Information security · compliance · assurance
Certification is a deadline. We make it a controlled one.
Your customer wants an ISO 27001 certificate or a SOC 2 report, and wants it this quarter. We build the management system that earns it, put the evidence behind every control, and stay in the room through the audit — so the certificate arrives on a date you chose.
Control set — ISO/IEC 27001:2022 + SOC 2
- A.5.15Access controlPassing
- A.8.12Data leakage preventionPassing
- A.8.24Use of cryptographyPassing
- CC6.1Logical access controlsPassing
Evidence verified sha256:9f2b…c41e
- ISO/IEC 27001:2022 certifiedWe run the system we implement.
- Audit-ready evidenceEvery control mapped to proof.
- India-based, on your timezoneOn site when it matters.
Services
Where we are usually brought in.
Most engagements start with one of these and grow into the next. They share a management system, so running two together costs far less than running them apart.
ISO/IEC 27001 — Information Security Management
Build an information security management system that survives Stage 2 — and the three years of surveillance that follow.
SOC 2 Type 1 Readiness
Prove your controls are designed and in place on a given date — the fastest honest way to unblock a contract.
SOC 2 Type 2 Readiness
Evidence that your controls ran for months, not that they existed on a date — the report enterprise procurement usually means.
Vulnerability Assessment and Penetration Testing (VAPT)
Find what an attacker would find, ranked by what it would actually cost you — and get a report your auditor and your engineers can both use.
ISO 22301 — Business Continuity Management
Know which activities cannot stop, how long they can be down, and what you will actually do — tested before you need it.
ISO/IEC 27701 — Privacy Information Management
Turn privacy from a policy document into a management system, with the records a regulator or an enterprise buyer will ask to see.
Where we sit
We prepare you for the audit. We do not sell the certificate.
An accredited certification body issues your ISO certificate; a licensed CPA firm signs your SOC 2 report. Neither may also build the management system it assesses — ISO/IEC 17021-1 forbids it, and it is what makes the certificate mean something. Our work is everything up to that line: the system, the controls, the evidence, the rehearsal, and the answers on audit day.
What we do
- Design and implement the management system
- Run gap assessments and internal audits
- Collect, structure and defend the evidence
- Test your controls the way an attacker would
- Brief and support you through Stage 1, Stage 2 and surveillance
What we never do
- Issue a certificate or sign an attestation
- Act as your certification body or your auditor
- Promise a pass — no consultancy honestly can
- Mark our own homework on an audit we prepared
At a glance
What an engagement actually looks like.
Durations assume an organisation under 200 people with a contained scope. We give you real figures once we have seen the estate — these are the shape, not a quote.
| Engagement | Standard | Typical duration | What you end with |
|---|---|---|---|
| ISMS implementation | ISO/IEC 27001:2022 | 6–9 months | Stage 2 audit, certificate issued by an accredited body |
| SOC 2 Type 1 | AICPA Trust Services Criteria | 6–12 weeks | A point-in-time report from a licensed CPA firm |
| SOC 2 Type 2 | AICPA Trust Services Criteria | 3–6 months + observation | A signed report covering the whole observation window |
| Penetration testing | OWASP · NIST SP 800-115 | 2–4 weeks | Severity-rated findings, remediation support, retest letter |
| Business continuity | ISO 22301:2019 | 4–8 months | A BCMS with exercised, evidenced plans |
| Privacy management | ISO/IEC 27701:2025 | 4–8 months | A PIMS mapped to your DPDP and GDPR obligations |
We prepare and we advise. The audit itself is performed by an independent accredited certification body or a licensed CPA firm, and we are neither.
How we work
A fixed scope, a named date, and no surprises in month three.
We scope from evidence, not from a questionnaire. You get a written statement of what is in scope, what it costs, who does what, and the date the certification body can be booked for — before the first invoice.
Who we work with
Organisations whose customers ask hard questions.
The trigger is almost always external: an enterprise procurement review, a regulator, a funding round, or a customer contract with a security schedule attached.
SaaS and technology
Enterprise buyers gate procurement on SOC 2 or ISO 27001. The blocker is rarely the controls — it is evidence that they ran all year.
IT and business services
You hold client data under contract. Your obligations are inherited from their compliance programme, and you are audited against theirs.
Financial services and fintech
Layered obligations: sectoral regulation, ISO 27001, customer due diligence, and penetration testing on a defined cycle.
Healthcare and life sciences
Sensitive personal data, cross-border transfer, and a privacy regime that expects a management system rather than a policy document.
Trusted by
Teams that answer to regulators, auditors and enterprise buyers.
Four sectors, four sets of obligations. The pattern is the same each time: someone external asked a question the organisation could not yet answer with evidence.

Proclaim Insurance Surveyors and Loss Assessors
Insurance loss adjusting and claims management
Operating in — India

Disk Archive Corporation
Enterprise archive systems for media, legal, medical and forensic data
Operating in — United Kingdom · India

Nirantara Solutions
Environmental consulting, ESG and sustainability advisory
Operating in — UAE · India

Goals101
Transaction behavioural intelligence for banks
Operating in — India · Malaysia · Sri Lanka · UAE
Insights
The standards behind the work.
Explainers on what each standard actually requires, what it does not, and the dates that matter. Written for the person who has to act on them.
Regulation · India
Is the DPDP Act in force? What applies today, and the deadline that matters
The Act is law today and its obligations bite on 13 May 2027. Penalties reach ₹250 crore, and the work that takes longest is the work nobody has started.
Regulation · EU
Does the GDPR apply to an Indian company? Scope, roles and the EU representative question
Most Indian firms are caught through a contract rather than by a regulator — and most do not need the EU representative they are being sold.
Technical testing
The OWASP Testing Guide, and how to tell a real penetration test from a scan
Two tests can cost the same and cover entirely different ground. The methodology is how you tell, and it is checkable before you pay.
Next step
Tell us the deadline you are working to.
Send the date, the standard, and roughly how large the organisation is. You will get a reply from a practitioner — not a sales sequence — with an honest read on whether the date is reachable.