This is an internal ops/dev console, not the guardian-facing web dashboard from the product
wireframes — that needs real user accounts and guardian-linking, which the backend doesn't have yet
(see founder-outputs/build-brief-output.md). This console exists to look up a device's detection
history using the same X-Device-Key the mobile app uses, against the real
GET /api/v1/detections endpoint.
Type
Risk
Matched rule
Content hash
Created
Privacy Center
What RakshaKawach actually knows about this device, and your rights over it under India's DPDP Act 2023 —
see docs/ROADMAP.md item 35. What stays on the device: the SMS/call text itself,
transaction amounts, and payee/VPA details — never uploaded. What reaches the backend: only a
risk tier, a matched rule name, and a content hash per detection (see the table above), plus consent
grant/withdrawal receipts (below).