The Platform

A knowledge engine, with professional workflow on top.

Praxis separates what the law says from the work an accountable person does with it. A maintained engine structures authoritative sources, evidence mappings and a versioned methodology; seven applications turn that into reviewable, evidence-linked assessments a lawyer, a DPO or a business owner can defend. Both halves are versioned, hash-chained and auditable end to end — the human is the only part that concludes.

The Praxis Knowledge Engine

How information becomes an accountable decision.

Seven stages, in order. Each one is where a specific kind of trust is earned or lost.

01
Source knowledge

Acts, regulations, guidelines, standards and regulatory decisions.

02
Praxis methodology

Criteria, mappings, assumptions, validation and versioned scoring.

03
Professional judgment

Context reviewed, assumptions challenged, conclusion owned.

04
Organisational knowledge

Approved templates, playbooks and review checks.

05
Client delivery

Assessments, evidence, recommendations, audit-ready outputs.

06
Safe feedback

Governed learning that never reuses confidential client material.

07
Trust

Repeated defensible delivery, compounding into reputation.

A source is not a conclusion. A methodology states its criteria, assumptions, version and limits — and every material conclusion stays explainable after the fact.
What the engine structures

Structured records, not free text.

Jurisdictions & instruments

Destinations, legal instruments, provisions and citations, held as structured records — 129 jurisdictions scored on the same 21-provision matrix.

Versions & provenance

Source versions and review status, so a finding traces to the exact text it relied on; issued assessments freeze the dataset they used.

Criteria & mappings

Malaysian-floor mappings and essential-guarantee gates framing each comparison; DEICA criteria; the three-layer notice rubric.

Change history

Recorded developments linked to the provisions, criteria and findings they may affect — so change can be connected to the work it touches.

The Applications

Seven applications on one engine —
and they hand off to each other.

A DPIA's cross-border step opens a Transfer Impact Assessment in Praxis Frontier, with the facts and evidence carried across and the finding returned to the DPIA record. A notice audit's structured findings can seed the data inventory a DPIA or TIA starts from. Every application keeps its own append-only, hash-chained audit log with a verification endpoint — and every suite plan includes all seven as each ships.

Praxis DPIA
Live

Praxis DPIA

Impact assessments on the 2026 PDPA DPIA Guideline (DEICA).

Two-tier statutory screening, a 3×3 risk matrix across principle and harm risks, mandatory mitigation for Medium and High, enforced separation of duties on approval, hashed evidence with cross-assessment reuse, and PDF reports rendered from immutable snapshots.

Explore Praxis DPIA
Praxis Frontier
Live

Praxis Frontier

Transfer Impact Assessments under s.129.

129 jurisdictions scored on a 21-provision Malaysian-floor matrix with four essential-guarantee gates, all eight s.129 conditions, Route A/B mapping, a hashed Evidence Vault, “Explain why” traceability, a three-year validity clock and a Commissioner-ready audit pack per client.

Explore Praxis Frontier
Praxis Privacy Audit
Live

Praxis Privacy Audit

Privacy-notice audit against PDPA statutory text.

Three never-blended layers (PDPA 2010 core, Act A1727 readiness, Data Protection by Design), a disclosure-weighted check on six sensitive-data categories, verbatim-quote evidence on every finding, confidence bands with a human review queue, and a Praxis Grade A–D that is explicitly not a certification. English and Bahasa Malaysia.

Explore Praxis Privacy Audit
Praxis Breach
Early access

Praxis Breach

s.12B breach notification with a live 72-hour clock.

A mobile-first wizard any employee can start on discovery: the official Annex B form mirrored question by question, significant-harm triage across the five statutory triggers, a live 72-hour countdown, a DPO review queue before anything is recorded as filed, and downstream 7-day and 30-day clocks with staged reminders.

Explore Praxis Breach
Praxis Schema
Preview

Praxis Schema

Data mapping and Records of Processing Activities.

A shared PDPA/GDPR sensitivity taxonomy with sector packs (healthcare, retail, hospitality and more), a row-per-activity register, an automatic sources → systems → recipients flow map flagging cross-border and sensitive flows, and exports built to feed DPIA, Frontier and Breach.

Explore Praxis Schema
Praxis Passport
In development

Praxis Passport

A citation-backed adequacy reference.

How closely another jurisdiction's data-protection law matches Malaysia's PDPA, scored on a 21-criterion rubric with a deterministic Adequate / Adequate with safeguards / Not adequate verdict, every rating tied to a verified quote from the source law. Borderline cases refer to Praxis Frontier.

Explore Praxis Passport
Praxis Integrity
Planned

Praxis Integrity

A public verification registry for every issued report.

A read-only registry for every DPIA and TIA issued through the suite: a unique code printed on the report that a regulator, counsel or counterparty can look up to confirm it is genuine, which methodology version it used and whether it is still valid — without exposing the report's contents.

Explore Praxis Integrity

Applications marked Early access, Preview, In development or Planned are described as direction, not availability. Privacy is the first domain of the Praxis thesis, not its limit; adjacent regulated domains are evaluated against a published market test before any commitment.

Matter Architecture

Every assessment lives inside a controlled matter.

Work is organised by client and matter, with evidence, findings, versions and approvals attached to the assessment they belong to — so records stay segregated, portable and defensible.

Client & matter
Organisation → Client → Matter → Assessment. Multi-tenant by design: a law firm's clients, or a group's entities, are separated and access-controlled per workspace, with every query scoped to the tenant.
Evidence
Supporting documents hashed on upload (SHA-256) and attached to the finding they substantiate — a chain of custody rather than a shared folder.
Versioning
Issued assessments are immutable; revisions clone and supersede, and each keeps a frozen snapshot of the dataset it relied on. Nothing is silently overwritten.
Approvals
Assessor notes, reviewer comments and qualified-person sign-off recorded against the assessment, with separation of duties enforced by the system.
Audit log
Append-only and hash-chained in every application, with a verification endpoint that lets an auditor confirm the chain is intact.
Archive
A concluded matter keeps its full history and evidence — and frees the capacity slot it occupied.
The Knowledge Boundary

What improves the system — and what never leaves your matter.

Every engagement may improve Praxis only through an explicitly governed learning pathway. The boundary is a design commitment, not a setting.

May improve the platform

Generic methodology, product workflows, validation rules, evidence mappings to public sources, non-client templates, de-identified quality signals, research gaps and workflow friction.

Never reused across clients

Client documents, personal data, legal advice, confidential commercial information, client-specific reasoning or facts, privileged communications, and any output whose reuse could reveal the client or matter.

Uncontrolled data reuse is not compounding; it is a trust failure. Lock-in must never depend on holding client data hostage — portability and fair exit treatment are constitutional commitments at Praxis.

Knowledge engine · three applications · matter architecture · audit chain

See the platform on your own use case.