10 frameworks · one platform

Every framework that matters, in one place.

Indian and global standards, pre-loaded with 287 controls and 40+ cross-mappings - so a single implementation counts across many frameworks at once.

Interactive

Which frameworks do you need?

Select everything that applies to your business. We'll recommend the frameworks to prioritise.

Indicative guidance - your free gap analysis confirms exactly what applies and where you stand.

The catalog

Every framework, grouped the way you work.

Ten frameworks live now, cross-mapped once - plus the ones on our roadmap. Implement a control once and satisfy many at the same time.

Privacy & Data Protection

DPDP

DPDP Act 2023

India's Digital Personal Data Protection Act with the 2025 Rules - consent, breach reporting, data-principal rights and SDF obligations.

MandatoryGuide →
GDPR

GDPR

The EU's data-protection regulation - relevant if you process the personal data of individuals in the EU.

If EU users
HIPAA

HIPAA

US healthcare privacy & security rules - for health-tech and providers handling US patient data.

If US health

Information Security & Certification

ISO

ISO 27001:2022

The international information-security management standard - the benchmark for enterprise security governance and vendor trust.

Certification
SOC

SOC 2 Type II

Required for Indian SaaS selling to US enterprises - security, availability, processing integrity, confidentiality and privacy.

Global market
NIST

NIST CSF 2.0

The US NIST Cybersecurity Framework - a widely-adopted best-practice model for governing and managing cyber risk.

Best practice
800-53

NIST SP 800-53 Rev 5

The US federal control catalogue - the deep control set US federal and regulated buyers map to.

Best practice

India Regulatory & Sector

RBI

RBI ITGRC 2023

RBI's IT Governance, Risk & Compliance framework - mandatory for banks, NBFCs and regulated fintech entities.

Mandatory · BFSI
SEBI

SEBI CSCRF 2023

SEBI's Cybersecurity & Cyber Resilience Framework for listed companies, brokers and capital-market intermediaries.

Mandatory · Markets
CERT

CERT-In 2022

Mandatory CERT-In directions - incident reporting, log retention and security audits for all Indian organisations.

Mandatory

On the roadmap

42001

ISO 42001

The AI management-system standard - governance for organisations building or deploying AI responsibly.

Roadmap
PCI

PCI DSS

Payment-card industry data-security standard - for organisations handling cardholder data.

Roadmap
+N

Sector & custom frameworks

IRDAI, telecom, healthcare and company-specific frameworks - tell us what you're working toward.

Roadmap

Beyond frameworks

VAPT

VAPT & security testing

Standalone Vulnerability Assessment & Penetration Testing, delivered by our security team as a scoped engagement. Not a framework and not a plan feature.

Standalone serviceVAPT →
TPRM

Third-Party Risk Management

A vendor register, structured assessments and risk tiering - alongside your compliance programme or on its own. Scoped with our team.

Standalone offeringTPRM →

40+ cross-mappings

Implement a shared control once and satisfy several frameworks at the same time. Implement once, count everywhere.

Need one that isn't listed?

We add frameworks as our customers need them. Tell us what you're working toward.

Request a framework

See your posture across every framework.

Start a free gap analysis - we'll confirm which frameworks apply and exactly where you stand today.