MVP to Scale
From the Andhra Pradesh pilot build to a single proactive, anonymous intelligence layer that scales across verticals.
A technology document for the Board, Advisory Group, and delivery partners — product positioning, MVP delivery scope, the parallel build map, and the future-state architecture roadmap.
Be Ready.
In brief
Dimple is proactive, anonymous intelligence infrastructure — a layer that lets an institution understand and act on the wellbeing of an entire student population without ever identifying a single individual within it. Its first deployment answers a constitutional mandate in Indian education, beginning with a ~50,000-student pilot in Andhra Pradesh, but the architecture is domain-agnostic. This document moves from what the product is and why it matters, through exactly what is being built for that pilot, to where the same engine scales next — and it shows that because Dimple is anonymous yet persistent, the compliance, the intelligence roadmap and the future verticals all fall out of the architecture rather than being bolted on.
How to read this document
This document does three things, each addressed in its own section:
- Section 1 — The Product. What Dimple is, and why it is best understood not as a mental-health app but as proactive intelligence infrastructure. Its first play is education, but the architecture is domain-agnostic.
- Section 2 — MVP & Scope. Exactly what is being built for the Andhra Pradesh pilot: the MVP scope, the technical stack, the vendor position, and the agreed reference architecture. Running alongside it, the Parallel Build Map sets out the foundations, design and IP work that must happen in step with the build so the AI roadmap is inherited cheaply rather than rebuilt later.
- Section 3 — Future State. Where the same engine goes next.
It is deliberately layered. A board reader can stop at the end of each section and have a complete picture at that altitude. A technical reader can go straight to Section 2 and the governing artefacts it references. The live product positioning sits at reboundgrp.com; the working product interface is referenced throughout as the Dimple wireframes.
The Product
Every system built to help people charges the same price first: be seen. Dimple is the first that doesn't. It never holds who you are, so a person can be wholly honest the moment they're ready — and a society can see the shape of its own mind without exposing a single soul in it. One door for a schoolchild, a night-shift nurse, a father who's never said the words aloud. Not something you open when something breaks. The layer underneath, always there, meeting a whole population as people — at a scale nothing before it could reach.
1.1What Dimple is
Dimple is a proactive, anonymous wellbeing platform — but the more accurate description, and the one this document adopts throughout, is that Dimple is proactive intelligence infrastructure. It is the layer that lets an institution understand and act on the wellbeing of a whole population without ever identifying a single individual within it. Most platforms in this space are one of two things: fully identified, which is clinical, high-friction and stigma-exposed; or fully anonymous, which means no memory, no relationship and no ability to help over time. Dimple is the rare third thing — anonymous yet persistent — and that combination is the precondition for everything else it does.
The platform reaches students through STAR Station kiosks in device-restricted environments and through personal devices and PCs where students have them. It gives them a resource library built for collectivist help-seeking, asynchronous access to trained counsellors, a graduated crisis-escalation pathway, and a continuous, anonymised measure of whether they are actually getting better — the SUKHA Index. For the institution and the government above it, Dimple turns that activity into population-level foresight and one-click statutory compliance, with no individual data exposed at any point.
1.2The problem it is built for
The founding insight is uncomfortable and it is universal: the fear of being seen prevents help-seeking in every setting where consequences follow visibility. In collectivist South and Southeast Asian contexts, the admission that something is wrong is the hardest step of all — it carries family consequences, marriage prospects, community standing, and shame. By the time distress is nameable, it is often already acute.
The evidence is stark. In a recent study, 82% of students across India had access to mental-health support and not one of them used it. The help was there; being seen asking for it was not safe. This is not a resourcing problem and it is not a funding problem. It is a design problem — and it is the design problem Dimple was built to solve, by making the door disappear rather than pushing harder at it.
She knows the door is open. She is not going to walk through it. Dimple was built for the people who never walk through the door.
1.3Why now — the mandate
On 25 July 2025, in Sukdeb Saha v. State of Andhra Pradesh & Ors. (2025 INSC 893), the Supreme Court of India declared the right to mental health an integral component of the right to life under Article 21, and issued fifteen binding interim guidelines that every educational institution, coaching centre and student-centric environment in India must satisfy. The guidelines are legally enforceable under Articles 32 and 141; the Court directed every State and Union Territory to notify rules within two months and established district-level monitoring committees, chaired by the District Magistrate, to oversee compliance.
For 266 million mandated students, this creates institutional urgency at a scale no sales team could replicate. Dimple does not sell into education so much as answer a constitutional requirement that institutions cannot meet with the infrastructure they currently have. Crucially, Dimple satisfies all fifteen guidelines automatically from platform data — the architecture is the compliance, not a policy bolted on top of it. Section 2 sets out the full mapping; the headline is that the mandate is the demand engine, and Dimple is the only deployment positioned to meet it at population scale in under-resourced settings.
Source: Sukdeb Saha v. State of Andhra Pradesh (2025 INSC 893); NCRB; platform deployment figures.
1.4The architecture in one idea
Our design gives Dimple something almost no one else has: continuity without identity. A student consumes a single-use enrolment token once, then creates a pseudonym and a six-digit PIN that persist for the life of the account. Learning attaches to that durable pseudonym — never to the person. A separate, one-way hashed institute reference sits dormant and is invoked only when a counsellor escalates a case and an institute wellbeing officer authorises reconciliation. Routine use is anonymous; identity recovery is exceptional, justified, approved and logged. The two never interact, and neither can act as a back door to the other.
This is the structural advantage on which everything in Section 3 depends. An intelligence layer that comes to know a person safely requires exactly this — a stable identity to learn against, and a guarantee that the identity can never be profiled, sold or exposed. Dimple has built that guarantee into the foundation rather than promising it at the surface.
1.5The empty quadrant
Plot the field on two axes — reactive versus proactive, and identified versus anonymous — and Dimple occupies a quadrant no competitor holds: proactive and anonymous-by-architecture. Reactive identified tools wait for a person who already knows something is wrong to walk through a door that, in these cultures, they will not walk through. Even the strongest adaptive platforms personalise inside a clinical relationship, within services that already know who the young person is. Dimple personalises without identity at all. That is not a thinner version of the same product; in markets where being seen seeking help is the barrier, it is a categorically different and more honest one.
1.6Education first, not education-bound
Dimple begins in education because the need is unanswerable and the Supreme Court has made the work mandatory. But the thesis underneath is a single universal fact, and the architecture is domain-agnostic. The same proactive, anonymous, persistent engine — re-tuned — is the readiness engine for an employee, a patient, a survivor, an athlete. What changes from one vertical to the next is the calendar of pressure, the professional in the loop, the buyer of the institutional signal, and the stakes of getting safety wrong.
