Skip to content
ISO 27001, SOC 2, the DPDP Act and manual VAPT.

Cybersecurity Consulting from Noida, India

Security that Holds up in the Audit Room and in Production.

SecureRoot builds compliance programmes that pass, tests the systems you ship, and stays with your team while the fixes land. Six practice areas, 34 services, one accountable team from scoping call to closing retest.

  • 250+ security assessments delivered
  • 30+ compliance programmes run end to end
  • 3 hour SLA on critical findings

Control Mapping

SecureRoot

One Evidence Item

Owned by a named person, dated, kept current

ISO 27001
SOC2AICPA
HIPAA
NIST CSF
PCI DSS
Digital Personal Data Protection Act 2023
GDPR
ISO 27701
Write the evidence once. It answers all eight.

Frameworks We Take Clients Through

  • ISO 27001

    Certified ISMS, built to fit how you work

  • SOC2AICPA

    Type I and Type II, readiness to attestation

  • PCI DSS

    v4.0 scope reduction and validation

  • Digital Personal Data Protection Act 2023

    India readiness, consent and data rights

  • GDPR

    EU privacy programmes and DPO support

  • HIPAA

    Safeguards for US healthcare partnerships

What We Do

Six Practice Areas, One Team

Most clients start with one problem and grow into a programme. Everything below is delivered by the same people, so the audit evidence, the test findings and the fix plan all agree with each other.

Compliance

Certification and privacy programmes across 13 frameworks, from ISO 27001 and SOC 2 to PCI DSS, the DPDP Act and GDPR. We scope, close the gaps, build the evidence trail and sit with you through the audit.

Explore

VAPT

Manual, exploit-driven testing across web, mobile, API, thick client, network, IoT and cloud. Every finding comes with proof, business impact and a retest that confirms the fix held.

Explore

Secure Code Review

Our engineers read your authentication, authorization, payment and data-handling paths line by line, then triage the SAST output so you only chase what is genuinely exploitable.

Explore

Software Composition Analysis

A full inventory of the open source and third-party code you ship, mapped to known vulnerabilities and license risk, with an SBOM you can hand to any customer who asks.

Explore

Hardening and Configuration Review

We measure your live cloud, operating system, firewall, Active Directory and data tier settings against CIS Benchmarks and vendor baselines, then hand your team runbooks they can apply.

Explore

Managed Services

Ongoing offensive, defensive and advisory work: red teaming, SOC as a service, vCISO and vDPO, phishing simulations, awareness training and forensics. A named team, reporting you can show the board.

Explore

That is 34 services in the catalogue. Start with the one you need today; the rest are there when you grow into them.

Browse All 34 Services
Our Toolkit

Tools and Standards We Work With

Every name below is drawn from the methodology of a service we deliver. Working tools on the first row, published frameworks and standards on the second.

Burp Suite Professional
Nmap
Wireshark
Metasploit
Nuclei
OWASP ZAP
sqlmap
Ghidra
BloodHound
IImpacket
Frida
MobSF
Semgrep
CCodeQL
SonarQube
Snyk
Trivy
Syft
OSV-Scanner
Prowler
SScoutSuite
Tenable Nessus
Qualys
Splunk
MSMicrosoft Sentinel
Wazuh
Suricata
Velociraptor
Volatility
GoPhish
OpenSCAP
CIS-CAT Pro
Vanta
DDrata
SSprinto
Scrut
OneTrust
BigID
MPMicrosoft Purview
Jira
ISO/IEC 27001:2022
ISO/IEC 27002:2022
ISO/IEC 27017
ISO/IEC 42001:2023
ISO 22301:2019
ISO 31000
SOC2AICPATrust Services Criteria
DPDP Act
DPDP Rules
GDPR
HIPAA Security Rule
AI ACTEuropean Union
NIST CSF
NIST SP 800-53
NIST SP 800-115
NIST Privacy Framework
NIST SSDF
MITRE ATT&CK
D3FENDMITRE
OWASPTop 10
OWASPASVS
OWASPMASVS
OWASPAPI Top 10
CISBenchmarks
CISControls
CVSS v4.0
CWEMITRETop 25
PTES
OSSTMMISECOM
OWASPCycloneDX
SPDXLinux Foundation
SLSAOpenSSF

Our Platforms

Software We Built Because the Work Needed It

TrustGrid and DPDPA Compass are SecureRoot's own products. We use them to run engagements, so the busywork of collecting and refreshing evidence stops eating your team's week. They support the consulting; they never replace the judgement.

TrustGrid

GRC and Evidence Automation

TrustGrid holds one control set mapped across every framework you are pursuing, so a single piece of evidence answers ISO 27001, SOC 2 and PCI DSS at once. Your team sees what is open, what is due and what an auditor will ask for next.

