VITI Security
We do the security engineering, not the audit or the legal work. VITI Security implements and tests the technical security controls these frameworks require - access control, encryption, logging and monitoring, vulnerability management, and penetration testing. The certification or attestation is issued by an independent, accredited auditor or CPA firm that you retain; formal policy authoring, legal review, and Data Protection Officer duties sit with your auditor and privacy counsel, not with us. We have no partnership, referral fee, or kickback with any certifying body - you pick them, and we make the technical controls pass.

Compliance + Standards

The security controls behind the frameworks.

Almost every compliance framework shares a common core: encryption, access control, logging and monitoring, vulnerability management, and regular testing. That technical core is what we build and test. This is the list of frameworks whose security requirements our work maps to - not a list of certifications we hold or full programs we run. We are not a certification body, we do not issue attestations, and the audit, policy, and legal work stays with your auditor and counsel.

India + South Asia

Frameworks whose technical security requirements our controls help you meet. The legal and reporting obligations are for your counsel.

DPDP Act 2023
India · security safeguards
CERT-In Guidelines
India · logging + reporting
RBI Cyber Security Framework
India · BFSI controls
SEBI Cyber Resilience
India · capital markets

USA

For US clients and Indian clients selling into the US - the security-controls side of each.

SOC 2 Type I + II
SaaS · security controls
HIPAA Security Rule
Healthcare · technical safeguards
PCI-DSS v4.0
Card handling · technical reqs
NIST CSF
Control framework
CIS Controls
Hardening baseline

EU + global

The security-of-processing and ISMS-controls side. Consent, transfers, and DPO duties sit with privacy counsel.

GDPR (Article 32)
EU · security of processing
UK GDPR + DPA 2018
United Kingdom
ISO 27001:2022
Global · ISMS technical controls
ISO 27701
Global · privacy controls

Security testing standards we follow

The public methodologies our penetration testing and assessments are run against.

OWASP Top 10 + ASVS
Web apps
OWASP API Top 10
APIs
OWASP MASVS / MSTG
Mobile
NIST SP 800-115
Pentest guide
PTES
Pentest standard
CIS Benchmarks
Cloud + endpoints
MITRE ATT&CK
TTPs

Cloud + infra stacks we work with

Vendor-neutral, with no resale or referral arrangement with any of these. We pick what fits your team, geography, and posture - not what pays us a commission.

AWS
Cloud
Google Cloud
Cloud
Microsoft Azure
Cloud
Hetzner Cloud
Cloud · cost-leader
DigitalOcean
Cloud
Vultr
Cloud
Cloudflare
CDN + DNS + WAF
Microsoft 365
Productivity
Google Workspace
Productivity
Splunk / Sentinel / Sumo Logic / Datadog / Elastic
SIEM
CrowdStrike / SentinelOne / Microsoft Defender
EDR
Cisco / Fortinet / Sophos / Palo Alto
Network security

Working toward a framework not listed here?

Tell us the framework, your business, and your timeline. We will be honest about which parts we can do (the technical security controls) and which parts need an auditor or a lawyer.