The strategic point is the multiplier: one readiness engine, one outcome currency in the SUKHA Index, one set of safety rails, re-pointed per domain rather than rebuilt each time. We do not build a new company for each vertical.
| Vertical | The line that names it |
|---|---|
| Education (K-12 & tertiary) | Constitutional compliance, and the platform students will actually use. |
| Workplace | The EAP they will actually use. |
| Healthcare | The conversation the doctor cannot start. |
| Domestic violence | No trace. No trail. No risk. |
| Fintech | The support they will not ask for out loud. |
| Elite sport | Strength without silence. |
| Insurance, defence, refugee, maternal health | The same unseen door, re-cut for those our systems reach last. |
1.7The outcome currency — the SUKHA Index
Every learning system needs a feedback signal: a consistent measure of whether a person is actually getting better. The SUKHA Index is that signal. It scores wellbeing across five dimensions — Support-Seeking and Self-Preparation, Uplift Trajectory, Key Risk Signals (inverted), Help Engagement and Resource Depth, and Academic Resilience — built from structured, language-agnostic inputs and computed against an anonymous account UUID. The individual score is never shown to the student and never tied to identity; it exists to personalise the experience, prioritise counsellor attention, and feed the institutional aggregate.
At the population layer the index becomes the metric governments, boards and institutional leaders track and are certified against — generated through differential privacy, k-anonymity (k ≥ 10) and calibrated noise injection, so no individual is ever exposed.
The headline measure is the Proactive Engagement Rate: the share of students using coping resources before any risk flag. It answers the question the Supreme Court is actually asking — not “does this school have a counsellor?” but “is this a place where students can be well?” — and it is the foundation of the SUKHA certification pathway, the data flywheel, and ultimately the largest culturally-contextualised wellbeing dataset in Asia.
1.8How the entity structure maps to the product
The corporate structure mirrors the commercial logic. Reboundgrp Pty Ltd is the holding entity. Rebound Dimple Pty Ltd is the commercial entity and the owner of all intellectual property, including the patent estate, the SUKHA Index and the brand. Rebound Global Ltd is the registered charitable foundation (DGR / ACNC), which funds pilot infrastructure into under-resourced communities.
Once the pilot proves the model, Rebound Dimple commercialises — beginning with education in India and expanding across verticals — while the foundation continues to carry reach into the settings that can least afford it. The intelligence infrastructure is one asset; the structure simply lets it serve both a mission and a market without compromising either.
The MVP & Scope
Near-term execution is the education vertical and the August go-live. This section defines exactly what is being built, on what stack, by whom, against which agreed architecture — and what runs in parallel to it.
The Pilot Objective
The pilot carries two objectives that work together. First, to provide a safe space for the unseen to become seen — a place where students who would otherwise go unnoticed can seek help without exposure. Second, to generate the first help-seeking longitudinal dataset created within collectivist cultures, building an evidence base that does not yet exist anywhere.
2.1The objective and the deployment
The MVP objective is a controlled, pilot-ready Dimple platform that enables anonymous student wellbeing access while preserving duty-of-care escalation pathways and aggregate reporting, deployed for the Andhra Pradesh pilot. The pilot reaches approximately 50,000 students across roughly thirty schools and colleges, under a signed MOU with the Commissionerate of Collegiate Education, Andhra Pradesh, facilitated through Australian diplomatic channels. Go-live is targeted for mid-August 2026. The pilot spans three cohorts with deliberately different access realities: urban colleges (Cohort A), residential colleges (Cohort B), and welfare hostels (Cohort C). STAR Stations serve the device-restricted environments; personal devices and PCs serve the rest. The governing test is simple — if it works here, it works everywhere.
The MVP is built around a single non-negotiable principle: a zero-knowledge separation in which anonymous platform activity stays inside Dimple and real-world identity remains under institute governance. No student identity — name, roll number, date of birth, parental contact, phone, email or Aadhaar — ever enters the platform. The product reference for the build is the current Dimple interface, captured in the wireframes.
2.2The anonymity architecture — the two-system model
Onboarding involves two systems that never share identity data. The Dimple Token Platform, operated by Rebound Dimple on AWS in-region, holds anonymous accounts and all activity. The Institute Student Database, operated by the institute, holds identity and enrolment records exactly as it already does. They are bridged by one element only: Dr. Rajendran's hashed institute reference, which is one-way and inert without governance approval. The credential model separates four jobs cleanly, and each layer does exactly one of them:
- Token — single-use enrolment bootstrap. Cryptographically signed, tied to the hashed institution code, consumed once at first onboarding, and never linked to the account UUID in any data store. It carries no identity and no credential value beyond proof of enrolment.
- Pseudonym + 6-digit PIN — persistent credential. Created by the student at the end of onboarding. The pseudonym is the username; the PIN is stored as an Argon2id hash with a per-user salt. Together they authenticate the student for the life of the account, across devices. Six digits (one million combinations) with slow-hashing and rate-limited login put the credential well outside practical attack.
- Three challenge-question hashes — in-platform recovery. Selected from a curated, translated library at onboarding; answers normalised and Argon2id-hashed with the same per-user salt. Forgotten-PIN recovery is entirely self-service, with no PII captured at any point. This handles the overwhelming majority of recovery cases.
- Hashed institute reference — governance bridge. SHA-256 over institute code, roll number and an institute-held salt that is never transmitted to Dimple. Invoked only for crisis reconciliation or last-resort PIN reset, under counsellor escalation and wellbeing-officer approval, audit-logged on both sides.
The two categories of hash — the internal credential hashes and the institute reference hash — use different salts, serve different purposes and sit under different governance. The institute-side hash cannot decrypt the PIN; the PIN hash cannot identify the student. This is the architectural claim that lets the platform be both genuinely anonymous in ordinary use and capable of a controlled duty-of-care intervention when a life may be at risk. The full ten-step onboarding journey, recovery paths and reconciliation workflow are specified in the Dimple Onboarding Flow v1.1, which is the governing reference for the build.
2.3In-scope delivery
The MVP scope is organised into nine delivery workstreams. Each is contracted, demonstrable, and mapped to a milestone in section 2.10.
| Workstream | Included scope |
|---|---|
| Mobilisation & governance | Kickoff, access readiness, delivery plan, project cadence, risk and decision register, UAT planning and stakeholder reporting. |
| Architecture & engineering foundation | Solution architecture, information model, API contracts, Java/Undertow service design, React shell, database design, repository governance and DevSecOps baseline. |
| Anonymous token & identity foundation | Token generation, validation, activation, revocation, QR/PDF output, pseudonym creation, 6-digit PIN model, challenge recovery and no-PII platform controls. |
| Student experience | STAR Station / BYOD entry, session flows, consent / age / language capture, resource library, return-user journeys and low-bandwidth UX readiness. |
| Messaging & crisis workflows | Asynchronous messaging, unread / SLA handling, counsellor queue, thread view, notes, flags, crisis button, keyword-triggered escalation and supervisor routing. |
| Admin & reporting | Admin portal, token administration, pilot metrics, operational dashboards, Saha / compliance reports, executive dashboards and PDF/Excel export orchestration. |
| SUKHA & localisation | Rules-based SUKHA aggregation, score storage, trend baseline, English / Hindi / Telugu localisation and offline-ready resource packaging. |
| AI / audio controls | Integration controls for approved AI/API and audio-to-text services, subject to client approval of provider, region, retention and usage limits. |
| Deployment, QA & handover | AWS deployment path, service availability / NFR checks, security hardening, regression testing, UAT support, documentation, runbooks, knowledge transfer and go-live readiness. |
2.4Out of scope for the MVP
Scope discipline protects the August date. The following are explicitly out of scope unless separately contracted through change control: production cloud charges, AI/API usage charges, third-party licence fees and SMS/email gateway charges; new feature development or enhancements beyond the agreed MVP; Australian-rate onsite or local Australian delivery staffing; institute-side remediation, data cleansing, clinical policy design, formal legal or privacy advice, and independent security certification; and post-warranty production support, managed services and enhancement releases beyond the optional support model. None of these are abandoned — several appear in the Parallel Build Map as parallel workstreams or in Section 3 as roadmap — but none of them sit on the critical path to go-live.