One control library mapped across multiple frameworks

Evidence collection, ownership and renewal reminders

Audit-ready exports and internal audit tracking

Third-party risk assessments in the same place

One Control Set, Scored Against Every Framework

This is the board TrustGrid keeps current: 100 unified controls across 7 frameworks, 63 of them implemented, and the 11 failing checks named rather than averaged away.

A flat product screenshot of TrustGrid, a compliance automation platform, shown in its dark product interface. The left sidebar carries the TrustGrid mark, the line "Powered by SecureRoot Risk Advisory LLP", and grouped navigation: Overview holding Dashboard, Automation and Tasks with 23 outstanding; Compliance holding Frameworks, Controls, Applicability, Evidence, Policies and Audits; Risk holding Risk register, Third parties and Incidents; Privacy and AI holding Privacy and AI governance; Organisation holding People and access, Integrations, Trust centre, Reports and Settings. Header: compliance posture for SecureRoot Risk Advisory LLP, 7 frameworks in scope, 100 unified controls, with a button to run automated checks. Five headline figures: overall readiness 63 percent, being 63 of 100 controls implemented; 11 failing checks, from 22 passing and 7 warning out of 40; 23 open remediation and implementation tasks; 12 third parties, 2 of them overdue for reassessment; 4 rights requests, 1 past its statutory deadline. Posture trend, recorded once per day when the automated sweep runs, shown for the quarter with trust score selected: 74, 71, 69, 73, 75, 74, 72 on 06-04, 07-02, 07-30, 08-21, 08-25, 08-29, 08-30, so the trust score stands at 72 of 100 and has moved -2 points over the quarter. Trust score, a weighted blend shown broken down so it is never a black box: control readiness scores 66 at 45 percent weight, 63 of 100 controls implemented; automated checks scores 55 at 25 percent weight, 22 of 40 passing; operational hygiene scores 91 at 20 percent weight, 8 of 85 dated items overdue; risk exposure scores 100 at 10 percent weight, 0 of 11 open risks are critical. Those four weighted scores total 71.65, which rounds to the headline 72. Open findings by severity, covering failing checks, vendor findings and remediation tasks: 5 critical, 19 high, 34 medium, 15 low, which sum to the 73 open at the centre of the donut. Illustrative snapshot of a typical programme, not a named client.

Illustrative snapshot of one sample programme, not a named client. 63 percent readiness, a trust score of 72 broken into the four measures that produce it, and 73 open findings.

DPDPA Compass

DPDP Act Readiness and Privacy Operations

DPDPA Compass turns the DPDP Act into work you can assign and finish. It maps where personal data lives, tracks consent and data principal requests, and keeps the breach playbook current rather than filed away.

Personal data discovery and processing records

Consent capture, withdrawal and audit history

Data principal rights requests with response clocks

Breach assessment and notification workflow

Privacy Operations You Can Assign and Close

The working view of a DPDP Act programme: what consent you hold, which rights requests are running down their clocks, and how far the readiness assessment has actually got.

Illustrative snapshot of one sample programme, not a named client. The score is weighted: two domains the organisation cannot yet measure are excluded and the weights renormalised, never scored zero. One rights request is overdue, and the board says so.

How We Work

Four Steps, No Surprises

The same shape whether you need one penetration test or a full certification programme. You always know what happens next, who owns it and what you receive at the end of it.

How an Engagement Runs

Understand, Assess, Strengthen, Sustain

Flow

Loop diagram with four selectable stages. The stages run in order and the fourth feeds the first, so the sequence is a closed loop. Stage 01, Understand: we agree what matters and what you must prove. We start with the business, not the network diagram. What you sell, who is asking the hard questions, what the regulator expects, and what your engineers can absorb this quarter. Handover, Scoping Note, Fixed Quote and an Agreed Timeline. A scoping note naming what is in and out of test, a fixed quote written against it, and a timeline both sides agreed first. Stage 02, Assess: we test it and rank what we find. We test, review and measure against the standards that actually apply to you. Anything critical reaches you the moment we confirm it, not when the report lands. Handover, Findings Ranked by Business Impact, with Proof. Findings ranked by business impact rather than raw score, each with reproduction steps and evidence attached. Stage 03, Strengthen: we fix alongside your engineers, then retest. Every finding ships with remediation guidance written for your stack. We sit with your engineers through the fix, then retest to confirm the issue is genuinely closed. Handover, Remediation Plan and Verified Retest Report. A remediation plan with a named owner against each item, and a retest report stating what is closed and what is not. Stage 04, Sustain: we keep evidence current and testing on schedule. Security decays quietly. We keep controls current, evidence fresh and testing on a cadence, so the next audit or customer questionnaire is a routine day. Handover, Quarterly Review, Refreshed Evidence and a Roadmap. A quarterly review of what actually moved, refreshed evidence an auditor can open cold, and the scope of the next turn. A return path runs from Sustain back to Understand: What Sustain Finds Sets The Next Scope.

