Calculators · field guides · playbooks · templates · all India-first

Free resources for Indian compliance teams.

Calculators, field guides, decision trees, RFP templates, and playbooks — built for the Indian regulator stack. All free to use without signup. The blog is the long-form companion to these tools.

Resource library.

Twelve resources covering DPDP, SEBI CSCRF, RBI, CERT-In, SOC 2, ISO 27001, and VAPT. Updated as regulations change. The blog is updated weekly with new long-form content.

Calculator · live

DPDP Section 33 penalty calculator

Calculate your DPDP Section 33 Schedule penalty exposure based on turnover, severity, and mitigation posture. Statutory ceilings up to ₹250 Crore.

Interactive · 2 minutes Open calculator →
Field guide

CERT-In Direction 20(3)/2022 reporting runbook

The six-hour incident reporting runbook — step-by-step workflow, internal escalation chain, regulator notification templates, common mistakes that extend the timeline.

Read · 12 min Read runbook →
Field guide

CERT-In empanelled auditor list 2026

How to verify a vendor's CERT-In empanelment, what categories matter, what changes in 2026, and the cross-referenced public list of currently-empanelled firms.

Read · 10 min Read guide →
Decision tool

ISO 27001 vs SOC 2 — Indian SaaS decision tree

Pick the right first certification based on your buyer pipeline, geography, and stage. Indian / APAC vs US / EU branching, with the joint-engagement option for mixed pipelines.

Read · 8 min Open tree →
Field guide

DPDP Act 2023 — complete India compliance guide

Data Fiduciary obligations, lawful basis, consent manager wiring, DPIA, Significant Data Fiduciary classification, Section 33 penalty framework, and audit-ready evidence.

Read · 18 min Read guide →
Field guide

SEBI CSCRF stock broker compliance field guide

The six SEBI CSCRF domains explained for stock brokers, AMCs, and Market Infrastructure Institutions. Quarterly cadence, MSOC integration, cyber-resilience drill expectations.

Read · 14 min Read guide →
Self-assessment

SOC 2 readiness self-assessment

Five-minute self-assessment to gauge how close your organisation is to SOC 2 Type II readiness. Covers access management, change management, vendor risk, and evidence discipline.

Self-test · 5 min Take self-test →
RFP template

VAPT RFP template (DOCX)

Pre-structured VAPT RFP template — scope, methodology, deliverables, auditor qualifications, commercial terms, evaluation criteria. Sector-specific customisations included.

Template · DOCX Get template →
Playbook

Got asked for SOC 2? · 90-day playbook

Your enterprise prospect just asked for SOC 2 — the 90-day triage playbook. Day-1 buy-time email, Days 2-7 build-week, Days 8-30 programme start, Days 31-90 fieldwork.

Read · 15 min Read playbook →
Field guide

IR retainer cost factors · what drives the quarterly fee

The six factors that drive incident-response retainer cost — SLA, included hours, tier, on-site posture, regulator-reporting depth, engagement model.

Read · 10 min Read guide →
Field guide

VAPT cost factors · what drives the quote

The seven factors that drive VAPT engagement cost — scope breadth, methodology depth, tester seniority, re-test policy, reporting granularity, on-site posture, empanelment.

Read · 12 min Read guide →
Field guide

SOC 2 Type II cost factors · 6 factors explained

The six factors that drive SOC 2 Type II cost in India — TSC scope, observation window, organisation size, multi-cloud complexity, readiness maturity, auditor pedigree.

Read · 12 min Read guide →
Design-partner cohort · first 10 free for 6 months

Be one of the first ten Indian SaaS, BFSI, or fintech teams on the platform.

India regulators as first-class frameworks. Bharat-resident evidence. Pricing locked in INR for the first 12 months. We are onboarding ten design partners through Q2-Q3 2026 ahead of general availability.

You will be contacted by a founder within two business days. We do not run sales sequences.

Bengaluru HQ · L149 Sector 6, HSR Layout