2.5Technical scope and stack
The MVP uses a modular, privacy-first architecture that separates the student experience, workflow orchestration, domain services, connector surfaces and state layers, so that anonymity and escalation controls remain enforceable at the boundary rather than as a matter of policy. The agreed stack is:
| Layer | Technology | Responsibility |
|---|---|---|
| Experience | React web (STAR Station / BYOD) | Student journey, counsellor workspace, admin portal. |
| Services / API | Java / Undertow | Token & session services, messaging & crisis workflows, SUKHA and reporting. |
| System of record | PostgreSQL | Durable records — accounts, credentials (hashed), activity. |
| Cache / session | Redis | Session handling and caching. |
| Events / audit | Apache Kafka | Event stream and immutable audit trail. |
| Object storage | Object storage (AWS) | Reports and assets. |
| Deployment | AWS India region | Single in-region deployment path for the MVP application. |
The component architecture is layered so that workflows decide sequence, domains enforce rules, connectors isolate outside systems, and persistence stores approved state only. The four bounded domains — Token, Identity, Counselling and Resource — each carry clear privacy responsibilities, with an Audit & Security domain maintaining the evidence trail. External connectors (the institute database, approved AI / speech services, email / SMS, and AWS services) are isolated behind the connector surface so that no outside system can reach into the state layer directly. Communication is via REST APIs, asynchronous polling, and Kafka events, with batch token and report generation.
Security, privacy and compliance commitments
- No-PII logging rules apply across application logs, analytics, support workflows and operational reports.
- TLS, encryption at rest, secrets management, role-based access control and audit logging appropriate to the MVP scope.
- Absolute separation between Dimple anonymous activity and institute-held real-world identity records; routine use never crosses the boundary.
- AI / audio usage restricted to approved providers, approved regions, agreed retention rules, usage caps and human-review workflows.
- Only aggregate reporting is exposed for pilot governance and compliance; individual student data is never exposed in dashboards or standard reports.
The governing technical artefacts for this scope are the Technical Requirements Document v1.2 (with comments actioned), the Technical Architecture Deck, the Statement of Work, and the Onboarding Flow v1.1. The Statement of Work is the execution-ready contract that converts the agreed proposal, addendum, architecture and requirements into delivery obligations and acceptance mechanics.
2.6The vendor position and the agreed reference architecture
The technical scope in this section is not a single vendor's proposal; it is the convergent architecture that emerged from a structured two-vendor evaluation across Memorres and Kairiz. Both vendors were taken through the same requirements, the same anonymity model and the same onboarding architecture. That process did two valuable things: it stress-tested the design against two independent engineering perspectives, and it surfaced the scope boundaries that the final contract had to close — most notably the persistent-identity model (token-as-bootstrap, pseudonym and PIN as credential) that the build must implement in full.
Kairiz Technology is confirmed as the MVP build vendor, on a fixed-price professional-services basis payable against milestone acceptance. The selection reflected scope completeness, a pre-existing network relationship relevant to the pilot, and delivery proximity. Memorres was declined with thanks; the evaluation work it contributed nonetheless sharpened the agreed reference architecture that Kairiz now builds against. The intellectual property position is unambiguous: all business-related IP, product concepts, requirements, workflows, wellbeing content, branding, pilot data, student and institute-related data, reports, dashboards and derived insights remain the exclusive property of Rebound Dimple Pty Ltd, and the build partner may use client data only to perform services under the SOW.
2.7Parallel build opportunities
The ten-week engineering build is the critical path, but it is not the whole programme. Several workstreams can and should run in parallel, so that go-live lands with the surrounding system already in place rather than waiting on it. None of these depend on the core build completing first; each de-risks the pilot or extends its value. The full coordination of these tracks — and the architectural decisions that must be locked before they freeze — is set out in the Parallel Build Map that follows this section.
- Resource library and cultural localisation. Production and cultural validation of the eight resource categories in Telugu, Hindi and English. Localisation is not translation — each resource is reviewed for cultural resonance through the SUKHA Council and cultural-advisory process.
- Counsellor network and DAC certification. Onboarding the Telugu-speaking counsellor cohort (via the CCI partnership) and finalising the accredited Dimple counsellor course, co-endorsed with Monash and the University of Melbourne.
- STAR Station hardware and kiosk hardening. Android-tablet provisioning, locked kiosk-mode configuration, QR camera integration and Telugu Unicode rendering, validated on the specific hardware selected for the pilot.
- Research instrumentation for validation. Folding the Monash validation-study design into the platform from day one, so the detection and outcome hypotheses are testable on real pilot data rather than asserted later.
- Compliance reporting engine. The one-click Saha compliance report (admin-portal Module 05) draws entirely on platform data; its specification and report formats can be finalised in parallel with the data layer it reads from.
- IP and post-quantum workstream. The patent and freedom-to-operate work (Section 3.9) proceeds on its own timeline against the October 2026 Paris Convention deadline, independent of the pilot build, and feeds claim construction rather than code.
2.8TRD modifications and the persistent-identity addition
The Technical Requirements Document has moved from v1.0 to v1.2, with Dr. Rajendran's review comments processed and actioned. The most consequential modification is architectural rather than cosmetic: the credential model in v1.1 of the onboarding flow, which the TRD and SOW now both reflect.
v1.0 treated the token as the credential — used once to create an account the student could not return to. That satisfied anonymity and controlled escalation but failed the third requirement Dimple cannot do without: continuity. Hyperpersonalisation is the reason the platform exists; it cannot be a Phase 2 enhancement layered on later, because the Be Ready companion needs a stable relationship to learn against. The v1.1 model resolves this. The token becomes a single-use enrolment proof; the pseudonym and PIN become the persistent credential; challenge questions become recovery. The student's account is theirs for the life of the platform, across devices and years, with no PII ever entering the Dimple environment.
Critically, this evolution does not breach the patent's central claim. The zero-knowledge separation between the Token Data Store and the User Activity Data Store remains absolute; the token remains single-use and unlinked to the UUID; the hashed institute reference still cannot be reversed by either side acting alone. The credential model adds depth without breaching the architecture. A short note to Mulla & Mulla ensures the persistent-identity and challenge-question architecture is captured cleanly in the Indian complete application ahead of the October deadline.