What Sustain Finds Sets The Next Scope

Stage 01 Understand

We start with the business, not the network diagram. What you sell, who is asking the hard questions, what the regulator expects, and what your engineers can absorb this quarter.

The Handover Contains

A scoping note naming what is in and out of test, a fixed quote written against it, and a timeline both sides agreed first.

Select a stage to open its detail. The fourth step feeds the first.

What the Loop Produces After Four Quarters

One board a sponsor can read in a minute: the score and how it is weighted, the findings still open, what to do next, and whether the last four quarters actually moved anything.

Posture

One Score, Its Working, and Four Quarters of Evidence

Worked example

Security posture overview, a flat product interface snapshot carrying a sample and demo data badge. Illustrative snapshot of a typical programme, not a named client. Security posture score 72 of 100, weighted by each domain's share of the in-scope estate; unweighted, the same five domains average 69.6. Open findings: 3 critical, 7 high, 14 medium, 22 low, which sums to 46. Recommended actions for the next 30 days: Rotate exposed cloud access keys and enforce MFA on all admin accounts; Patch the two internet-facing services running end-of-life versions; Close the storage buckets with public read on customer exports; Add rate limiting to the OTP verification endpoint. Domain control maturity out of 100: Application 68, Cloud 61, Identity 74, Infrastructure 79, Data protection 66. Compliance readiness: ISO 27001 82 percent, SOC 2 64 percent, DPDPA 48 percent. Vulnerability severity trend over the last four quarters, open findings by band: Q3 '25: 34 critical and high, 40 medium, 47 low, total 121; Q4 '25: 26 critical and high, 33 medium, 40 low, total 99; Q1 '26: 17 critical and high, 24 medium, 33 low, total 74; Q2 '26: 10 critical and high, 14 medium, 22 low, total 46. That is 121 open findings in Q3 '25 down to 46 in Q2 '26, a fall of 75, which is 62 percent of the opening figure. The final quarter's bands are the same three critical, seven high, fourteen medium and twenty two low findings shown in the open findings panel.

Illustrative snapshot of one sample programme, not a named client. The score is weighted by each domain's share of the estate and the board prints the unweighted average of 69.6 beside it, so the weighting is never doing quiet work. 3 critical plus 7 high plus 14 medium plus 22 low is the 46 open findings, and that same 46 is the last column of the trend, down from 121 in Q3.

Why SecureRoot

What Working with Us Actually Feels Like

Plenty of firms can produce a findings list. The difference shows up in what happens after the report lands.

Recommendations Tied to Your Business
We rank issues by what they cost you, not by scanner severity. If a medium finding sits on your payment path and a high sits on a staging box, we say so and sequence the work accordingly.
Technical Depth with Practical Execution
The people who find the flaw are the people who explain the fix. Our engineers pair with yours during remediation, in your language and your codebase, until the retest comes back clean.
Reporting Your Leadership Can Read
Two pages your board understands, then the technical detail your engineers need, with reproduction steps and evidence. One document, two audiences, no translation layer.
Improvement that Continues After We Leave
We hand over the runbooks, the control set and the habits. Your team should be able to run the next cycle without us, and call us because they want to, not because they are stuck.

Your Findings, Three Months In

The board your team works from between engagements. Every row shows whether the issue is being exploited in the wild, and the overdue rows stay on the board where you can see them.

VAPT

Worked example

A vulnerability management product view. Illustrative snapshot of a typical programme, not a named client. Headline figures for the quarter across 1,340 in-scope assets and 40 web applications: 4,812 open findings, of which 288 are past their internal SLA; 37 critical findings open; blended mean time to remediate 84 days, computed from the 3,371 closures this quarter, 24 critical at 21 days each, 391 high at 38, 2,100 medium at 74 and 856 low at 130, which is 282,042 finding-days over 3,371 closures; SLA compliance 68 percent, 2,292 of 3,371 closures within SLA. Open findings by CVSS v3.1 band: Critical 37, which is 0.8 percent; High 412, 8.6 percent; Medium 1,954, 40.6 percent; Low 2,409, 50.1 percent. A further 1,106 informational findings are excluded from that total. 19 open findings are listed on the CISA Known Exploited Vulnerabilities catalogue and 4 of those are past their CISA BOD 22-01 due date. Findings over 13 weeks: 2,993 new against 3,371 remediated, so the open backlog fell from 5,190 to 4,812, with a spike of 402 new findings in week 6 when the quarterly authenticated scan ran. Mean time to remediate by severity against target: Critical 21 days against a 15-day target, High 38 against 30, Medium 74 against 90, Low 130 against 180. The table lists 13 representative findings ranked by exploitability, led by CVE-2024-3400, GlobalProtect OS command injection, CVSS 10.0, EPSS 0.944, on KEV, 13 days old and open; CVE-2023-4966, NetScaler session token leak, CVSS 9.4, on KEV, 41 days old and in progress; and CVE-2021-44228, Log4j2 JNDI remote code execution on a legacy build host, CVSS 10.0, on KEV, 402 days old and still open.

