Compliance, privacy, risk and security - operationalised.
FlickerBytes builds the technology that turns regulatory obligation into day-to-day operations. Niyam, our flagship platform, runs consent, privacy, compliance, third-party risk and security posture in one system - covering India's DPDP, RBI, SEBI and CERT-In alongside ISO 27001, SOC 2, GDPR and HIPAA.
Two products. Both free to start.
No demo call required, no card. Pick the one that matches the problem in front of you - you can add the other later from the same account.
Collect consent you can defend.
A consent banner, notices, a preference centre and a full consent record for every data principal - live on your site in an afternoon.
- Cookie consent and notices
- Privacy centre with preferences and My Data
- Grievance channel and rights intake
- Immutable consent audit trail
500 free Active Data Principals a year - counted as unique people with a consent decision, so repeat or updated consents from the same person do not use up your allowance. The allowance is yearly whether you pay monthly or annually. Consent capture, withdrawal and data-principal rights are never blocked by a commercial limit.
Start FreeRun the whole programme in one place.
Pre-loaded controls, evidence workflows, privacy operations and audit packs across every framework you carry.
- Pre-loaded controls and cross-framework mapping
- Evidence collection with owners and due dates
- Privacy operations: rights, DPIA, breach, transfers
- One-click audit packs
Free tier available. Framework and user limits depend on your plan - the pricing page reads them live from our product catalogue.
Start FreeOne platform, and the people to run it.
Niyam is the product. Around it, FlickerBytes delivers the security testing and managed work that software alone does not cover.
Compliance Platform
Controls, evidence, audits and privacy operations across DPDP, ISO 27001, SOC 2, RBI, SEBI, CERT-In, GDPR, HIPAA and NIST.
Explore platformConsent & Preferences
Consent capture, notices, preference centre and consent records - a standalone product with its own free tier.
Explore consentPrivacy operations
Data principal rights, data mapping, DPIAs, breach timelines, cross-border records and DPA management.
Explore privacyThird-Party Risk
A vendor register, structured assessments and risk tiering that feed the same evidence base as your controls.
Explore TPRMCybersecurity
Policy library, PII scanning, control testing and CERT-In aligned incident records.
Explore securityVAPT & services
Penetration testing, managed compliance, Virtual DPO and data mapping - scoped and delivered by our team.
Explore servicesFrameworks such as DPDP, ISO 27001 and SOC 2 are not products - they are what Niyam helps you operationalise. See the framework catalogue.
Three pressures are converging on Indian businesses.
DPDP 2023 is law and its Rules are notified. Waiting is the expensive option.
The regulator is active
The Data Protection Board is operational, and DPDP carries India's steepest data-protection penalties - up to ₹250 crore. RBI, SEBI and CERT-In mandates keep tightening in parallel.
Customers demand proof
Enterprise buyers and partners now require SOC 2, ISO 27001 and DPDP assurances before they sign. Compliance has become a prerequisite to revenue, not an afterthought.
Spreadsheets don't scale
Managing five frameworks across teams by hand creates blind spots and last-minute audit scrambles. You need one system of record - and, when you want it, expert DPO support.
One system for controls, evidence and proof.
Everything you need to reach - and stay - audit-ready, built natively for India.
Complete DPDP coverage, out of the box.
Every section of the Act, pre-mapped to controls - consent, notices, data-principal rights and cross-border transfers - with automated 72-hour breach tracking and DPB notification workflows.
- Consent manager & notice builder
- Breach register with live 72h clock
- Data rights (DSAR) portal
Implement once. Count everywhere.
287 controls across 10 frameworks with 40+ cross-mappings. A single implementation satisfies DPDP, ISO 27001, SOC 2, GDPR and more at the same time - no duplicated work.
- Automated evidence collection
- Live posture score per framework
- One-click, board-ready audit packs
DPO-as-a-service, when you need it.
Technology alone isn't enough. Niyam pairs the platform with access to qualified Data Protection Officers who manage your obligations, DPIA calendar and regulator communications.
- Indian PII discovery - Aadhaar, PAN, UPI & 20+ patterns
- DPIA management & calendar
- Vendor & outsourcing risk register
Every framework that matters - Indian and global.
Pre-loaded and maintained as regulations evolve. Not sure which apply to you? Use the framework selector →
DPDP Act 2023
India · data protectionMandatory ISOISO 27001:2022
Global · InfoSecCertification SOCSOC 2 Type II
US · trust servicesGlobal market RBIRBI ITGRC
India · BFSIMandatory SEBISEBI CSCRF
India · marketsMandatory CERTCERT-In 2022
India · incidentsMandatory GDPRGDPR
EU · data protectionIf EU users HIPAAHIPAA
US · health dataIf US health 42001ISO 42001
Global · AI systemsOn our roadmap NISTNIST CSF
US · cyberBest practiceFrom unknown to audit-ready in three steps.