Consent and the SUKHA Index modifications
Two consent items were added to the MVP onboarding record as direct consequences of persistent identity: consent to a persistent pseudonymous identity (pseudonym and Argon2id-hashed PIN), and consent to challenge-question recovery (three questions and their hashed answers, used only for student-initiated PIN recovery). The clinical-assessment items proposed earlier — an ADHD/ASD intake questionnaire and a social-media/gaming education module — remain referred to the SUKHA Council and are not part of MVP onboarding. On the measurement side, the SUKHA scoring model (v3) raises the weighting of proactive resource engagement and introduces the +5 readiness bonus for pre-crisis, multi-category engagement — the mathematical expression of the Be Ready philosophy, tunable on pilot data.
2.9Saha compliance — the architecture is the compliance
The pilot's statutory anchor is the fifteen Saha guidelines, mapped guideline-by-guideline to platform capability, data source and automation level. The admin portal must generate a one-click PDF/Excel report demonstrating compliance against all fifteen from platform data alone, in a format that satisfies district-level monitoring committees, with every figure population-level only.
| Automation level | Guidelines | What this means |
|---|---|---|
| Fully automated | I, II, III, IV, V, VIII, X, XV (8 of 15) | Compliance is computable entirely from platform data with no manual input — including the anonymity-by-design guidelines (no performance segregation, confidential reporting) that are architectural, not policy-dependent. |
| Partially automated | VI, VII, IX, XI, XII, XIII (6 of 15) | The platform tracks and reports the digital components (training completion, content engagement, reporting mechanisms); offline institutional actions are monitored via self-certification with date stamps and admin sign-off. |
| Tracking only | XIV (1 of 15) | Physical-infrastructure requirement outside platform scope (e.g. tamper-proof fittings); the portal carries a self-certification checklist. |
Guideline IV is the clearest illustration of the thesis: because the platform is anonymous by design, performance-based segregation, public shaming and ranking are not merely discouraged — they are architecturally impossible. Compliance there is a property of the system, not a promise about behaviour.
2.10Delivery, milestones and acceptance
Delivery runs over a ten-week schedule, with an accelerated demonstrable baseline targeted by Week 8 and full MVP delivery, UAT, hardening, documentation and go-live readiness through Week 10. Five milestones gate the work, each accepted on demonstrated outcomes, resolution or formal deferral of material defects, and written client acceptance:
| Milestone | Weeks | Outcome |
|---|---|---|
| M1 — Mobilisation, governance & architecture | 1–2 | Mobilisation, repository governance, access model, delivery plan, information model and architecture confirmation. |
| M2 — Student core & token foundation | 3–4 | Anonymous token system, issuance/validation, STAR Station entry, session flow and resource-library foundation. |
| M3 — Messaging, crisis & operational workspaces | 5–6 | Async messaging, SLA tracking, crisis button, keyword escalation, counsellor queue and admin foundation. |
| M4 — SUKHA, compliance, localisation & offline readiness | 7–8 | Rules-based SUKHA aggregation, compliance reporting, Telugu/Hindi/English support, offline readiness and approved AI/audio controls. |
| M5 — Security, QA, UAT & go-live readiness | 9–10 | NFR, service availability, security hardening, regression, deployment validation, UAT support, handover pack and go-live readiness. |
Governance runs on a weekly governance review and twice-weekly delivery status cadence, with milestone acceptance reviews as the formal demonstration and payment-trigger points, and structured UAT coordination throughout. Defects are classified Critical / High / Medium / Low, with Critical (including any material privacy or security exposure) resolved before milestone acceptance unless a written workaround is agreed. A thirty-day project warranty applies to delivered MVP functionality that materially deviates from accepted scope, with optional application support available thereafter. The commercial structure is fixed-price against milestone acceptance, in INR, with cloud, AI/API, third-party, travel and FX costs excluded — and is governed by the signed master agreement for legal terms, with the SOW governing scope, delivery and acceptance.
The Parallel Build Map
Items to progress alongside the Kairiz Phase 1 MVP to prevent rework, rescoping and rebuild — the cheapest version of the entire AI roadmap is the one whose foundations were set correctly in the first two weeks.
The Kairiz SOW completes M1 (Mobilisation, Governance and Architecture) in Weeks 1–2, and the acceptance trigger is client sign-off on the information model, architecture direction and ER diagrams. That sign-off is the point at which the MVP data model, event schema and privacy boundaries freeze. Almost everything in the future-state roadmap that could otherwise force a rebuild is a consequence of decisions taken in those first two weeks. Anything the AI layer should inherit cheaply must be folded into the information model before it is signed off — after which it becomes change control under SOW §14, the rescoping and rebuild cost we are trying to avoid.
The parallel work divides into four streams: (A) architecture foundations to confirm into the MVP information model now; (B) clinical, content and data-science design Rebound can run with no Kairiz dependency; (C) IP, legal and governance tracks that are time-critical and independent; and (D) a deliberate “do-not-build” list, because building Phase 2 features speculatively is the other way to force rebuilds.
Owned by Kairiz Technology + Nathan + Dr. Rajendran (joint technical owner), with measurement input from the SUKHA Council. All items must be on the table during Weeks 1–2 and reflected in the M1 information model, API contracts and ER diagrams. These are where retrofitting is most expensive — and in two cases (A1, A3) the lost data is unrecoverable.
| # | Foundation to confirm | Future-state capability it protects | Cost if omitted from M1 |
|---|---|---|---|
| A1 | Forward-compatible behavioural event taxonomy. A structured, timestamped event stream on the anonymous UUID — resource opened/completed, dwell, return visit, check-in, help-seeking, quiet-period onset — captured in Kafka/Postgres from day one. | JITAI nudges, engagement-timing, topic heatmaps, the resource-efficacy flywheel, distress forecasting and the contagion signal — effectively all of Altitudes 1 and 3. | Catastrophic & unrecoverable. Behavioural history cannot be back-filled; without it the pilot's entire training signal is lost. The highest-leverage item in this document. |
| A2 | Per-pseudonym “learning / profile state” container. An extensible, UUID-bound state structure reserved in the model — empty in the MVP, but structurally present so personalisation can attach later without a schema migration. | Token-bound learning (the Altitude 1 keystone), the weekly readiness program, anticipatory readiness, and anonymity-preserving personalisation (an IP candidate). | High. Adding a durable profile model to a live, anonymised system is a data-model migration, not a feature add. |
| A3 | Longitudinal SUKHA Index time-series. Store SUKHA as a timestamped per-UUID series retaining sub-dimensions, with cohort aggregation derived from it — not only a rolled-up score. | The resource-efficacy flywheel, distress forecasting, SUKHA Forecast, and the insurance/actuarial outcome-signal line. | High & partly unrecoverable. A longitudinal signal cannot be reconstructed from snapshots you never stored. |
| A4 | Granular, versioned, purpose-scoped consent. Consent modelled as a structured, versioned object (personalisation, context-capsule hand-off, family bridge, research use) rather than a single flag. | Consent-gated context capsule, Family Bridge, the research engine — and DPDP purpose-limitation compliance. | Medium–high. Re-modelling consent on a live pilot means re-consenting the cohort. Largely defensible as already-implied scope under DPDP. |
| A5 | User-owned erasure / data-sovereignty boundaries. Per-UUID ownership and erasure/tombstoning designed across Postgres, Kafka and object storage so a pseudonym's data can be fully wiped on request. | User-owned erasable memory and the DPDP right to erasure. | High if retrofitted. Erasure that has to chase data through event logs and object storage after the fact is a re-engineering job. DPDP 2025 Rules arguably require it regardless. |
| A6 | AI/audio gateway built as a real control plane. Build the approved-AI/audio surface as a proper provider-abstraction gateway carrying the governance controls already named (provider, region, retention, usage caps, human review, audit) — not a thin stub. | Every Phase 2 AI feature — JITAI generation, ambient note-taking, triage, the bounded companion — plugs into a ready socket. | Medium–high. A stub gets thrown away. Depends on the provider decision (C3), currently flagged “Azure OpenAI / OpenAI / Claude” pending. |
| A7 | Research-ready de-identification overlay. Ensure the no-PII event stream (A1) is captured in a cleanly de-identifiable, exportable form for aggregate and synthetic-dataset generation. | The privacy-preserving research engine, the Monash validation study, and the cohort signals. | Lower if A1 is done well. Mostly a discipline overlay on A1, but worth naming so it is not lost, given the Monash pathway. |
These run alongside the 10-week build with no Kairiz dependency. If they are not progressed in parallel they become the bottleneck that delays Phase 2. B1 in particular is on the critical path — it is the design input that lets A1 and A3 be specified properly before M1.
