Skip to content
ISO 27001, SOC 2, the DPDP Act and manual VAPT.

Case Studies

Work We Can Talk About

We name clients where they have agreed to it, and describe the work without naming them where they have not. The scope, the approach and the numbers are exactly as delivered.

01SaaS, SOC 2

A SaaS Platform Reaches SOC 2 Type II on the First Attempt

Audit Exceptions
0
To Audit Ready
16 weeks
Faster Deal Reviews
3x

The Challenge

Enterprise deals kept stalling in security review. There was no formal control set, and evidence was scattered across half a dozen tools with nobody owning it.

What We Did

We ran a readiness assessment, agreed a control set sized to the company rather than the standard, automated evidence collection, and put the team through a mock audit before the real one.

02Healthcare, DPDP Act

A Hospital Network Builds DPDP Act Readiness Across 12 Facilities

Obligations Covered
94%
Facilities Onboarded
12
Breach Response SLA
48 hours

The Challenge

Patient data moved through dozens of systems with no data map, no consent record and no tested plan for a breach. Clinical operations could not pause for any of it.

What We Did

Data discovery and mapping first, then consent workflow design, DPO advisory and staff training, phased facility by facility so care delivery was never interrupted.

03Financial Services, Application Security

A Lending Platform Closes Critical Application Risk Before Scale-up

Findings Fixed
27
Criticals Closed
100%
Mean Time to Fix
9 days

The Challenge

Feature releases were outpacing security review, and a regulator-mandated audit was three months out with no assessment on record.

What We Did

Full web and API VAPT, secure code review of the payment and disbursement flows, fix support sprints with the engineering team, and verified retests, all inside the audit window.

In Their Words

What the Teams We Worked with Said Afterwards

The report was the first one our board actually read. Two pages of what mattered, then the detail our engineers needed. Every critical was retested and closed within a month.
Head of Engineering, fintech platformMumbai
We went from hoping we were fine to a SOC 2 Type II with zero exceptions. They did not just audit us, they taught our team how to keep it running.
CTO, B2B SaaS companyBengaluru
They found a critical issue three hours into testing and called us straight away instead of saving it for the report. That is the difference between a vendor and a partner.
CISO, healthcare groupDelhi NCR

Ready When You Are

Tell us what is due and who is asking. You will leave the call with a written scope, a timeline and a fixed price, and an honest answer if we are not the right firm for it.