Compliance + Standards
The security controls behind the frameworks.
Almost every compliance framework shares a common core: encryption, access control, logging and monitoring, vulnerability management, and regular testing. That technical core is what we build and test. This is the list of frameworks whose security requirements our work maps to - not a list of certifications we hold or full programs we run. We are not a certification body, we do not issue attestations, and the audit, policy, and legal work stays with your auditor and counsel.
India + South Asia
Frameworks whose technical security requirements our controls help you meet. The legal and reporting obligations are for your counsel.
USA
For US clients and Indian clients selling into the US - the security-controls side of each.
EU + global
The security-of-processing and ISMS-controls side. Consent, transfers, and DPO duties sit with privacy counsel.
Security testing standards we follow
The public methodologies our penetration testing and assessments are run against.
Cloud + infra stacks we work with
Vendor-neutral, with no resale or referral arrangement with any of these. We pick what fits your team, geography, and posture - not what pays us a commission.
Working toward a framework not listed here?
Tell us the framework, your business, and your timeline. We will be honest about which parts we can do (the technical security controls) and which parts need an auditor or a lawyer.