| # | Parallel design track | Why it must run now | Suggested owner |
|---|---|---|---|
| B1 | Measurement & event-taxonomy design. Define which behavioural signals matter, the vulnerability windows, the SUKHA sub-dimensions and engagement metrics — the design that feeds A1 and A3. | Critical path. A1 cannot be specified well without it, and A1 closes at M1. The bridge between Workstreams A and B. | SUKHA Council (Pritha Mani, Kerryn Pennell) + a data scientist |
| B2 | Weekly readiness program + JITAI content/rules library. Author the micro-interventions (cognitive restructuring, problem-solving, self-compassion, gratitude) mapped to the eight categories and to vulnerability windows (exam block, results day, seasonal dip). | Long-lead content. Building it now means the library exists when Phase 2 engineering begins, rather than becoming the delay. | Pritha Mani / SUKHA Council; Pallavi Sharda (content, micro-drama) |
| B3 | Multilingual validated risk lexicon. A native-speaker-reviewed, clinically validated crisis-keyword and escalation lexicon across Telugu, Hindi and English. | Strengthens the MVP crisis flow (a Week-1 prerequisite anyway) and is the foundation for Phase 2 triage. The deeper validated build should not wait. | CCI Telugu-speaking counsellors (pilot cohort of fifteen) + clinical lead |
| B4 | Distress-forecasting & contagion-signal methodology. Define the velocity-of-distress metric, the statistical fingerprint of a forming cluster, and the alert thresholds — as a method that runs on A1/A3 data once the pilot generates it. | Does not need the MVP to exist — only the data model defined. Doubles as substance for the Monash partnership and validation study. | Monash working party (Abbi Sharma) / validation study |
| B5 | SUKHA Forecast / cohort-mirror product definition. Define the institutional-foresight outputs — what an institution receives, at what cadence, with what recommended actions. | Lighter-touch, but defining it early ensures the MVP reporting model (dashboards, PDF/Excel exports) is shaped not to preclude these. | Product + clinical |
Time-critical and independent of Kairiz delivery. C1 and C3 in particular have hard external clocks.
| # | Parallel track | Why it must run now | Suggested owner |
|---|---|---|---|
| C1 | IP filing — personalisation, context capsule, covert-mode. Coordinate patent claims with the A2/A4 architecture so design and claims align. Anonymity-preserving personalisation is flagged as a strong candidate alongside the Section 3(k) strategy. | Hard deadline. October 2026 Paris Convention window; filing must precede public disclosure. Architecture and claims drafted together, not sequentially. | Mulla & Mulla / Ritwik Rao + Dr. Rajendran + Todd |
| C2 | Responsible-AI & safety governance framework. Author the seven non-negotiables plus the responsible-AI layer: explainability, multilingual bias monitoring, audit trails, pre-deployment harm-testing and APA-aligned AI-disclosure rules. | Must exist before any youth-facing AI ships. Also a procurement asset in a government market — trust is the thing being bought. | Todd + Nathan + Dr. Rajendran + governance |
| C3 | AI + audio provider / region / retention decision. Resolve the pending “Azure OpenAI / OpenAI / Claude” choice and the audio-to-text provider, with DPDP region and retention constraints and a cost model. | Unblocks A6 and milestone M4 (Weeks 7–8). If unresolved, the AI/audio control surface stalls or is built against the wrong assumptions. | Todd, with Dr. Rajendran and privacy/legal |
| C4 | DPDP consent-and-erasure legal posture. Confirm the A4 consent and A5 erasure models against the DPDP Act (2023) and 2025 Rules so the MVP foundations are compliant by design. | Aligns the legal position with the architecture decisions while they are still cheap to change — before M1 sign-off. | Legal / privacy + governance |
Mitigating waste cuts both ways. Nothing youth-facing ships ahead of its safety testing, and the Phase 2–4 features depend on pilot-scale data and clinical validation. Building these now — as opposed to the foundations (A), design (B) and IP/governance (C) above — is the other route to rework. Parallel effort should lay sockets and author content, not deliver speculative features. The following stay out of the MVP:
- The bounded companion / conversational layer — gated behind safety testing (Phase 2–3).
- The live JITAI delivery engine — the content and rules (B2) are authored now; the engine is Phase 2.
- Vernacular voice-first access — Phase 3, tied to the STAR Station footprint.
- The Family Bridge and precision routing / health triage — Phase 3–4, requiring cultural and clinical validation.
- All vertical expansion (workplace, healthcare, DV covert-mode, fintech, insurance, sport) — same engine re-tuned later; only the IP groundwork (C1) touches it now.
- Circulate Workstream A to Kairiz and Dr. Rajendran this week so A1–A7 are reflected in the M1 information model, API contracts and ER diagrams — not raised later as change control. Flag A1 and A6 as the two items most likely to carry genuine scope, so they are priced in now.
- Stand up B1 (measurement & event-taxonomy design) immediately. It is the critical-path input to A1 and A3, and both close at M1 in Week 2.
- Resolve C3 (AI/audio provider, region, retention) well ahead of M4 (Weeks 7–8), so the gateway in A6 is built against a settled decision.
- Sequence C1 (IP) with the A2/A4 architecture, drafting claims and design together, ahead of the October 2026 filing window.
- Treat Workstream D as a standing scope discipline — review any mid-build request against it before it reaches change control.
One line to take away: the cheapest version of the entire AI roadmap is the one whose data model, event schema, consent and erasure boundaries were set correctly in the first two weeks of the MVP. Everything in Workstream A is an attempt to spend a little now to avoid rebuilding a lot later.
The Future State
We are not building a chatbot that waits for someone to break and then responds. We are building a readiness engine — to put the user ahead of the parade, before the exam, before results day, before the crisis that currently arrives unannounced and unsupported.
