Government vision · once TPM governs

Every rupee. Every contract. Every milestone.

The Open Ledger is Karnataka's financial-spine publishing surface — OCDS-compliant, witness-cosigned, cryptographically anchored. Plus five more publishing surfaces that publish other classes of state data on their own governance.

Open Ledger public dashboard
The Open Ledger

Real-time public contract + payment data, with cryptographic backstop.

Every Karnataka state contract published in OCDS form within hours of award. Every payment tied to milestone evidence anyone can verify. Every anomaly flagged by the Procurement Audit Cell. Periodic anchors of the entire ledger are co-signed by independent witnesses — even the state cannot quietly rewrite the record after the fact.

Publication windows

How fast it goes public

Planning data — at budget tabling. Tender data — within 24 hours of issue. Award data — within 7 days. Execution + payment — within 30 days of underlying event. Implementation publishes against these commitments as KPIs.

Cryptographic anchoring

KSSL backstop

Every Open Ledger transaction flows through the Karnataka State Service Log. Periodic batches anchored publicly. Independent witnesses (Karnataka State Audit Office, Civil-society Independent Audit Board, accredited universities) co-sign every anchor.

Citizen receipts

Verify your own transaction

Every state transaction returns a signed digital receipt to the citizen. The receipt carries an inclusion proof against the published anchor — a resident can independently prove their transaction was logged correctly.

All six publishing surfaces

Right data, right governance, right access.

State data isn't homogeneous. The architecture splits it into six purpose-built surfaces, each with its own data model, access controls, and governance authority.

Surface 1 · Public

Open Ledger

Financial spine. Contracts, payments, milestone evidence, outcome-budget tagging. OCDS-compliant. Public, default.

Surface 2 · Public

AI-Use Register

Every state-operated AI system. Purpose, training-data scope, performance metrics by demographic group, annual algorithmic audit, citizen contest log.

Surface 3 · Public

Karnataka Open Data Portal

Datasets + time series. KFDA forecasts, environmental sensor streams, transit data, soil-test aggregates, KDT public visualisations, mobility data. Public, machine-readable.

Surface 4 · Personal

Citizen Data Trust

Personal records: UMRS, scheme entitlements, KCIF claims, scheme application history. Citizen-private by default; aggregates only after statistical-disclosure standard.

Surface 5 · Geospatial

Karnataka Digital Twin raw store

Point clouds, building footprints, utility geometries, contour data. Closed by default; access via KDT Authority for authorised use; public derivatives on KODP.

Surface 6 · Operational

Sector operational systems

Per-department operational data. KHPA inventory, KDCDN stock dashboards, KSAMB procurement, KAEC monthly visits. Operational, not public surface by default.

The Citizen Consent Ledger

Every flow that touches your data is tokenised. You can see them all.

Every data flow through KSSL that touches a citizen's record requires a consent token issued by the citizen. The Citizen Consent Ledger is the citizen's view of every token issued, every access made, and the legal basis claimed.

Full transparency on JANATA

Which party accessed which class of your data, when, why, for how long, and under which consent token. Per access. Revocation propagates to all downstream systems within published time-windows.

Break-glass auditing

Emergency overrides bypass consent at the moment of access but trigger immediate citizen notification, 24-hour formal notice, and quarterly review-panel audit. No silent overrides.

Deletion right

Citizens hold a statutory deletion right over their personal records for data classes not under legal hold. Deletion events anchored on KSSL. Established by the Karnataka Cyber Security & Citizen Consent Act.

Zero-knowledge eligibility pilot

Year 3 — pilot of zero-knowledge eligibility proofs: a citizen proves entitlement to a scheme without revealing the underlying records to the verifying officer. Privacy-preserving public benefit.

Public verifier nodes

Civil society can audit the state without state permission.

The architecture deliberately enables civil-society organisations to run independent verifier nodes that re-verify the cryptographic-anchoring proofs. The state does not have a monopoly on integrity verification.

Open-source clients

All four front doors are open-source. Anyone can audit the client code; civil society can run their own builds.

Verifiable anchors

KSSL anchors published periodically with witness co-signatures. Any party can re-verify the chain independently. The Civil-society Independent Audit Board has statutory standing to compel disclosure for audit.

Annual algorithmic audit

Every state AI system gets an annual independent algorithmic audit. Disaggregated performance metrics by district, caste, gender, language, age. Audit summaries on the AI-Use Register.