Assurance, stated precisely.
We describe our compliance posture only in terms we can defend. No inflated claims, no invented numbers: verifiable documentation, made available to evaluating institutions.
ISO 27001
Verify current scopeInformation security management requirements may inform a deployment review. Any certification claim must be confirmed from a current certificate showing the legal entity, scope, and validity period.
Current evidence shared during reviewCERT-In
Verify current scopeRelevant security assessment evidence, including assessor and scope, is discussed during due diligence when available and appropriate to the proposed deployment.
Available evidence may require an NDADPDP
Aligned controlsDeployments can include data minimisation, scoped access, and role-based processing. Legal responsibilities and compliance are determined for each context by the institution and its advisers.
Data handling overview shared during reviewISO 9001
Reference frameworkQuality-management concepts such as documented delivery, review, and change control may be used in project governance. This is not a public claim of certification.
Project practices discussed during reviewSOC 2
Reference frameworkSecurity, availability, and confidentiality controls may be mapped to customer requirements. This page does not represent that a SOC 2 examination has been completed.
Assurance status confirmed during reviewSOC 1
Reference frameworkWhere controls are relevant to institutional financial reporting, the parties can determine whether SOC 1-related assurance is applicable. This page does not represent that an examination has been completed.
Applicability confirmed during reviewThis page is a general overview, not a certification, audit opinion, legal conclusion, or guarantee of compliance. Framework references describe review topics only. Evaluators should rely on current, scoped documentation supplied during due diligence and on their own legal and security advisers.
Documentation & reports
Current control documentation and any relevant assurance evidence are reviewed with qualified evaluators. Sensitive material may require a mutual non-disclosure agreement, and availability depends on the system, scope, and proposed deployment.
Available documentation
- Security control summaryDuring review
- Available third-party assurance evidenceScope confirmed
- Relevant security test summariesIf available
- Data handling overviewDuring review
- Data flow & residency architectureDeployment-specific
Access & identity
Role-based access control, least privilege, and scoped permissions across every deployment.
Data governance
Data minimization, residency configuration, and retention aligned to DPDP expectations.
Auditability
Attributable, reviewable action logs supporting operational and regulatory defensibility.
Deployment security
On-prem, sovereign cloud, or hybrid boundaries validated against official risk constraints.
Request compliance documentation
Tell us what evidence and scope your evaluation requires. We will confirm what current documentation is available and any confidentiality requirements.