3.1The reframe — a step ahead, not a step behind
Almost every digital mental-health tool on the market is reactive by design: a door you walk through once you already know something is wrong. That model fails precisely the people Dimple serves. The future-state thesis is to move the moment of help earlier — to meet readiness, not crisis. Picture it from the student's side. They create a pseudonym. Over weeks, Dimple comes to know that pseudonym — never the person — through what they engage with, what they return to, when they go quiet, and how their SUKHA Index moves. It sets them a rhythm across the physical, mental and social, the way a good coach prepares an athlete for a season they can see coming. When exam block approaches, the student is already prepared. When the dip after results day is statistically likely, Dimple is already alongside. This is the difference between surveillance and preparation — and between a product people tolerate and one they trust.
3.2Where the field is going
Five currents in health technology are converging on exactly the space Dimple occupies. Read together, they explain both the opportunity and the discipline required to take it.
The field is converging on adaptive, anticipatory care
The most credible players in youth mental health have stopped betting on static self-help libraries. The consensus direction — backed by significant new investment, including from Orygen and Wellcome — is adaptive personalisation paired with human support, at scale. That validates Dimple's core wager. Where Dimple departs from the field is the route: it reaches the same destination without identity, which for these markets is the more honest path.
The counsellor's desk is being automated, and the evidence is strong
Ambient AI scribes crossed from novelty to near-standard of care during 2025. A three-arm randomised trial of 238 outpatient physicians published in NEJM AI found that leading scribe tools meaningfully reduced documentation time and burnout against usual care, with health systems reporting roughly thirty minutes per provider returned each day. For a market with 0.75 psychiatrists per 100,000 people and a treatment gap measured between 70% and 92%, this is not a productivity story — it is a capacity story. Every minute a counsellor does not spend writing is a minute returned to a young person.
The intervention itself is becoming time-aware
The research frontier is the just-in-time adaptive intervention (JITAI): delivering the right micro-intervention at the optimal moment and context, informed by patterns in a person's own data. Studies through 2025 show that brief, well-timed cognitive techniques — cognitive restructuring, problem-solving, self-compassion, gratitude — drive the highest engagement. This is the scientific name for what Dimple describes as its weekly readiness program: not content waiting in a library, but the right nudge arriving at the right hour.
The safety reckoning has already happened to others
Through 2025, consumer AI companions collided with youth mental health in the worst possible way. A survey found 72% of US teenagers had used AI chatbots as companions; two adolescent deaths were linked in litigation to companion chatbots that validated harmful thinking; the US Federal Trade Commission opened a formal inquiry; 44 state attorneys-general wrote to the major AI companies; and the American Psychological Association issued advisories warning that AI must never pose as a licensed professional, must not use engagement-maximising design on developing minds, and must never substitute for human care. The companies that got hurt built for engagement. Dimple builds for readiness and escalation — and can enter this space having designed in what others are now retrofitting under subpoena.
The Indian regulatory and infrastructure context
Our first market is moving fast and in our favour. Tele-MANAS operates across more than ten regional languages, but its automated layer remains a rule-based chatbot that mostly routes to humans. The Digital Personal Data Protection Act (2023) and its 2025 Rules now impose consent, purpose limitation, data minimisation, breach notification and fiduciary accountability on anyone handling sensitive health data. The strategic reading is clear: government has built the rails and named the gap, but the proactive, personalised, vernacular layer does not yet exist — and Dimple's anonymity architecture is not a compliance liability under DPDP, it is the cleanest possible answer to it.
3.3Dimple's unfair advantages for AI
Generic AI features are not a strategy; anyone can add a chatbot. The case for Dimple's intelligence layer rests on five assets that are structural to how the platform is already built and that competitors cannot bolt on after the fact: anonymous yet persistent identity (continuity without identity — the precondition for an AI that can know you safely); a hybrid of shared and personal access (STAR Stations plus devices reach the lowest-resourced cohort that app-only competitors structurally miss); a population layer that sees patterns no individual-download app can; cultural specificity as a moat, because collectivist stigma dynamics are the product thesis rather than an afterthought; and a proprietary outcome signal in the SUKHA Index paired with a human counsellor network that keeps the AI honest and safe. Together they close the loop — measure, intervene, learn, escalate.
3.4Four altitudes of readiness
In education — the first and mandated market — Dimple's AI develops across four altitudes, each with its own form of readiness. They share infrastructure but serve different actors, and the same four recur, re-tuned, in every other vertical.
| Altitude | Be Ready means… | Capabilities |
|---|---|---|
| 1 — The individual | Dimple learns your pseudonym and prepares you before life arrives. | A weekly readiness program across physical, mental and social domains; just-in-time nudges timed to predicted vulnerability windows; anticipatory readiness that pre-positions support where a dip is statistically likely; a bounded companion that is explicitly an AI, escalation-first, never a substitute for human connection. |
| 2 — The counsellor | The counsellor walks in prepared and leaves without paperwork. | Ambient note-taking that returns ~30 minutes per practitioner per day; issue identification and triage support; resources generated in the moment; supervision-at-scale that raises the floor of care across a thinly-spread workforce. |
| 3 — The cohort & institution | The institution sees the wave before it breaks. | Engagement-timing signals; topic heatmaps; distress forecasting around predictable pressure periods; resource-efficacy measurement against the SUKHA Index so the library improves itself — all anonymised by design. |
| 4 — The health system | The right specialist, sooner. | Precision routing that matches an engager to the appropriate level and specialty of care — stepped from self-help to peer support to counsellor to specialist — by genuine need, without over-medicalising. |
The benchmark worth measuring against is MOST. In December 2025, Orygen and the University of Melbourne secured A$14 million from Wellcome to evolve their Moderated Online Social Therapy platform into MOST-Nexus, billed as the world's first hyper-personalised adaptive platform for youth mental health, already embedded in more than 400 services. Two things follow. First, the strongest player in the space confirms the direction of travel. Second, and decisively, MOST is identity-bound and service-integrated — it personalises inside a clinical relationship, within services that already know the young person. Dimple personalises without identity at all. We are not a smaller MOST; we are the platform for everyone MOST's model cannot reach. That Monash sits on the MOST-Nexus grant — the institution we are courting — is all the more reason to articulate our anonymity-first position with confidence rather than blur it.