Free gap analysis
Tell us your sector and systems. We map the frameworks that apply and show exactly where you stand - no cost, no obligation.
Get compliance-ready
Assign controls, collect evidence and close gaps in the platform, with DPO support where you need it. Your posture score updates live.
Prove it, continuously
Generate board- and auditor-ready packs in one click, and stay continuously monitored as regulations and your business change.
One platform, priced and mapped for the markets you operate in.
Compliance is regional even when your business is not. Niyam carries the frameworks each market actually asks for, and prices in its currency, without you running a separate programme per country.
India
Our deepest coverage. DPDP 2023 with the notified Rules, plus the sector regulators.
Priced in INR, exclusive of GST.
United States
What US enterprise buyers and their procurement teams ask for before they sign.
Priced in USD.
Europe & UK
GDPR obligations run through the same consent, rights and records machinery as DPDP.
Priced in EUR and GBP.
UAE & Middle East
International certification is the common currency of trust across the Gulf.
Priced in AED.
Singapore & APAC
A regional hub where consent and security posture are both scrutinised closely.
Priced in SGD.
Operating across several of these?
That is the case Niyam is built for. Map a control once and satisfy every framework that depends on it, instead of evidencing the same thing per market.
See pricing in your currencyFramework coverage is the same everywhere - see the full catalogue. Currency follows the region you choose on the pricing page.
A tailored compliance path for every industry.
Each sector carries its own mix of regulators. Niyam maps the right frameworks to yours.
BFSI & NBFCs
RBI ITGRC, DPDP and CERT-In for banks, NBFCs and fintech.
ExploreHealthcare
DPDP, HIPAA and sensitive-data handling for health providers.
ExploreSaaS & Tech
SOC 2 and ISO 27001 to win global enterprise trust.
ExploreE-commerce
Consumer data protection and consent at scale.
ExploreReal Estate
KYC, lead and buyer-data governance under DPDP.
ExploreEnterprise
Multi-framework governance across large estates.
ExploreTrusted by teams building India's fintech.
One platform
DPDP, ISO and CERT-In unified in a single system of record.
Less overhead
Streamlined compliance operations, with the busywork removed.
Audit-ready
The governance and audit-readiness a regulated fintech needs.
Clear packages. No complexity.
Every package includes onboarding and access to our compliance team. Contact us for pricing tailored to your size.
DPDP Foundation
For startups that need DPDP 2023 quickly and confidently.
- DPDP 2023 - all 53 controls
- Consent, DSAR & breach tracker
- Evidence vault & risk register
Multi-Framework
For companies managing DPDP alongside ISO 27001, SOC 2 or RBI.
- All 10 frameworks - 287 controls
- Cross-framework mapping (40+)
- Policy library & connectors
Full Suite + DPO
Platform, reporting and DPO-as-a-service in one.
- Everything in Multi-Framework
- DPO-as-a-service & DPIA calendar
- Board-ready audit packs
Custom Solutions
For complex obligations, integrations and SLAs.
- SSO / SAML & unlimited users
- API & custom integrations
- 4-hour SLA & onsite training
DPIIT-recognised startups receive special pricing. Get in touch with your certificate.
Questions, answered.
Almost certainly. If you collect any personal data of individuals in India - customers, employees or leads - you are a Data Fiduciary under DPDP. Take our 2-minute “Does DPDP apply to you?” check to be sure.
Niyam is built India-first and works globally. DPDP, RBI, SEBI and CERT-In are core rather than add-ons, and GDPR, SOC 2, ISO 27001, HIPAA and NIST are carried in the same control set. Indian PII patterns (Aadhaar, PAN, UPI) are built in - while still covering ISO 27001, SOC 2, GDPR and HIPAA for your global needs.
With 287 pre-seeded controls, policy templates and automated evidence collection, most teams move in weeks rather than the months a manual, consultant-led effort typically takes.
Both. The platform stands on its own, and you can add access to qualified Data Protection Officers who manage your DPDP obligations, DPIAs and regulator communications.
A short questionnaire and a 30-minute call. You get a framework-by-framework view of your posture and the top gaps to close first - free and confidential.
See exactly where you stand - free.
Start a gap analysis and get a prioritised view of your compliance posture across every framework that applies to you.