications, and key rotations — are recorded in append-only, tamper-evident audit ledgers (
user_provisioning_audit_logs). - Annual Compliance Certification: DISHA provides Institutions with annual third-party ISO/IEC 27001, SOC 2 Type II, and zero-knowledge circuit mathematical audit reports upon request.
user_provisioning_audit_logs table is append-only with cryptographic chaining. No record can be modified or deleted post-creation.07Term, Renewal & On-Premise Decommissioning
- Agreement Duration: Institutional Agreements are executed for terms ranging from 12 to 60 months.
- Data Portability & Exit Protocol: Upon termination or expiration of this Agreement:
- The Institution retains full, permanent access to all locally generated
.dhchyper-containers and verification proofs. - DISHA guarantees total, verified cryptographic purging of all cached verification tokens and temporary session states within 30 days of exit, issuing a certified Certificate of Purge.
- The Institution retains full, permanent access to all locally generated
08Governing Law & Dispute Resolution
This Framework is governed by the laws of India. Any legal proceedings, arbitrations, or institutional disputes arising under this Agreement shall be referred to sole arbitration under the Arbitration and Conciliation Act, 1996, with the seat of arbitration established in Guwahati, Assam, India.
09Institutional Relations & Partnership Contacts
To execute an Institutional Master Agreement, request custom ZK circuit development, or submit a Purchase Order, contact the DISHA Institutional Partnerships team:
Director of Institutional Partnerships
DISHA Intelligence & Security Systems
Document Identifier: DISHA-GOV-INST-2026-V1 · Effective August 10, 2026