3.5One architecture, many readinesses
Across every vertical the same four altitudes hold: a readiness engine for the individual, a co-pilot for the professional, foresight for the institution, and precision routing into the wider system. What changes is the calendar of pressure, the professional in the loop, the buyer of the signal, and the stakes of getting safety wrong. Each vertical is grounded in its own specific failure mode and carries at least one novel move that is distinctively Dimple's.
| Vertical | The thing they never had | The novel move |
|---|---|---|
| Education | A forming suicide cluster, made visible in time to act — not explained after a death. | The contagion-aware cohort signal: monitoring the velocity of distress across an anonymised cohort to flag a cluster forming around known cliff-edges, before contagion takes hold. |
| Workplace | An honest, real-time read of how the workforce actually is — because no one signs their name to it. | The living engagement signal: a continuous, anonymous read of team-level climate and a restructure shock-absorber that pre-positions support the moment a layoff is announced. |
| Healthcare | The patient who tells you what is really wrong, before the tenth unexplained visit. | The somatic-to-psychological bridge: recognising the repeat-somatiser pattern and, with consent, opening the door the clinician cannot — see 3.6. |
| Domestic violence | A way to reach for help that leaves no trace an abuser can find. | Covert-mode by design: a disguised entry path with a duress code, no recoverable trail, and embedded danger-assessment that escalates to human-led safe-planning. |
| Fintech | Sight of the moment financial stress turns into crisis — early enough to reach them in it. | The distress-intercept: detecting where the wellbeing dip and the money spiral intersect and routing to legitimate debt and welfare support, away from predatory lending. |
| Insurance | Proof that prevention pays: a mandated benefit that finally yields a number an actuary can use. | The SUKHA Index as a population outcome signal that prices the effect of a preventive benefit — rewards never penalties, aggregate-only, DPDP-clean. |
| Elite sport | Foresight at the cliff-edge — the career-ending transitions seen coming. | The transition-cliff engine: pre-positioning readiness around de-selection, long-term injury and retirement, tuned to the competitive calendar, delivered anonymously. |
Value levers draw on published benchmarks (WHO/Lancet on mental-health return on investment, turnover-cost and debt–mental-health findings); Dimple's own figures will come from the Andhra Pradesh pilot.
3.6The healthcare referral vertical (HC-01)
Healthcare is the natural second expansion of the same engine, and the strategic memorandum that develops it (HC-01) is worth carrying into this roadmap because it proves the category. India does not have a shortage of doctors so much as a routing failure. Patients bypass the lower tiers of a system they do not trust and arrive — unfiltered and without history — at tertiary hospitals that should be the last resort, not the front door. The bill lands on the patient: out-of-pocket spending is roughly 47% of total health expenditure, about half of care-seeking households face catastrophic expenditure, and outpatient care is more impoverishing than hospitalisation.
A decisive share of that misrouted demand is not a physical-health problem at all. It is psychological distress presenting as bodily pain — somatisation — routed endlessly through diagnostics that never reach the cause. Against a measured mental-health prevalence above 10% and a treatment gap on the order of 85%, depressive, anxiety and somatisation presentations account for a very large share of primary-care attendances. This is the most under-served, highest-leverage flow in the entire referral problem, and it is precisely the flow Dimple was designed to detect.
The case for now rests on three facts converging. The national rails exist and are at population scale: ABDM has crossed 90 crore ABHA accounts and over 100 crore linked records, and its Unified Health Interface is explicitly designed as an open, interoperable network — “UPI for health.” What the rails conspicuously lack is an intelligence layer that is both proactive and stigma-free; ABDM moves records only once a person has entered formal care and consented, and being identity-linked by design, it offers no comfortable path for a stigmatised problem. And we are not starting from scratch — the pre-assessment engine, the persistent pseudonymous identity, the token system, the kiosk footprint and the SUKHA framework are being built now for education. There is a board-level asymmetry worth stating plainly: UHI is modelled on UPI, and the architect of UPI sits on this board.
The mechanism is four moves: proactive pre-assessment that flags emerging distress before it peaks (detection-and-flagging, not diagnosis); anonymous disclosure of root causes people will not voice at a local clinic; consent-gated context capsules that hand the receiving clinician the context the current system loses, carrying the psychological signal forward and breaking the unexplained-symptom loop; and precision routing that directs high-acuity and root-cause-identified cases to the right provider while holding minor issues at the primary level. Dimple does not compete with the national infrastructure — it is the intelligence layer that sits over it, bridging into the ABHA/UHI rails only at the moment the user consents to enter care.
We do not need to build those rails. We need to be the intelligence that runs over them — proactive, precise, and anonymous.
3.7Net-new innovations to own
Beyond systematising the obvious, the following are genuinely differentiated ideas — several defensible as intellectual property — that exploit Dimple's specific architecture rather than chasing the field. Most are cross-vertical: they strengthen education first but apply wherever the architecture goes. They are sequenced loosely from nearest-term to most ambitious.
- Anonymity-preserving personalisation. An AI that personalises against the token, never the identity — the inverse of the surveillance model that just got the consumer apps into trouble, and a strong candidate for patent protection. “Hyper-personalisation without identity” is a category claim almost no one else can make.
- The consent-gated context capsule. A one-way bridge from anonymous to named care, surrendered only by the user, deliberately — resolving the anonymity-versus-continuity tension every other platform treats as either/or.
- SUKHA Forecast — distress weather for institutions. A forward-looking forecast an institution receives ahead of predictable pressure periods, with recommended pre-positioning of resources. It reframes wellbeing from autopsy to meteorology.
- The Family Bridge. A collectivist-aware capability that helps a young person navigate the hardest part of their context — talking to family — and, separately and only with consent, offers parents psychoeducation without ever breaching the child's anonymity. In our markets it may be the single most valuable thing we offer.
- The resource-efficacy flywheel. A closed loop in which the AI continuously learns which resources move the SUKHA Index for which profiles, promotes what works, and retires what doesn't — a moat that widens with every interaction.
- The anonymous cohort mirror. Safely showing students they are not alone (“most students felt exam pressure this week”) using anonymised peer signals. In a stigma-heavy setting, normalisation is itself a clinical intervention only a population-scale anonymous platform can deliver responsibly.
- Vernacular, voice-first access. A speech-first layer for low-literacy and rural hostel cohorts — the segment text-and-app competitors structurally miss, and the one the STAR Station footprint is uniquely placed to serve.
- The privacy-preserving research engine. De-identified and synthetic datasets of South and Southeast Asian youth wellbeing that do not exist anywhere — a research moat aligned to the Monash partnership, a training asset, and a future data-licensing line, all without compromising a single individual.
- User-owned, erasable memory. The user can review and wipe everything Dimple has learned about their pseudonym, at any time — the exact opposite of the permanent psychological profile the APA warned about, and a trust advantage at the point of use.
- Responsible-AI layer as a procurement product. Explainability, bias monitoring across language, gender and community, audit trails and pre-deployment harm testing, built in and then sold as assurance. In a government market, trust is not overhead — it is what procurement is buying.
3.8What the AI layer needs
The intelligence roadmap is only buildable because four foundations are being laid now, in the MVP. Naming them precisely is how the board can hold the difference between what is aspiration and what is already under construction.
- A stable identity to learn against. The persistent pseudonym (2.2, 2.8) is the precondition for any compounding relationship. Without continuity, every session starts from zero and personalisation is impossible. This is built in the MVP, not deferred.
- A consistent outcome signal. The SUKHA Index gives the learning system its feedback loop — a language-agnostic measure of whether interventions are working, captured against the UUID and aggregated under differential privacy. Its structured-input design is what makes the data layer trainable across languages later.
- A human network in the loop. Risk detection — including multilingual crisis-keyword work — is led by native-speaking counsellors, with the AI augmenting rather than replacing human judgement. The CCI counsellor cohort is onboarded in parallel.