SecureRoot VAPTVulnerability Management

4,812

Open

288 past SLA

37

Critical

19 on KEV

84d

MTTR

3,371 closed

68%

Within SLA

2,292 of 3,371

By Severity, 4,812 Open

Critical 37High 412Medium 1,954Low 2,409

19 on CISA KEV, 4 past their CISA due date.

Illustrative snapshot of a typical programme, not a named client.

Illustrative snapshot of one sample estate, not a named client. This one runs 1,340 assets, which is larger than the samples shown earlier on this page. Of its 4,812 open findings, 19 are on the CISA Known Exploited Vulnerabilities catalogue today and 4 of those are already past their due date. Those are the four we would call you about.

Case Studies

Work We Can Talk About

We name clients where they have agreed to it, and describe the work without naming them where they have not. The scope, the approach and the numbers are exactly as delivered.

All Case Studies

SaaS, SOC 2

A SaaS Platform Reaches SOC 2 Type II on the First Attempt

Challenge
Enterprise deals kept stalling in security review. There was no formal control set, and evidence was scattered across half a dozen tools with nobody owning it.
Approach
We ran a readiness assessment, agreed a control set sized to the company rather than the standard, automated evidence collection, and put the team through a mock audit before the real one.
Audit Exceptions
0
To Audit Ready
16 weeks
Faster Deal Reviews
3x

Healthcare, DPDP Act

A Hospital Network Builds DPDP Act Readiness Across 12 Facilities

Challenge
Patient data moved through dozens of systems with no data map, no consent record and no tested plan for a breach. Clinical operations could not pause for any of it.
Approach
Data discovery and mapping first, then consent workflow design, DPO advisory and staff training, phased facility by facility so care delivery was never interrupted.
Obligations Covered
94%
Facilities Onboarded
12
Breach Response SLA
48 hours

Financial Services, Application Security

A Lending Platform Closes Critical Application Risk Before Scale-up

Challenge
Feature releases were outpacing security review, and a regulator-mandated audit was three months out with no assessment on record.
Approach
Full web and API VAPT, secure code review of the payment and disbursement flows, fix support sprints with the engineering team, and verified retests, all inside the audit window.
Findings Fixed
27
Criticals Closed
100%
Mean Time to Fix
9 days

What Clients Say Once the Work Is Done

  • The report was the first one our board actually read. Two pages of what mattered, then the detail our engineers needed. Every critical was retested and closed within a month.
    Head of Engineering, fintech platformMumbai
  • We went from hoping we were fine to a SOC 2 Type II with zero exceptions. They did not just audit us, they taught our team how to keep it running.
    CTO, B2B SaaS companyBengaluru
  • They found a critical issue three hours into testing and called us straight away instead of saving it for the report. That is the difference between a vendor and a partner.
    CISO, healthcare groupDelhi NCR

Questions

Before You Get in Touch

The things people ask us on the first call, answered here so the call can start somewhere more useful.

Ask Us Something Else
We need ISO 27001 and SOC 2. Is that two separate projects?

No. The two frameworks overlap heavily, so we build one control set and one evidence base that satisfies both. That is faster and considerably cheaper than running them as separate programmes, and it keeps your team answering a question once instead of twice.

How long does DPDP Act readiness take?

For most mid-size organisations, 90 to 120 days to a defensible position: data mapped, consent flows live, a working process for data principal requests and a breach playbook you have actually tested. Maturity builds from there, and we usually stay on for the first few quarters.

How long does a VAPT take?

Most web or API assessments run one to three weeks depending on scope, plus a retest window once your fixes are in. You do not wait for the report to hear bad news: critical findings reach you within three hours of discovery.

Do you help with fixes, or only report problems?

We help. Every finding carries specific remediation guidance, our engineers are available to yours during fix sprints, and we retest to confirm each closure. The retest is part of the engagement, not a separate invoice.

What does an engagement cost?

It depends on scope: how many applications and environments, which frameworks, and how much of the work sits with your team. Walk us through what you run in a short call and you get a fixed quote, not an open-ended estimate that grows later.

How do we start?

One scoping call, usually 30 to 45 minutes, with the people who will do the work. We map what you need against what is urgent, then send a written scope, timeline and price. If we are not the right fit for the problem, we will tell you that on the call.

Ready When You Are

Tell us what is due and who is asking. You will leave the call with a written scope, a timeline and a fixed price, and an honest answer if we are not the right firm for it.

Based In
Noida, India
Response
We reply within one business day