- A safety architecture that holds it all. Every capability in this roadmap is permissible only because it sits inside the non-negotiable safety frame in 3.10. The companion layer is gated behind safety testing; nothing youth-facing ships ahead of it, regardless of phase.
The phasing of capability onto these foundations is set out in 3.11. The discipline is constant: the MVP builds the foundations; the intelligence layer is sequenced on top of them only as the data, the human network, and the safety testing allow.
3.9Quantum thinking — protecting the position for the decade ahead
The whole strategy rests on a cryptographic foundation, and the most disciplined thing a technology document can do is name where that foundation is exposed and how the exposure is being closed. Two workstreams, commissioned to Dr. Rajendran through QClairvoyance, do exactly this — and both feed the Indian complete application ahead of the October 2026 Paris Convention deadline, while the specification is still in draft and claim construction can extend the patent's useful life.
Workstream 1 — the post-quantum migration path
Dimple's token architecture currently specifies SHA-256 and HMAC-SHA256 as its cryptographic foundation. These are robust today, but the trajectory of quantum computing makes their eventual obsolescence a mathematical certainty — a realistic horizon of seven to fifteen years for cryptographically relevant capability, against an architecture meant to be embedded institutionally for the long term. NIST has already standardised post-quantum algorithms — CRYSTALS-Kyber for key encapsulation, CRYSTALS-Dilithium for digital signatures, and SPHINCS+ for hash-based signatures. The workstream answers three questions: which post-quantum family is the appropriate replacement for each cryptographic function; whether the current architecture can support algorithmic rotation without structural change — and therefore whether algorithmic agility should be claimed as a forward-looking dependent claim; and whether the Indian specification should reference post-quantum readiness explicitly to extend its defensive window. Treating algorithmic agility as a claimed property, rather than a future migration project, is the move that protects the estate without forcing a rebuild later.
Workstream 2 — freedom-to-operate against the credible usurpation vectors
The patents protect a specific architecture and its technical effect; they do not protect the outcome — anonymous verified institutional access — against a competitor who reaches the same outcome through a sufficiently different topology. Three emerging identity architectures represent the most credible such vectors, and a formal freedom-to-operate analysis is commissioned against each: W3C Verifiable Credentials and Decentralised Identifiers, which allow selective disclosure of institutional affiliation without any token being generated; zk-SNARK and zk-STARK zero-knowledge proof systems, which could prove enrolment without revealing identity and without a token at all; and self-sovereign identity frameworks such as Hyperledger Aries, Sovrin and Microsoft ION. The objective is to determine whether the current claims already cover these architectures or whether they achieve similar outcomes through methods not yet protected — and to close the gaps through careful claim construction now.
The Indian filing route runs through Mulla & Mulla (Purnima and Siddharth Thacker). The Section 3(k) analysis is complete and the claims have been reframed to emphasise technical effect over business method. The persistent-identity and challenge-question evolution (2.8) must be captured cleanly in the complete application, alongside the post-quantum readiness and algorithmic-agility claims, so that the specification filed under the Paris Convention reflects the architecture as it now stands rather than as it stood at provisional. The combined effect of the two workstreams is to make Dimple's anonymous architecture defensible not just today but across the horizon over which it intends to become infrastructure.
3.10Designed-in safety — non-negotiable
Everything above is permissible only because it is held inside a safety architecture treated as foundational, not as a feature. The market has just shown the world what happens when youth mental health meets AI built for engagement. The following principles are binding on every capability in this roadmap:
- Never a clinician, always honest. The AI never represents itself as a licensed professional and always, persistently, discloses that it is an AI — in line with the APA's 2025 advisories.
- Escalation-first, not engagement-first. Success is measured by readiness and appropriate hand-off to humans, never by time-on-platform. No manipulative retention design, ever.
- Human-in-the-loop for risk. Risk detection, including multilingual crisis-keyword work, is led by native-speaking counsellors with the AI augmenting, not replacing, human judgement.
- Not a substitute for human care. The companion layer is explicitly a bridge to people, not a replacement, and is designed against unhealthy dependency.
- Anonymity as protection. A young person's most intimate disclosures are not tied to an identity that can be profiled, sold or exposed — the precise harm regulators are now naming.
- DPDP by design. Consent, purpose limitation, data minimisation and user-controlled erasure are built in, satisfying India's framework as a baseline rather than a retrofit.
- Tested before it ships. Any youth-facing capability undergoes pre-deployment testing for psychological harm, and ongoing bias monitoring across language, gender and community.
This is not a constraint on the vision. It is the vision. A readiness engine that families trust enough to let their children near is worth more than a clever one they don't. The clinical safety of routing in the healthcare vertical, in particular, must always be governed with conservative thresholds and human oversight — sending someone past a needed assessment is more dangerous than the queue we are trying to fix — and detection remains a hypothesis to be validated empirically, claimed as “flagging for review” rather than “prediction” until the evidence exists. The Monash research pathway is the right vehicle for that validation.
3.11Indicative sequencing
The following maps capability to phase. It is indicative — intended to anchor board discussion, not to commit timelines ahead of the MVP build and pilot learnings. Each phase assumes the prior phase's data and trust foundations are in place; nothing youth-facing ships ahead of its safety testing, regardless of phase.
| Phase | Capability focus | Dependencies |
|---|---|---|
| Phase 2 | Token-bound learning; the weekly readiness program; JITAI nudges; counsellor ambient note-taking. | Builds on MVP token architecture and SUKHA Index; counsellor tools piggyback on the CCI network. |
| Phase 2–3 | Cohort engagement-timing; topic heatmaps; resource-efficacy flywheel; bounded companion (safety-gated). | Requires pilot-scale data; companion layer gated behind safety testing. |
| Phase 3 | SUKHA Forecast; anonymous cohort mirror; consent-gated context capsule; vernacular voice-first. | Institutional product packaging; voice tied to the STAR Station footprint. |
| Phase 3–4 | Family Bridge; supervision-at-scale; precision routing / health triage. | Cultural and clinical validation; health-segment commercial model. |
| Vertical expansion | Workplace EAP; healthcare triage; elite sport; DV safe-disclosure; fintech wellbeing. | Same engine re-tuned per domain; DV and defence demand heightened safety design. |
| Cross-cutting | Anonymity-preserving personalisation (IP); responsible-AI layer; research & synthetic-data engine; post-quantum readiness. | Patent and FTO work with Mulla & Mulla and QClairvoyance; research engine aligns to Monash pathways. |
3.12In closing
The field has decided that the future of youth mental health is adaptive, personalised and AI-assisted. The best-funded player in our adjacency is building exactly that, inside the clinic. The consumer apps tried to build it without conscience and are paying for it. India has laid the rails and named the gap but left the proactive, personalised, vernacular layer empty. Dimple's opportunity is to build that layer the right way — anonymous, culturally fluent, escalation-first, and ahead of the parade — and then to re-point the same engine at an employee, a patient, a survivor, an athlete. Built with this discipline and this architecture, very few others are positioned to build it at all.
“The intelligence that does not wait for a young person to fall.”
— Todd