Skip to content
ISO 27001, SOC 2, the DPDP Act and manual VAPT.

Our Platforms

Software We Built Because the Work Needed It

TrustGrid and DPDPA Compass are SecureRoot's own products. We use them to run engagements, so the busywork of collecting and refreshing evidence stops eating your team's week. They support the consulting; they never replace the judgement.

Jump to a Product

Every figure on these product boards is illustrative sample data from one example programme. No screenshot here shows a named client.

01

TrustGrid

GRC and Evidence Automation

TrustGrid holds one control set mapped across every framework you are pursuing, so a single piece of evidence answers ISO 27001, SOC 2 and PCI DSS at once. Your team sees what is open, what is due and what an auditor will ask for next.

What It Covers

  • One control library mapped across multiple frameworks
  • Evidence collection, ownership and renewal reminders
  • Audit-ready exports and internal audit tracking
  • Third-party risk assessments in the same place

Where It Fits in the Work

Inside the Product

One Control Set, Scored Against Every Framework

This is the board TrustGrid keeps current: 100 unified controls across 7 frameworks, 63 of them implemented, and the 11 failing checks named rather than averaged away.

A flat product screenshot of TrustGrid, a compliance automation platform, shown in its dark product interface. The left sidebar carries the TrustGrid mark, the line "Powered by SecureRoot Risk Advisory LLP", and grouped navigation: Overview holding Dashboard, Automation and Tasks with 23 outstanding; Compliance holding Frameworks, Controls, Applicability, Evidence, Policies and Audits; Risk holding Risk register, Third parties and Incidents; Privacy and AI holding Privacy and AI governance; Organisation holding People and access, Integrations, Trust centre, Reports and Settings. Header: compliance posture for SecureRoot Risk Advisory LLP, 7 frameworks in scope, 100 unified controls, with a button to run automated checks. Five headline figures: overall readiness 63 percent, being 63 of 100 controls implemented; 11 failing checks, from 22 passing and 7 warning out of 40; 23 open remediation and implementation tasks; 12 third parties, 2 of them overdue for reassessment; 4 rights requests, 1 past its statutory deadline. Posture trend, recorded once per day when the automated sweep runs, shown for the quarter with trust score selected: 74, 71, 69, 73, 75, 74, 72 on 06-04, 07-02, 07-30, 08-21, 08-25, 08-29, 08-30, so the trust score stands at 72 of 100 and has moved -2 points over the quarter. Trust score, a weighted blend shown broken down so it is never a black box: control readiness scores 66 at 45 percent weight, 63 of 100 controls implemented; automated checks scores 55 at 25 percent weight, 22 of 40 passing; operational hygiene scores 91 at 20 percent weight, 8 of 85 dated items overdue; risk exposure scores 100 at 10 percent weight, 0 of 11 open risks are critical. Those four weighted scores total 71.65, which rounds to the headline 72. Open findings by severity, covering failing checks, vendor findings and remediation tasks: 5 critical, 19 high, 34 medium, 15 low, which sum to the 73 open at the centre of the donut. Illustrative snapshot of a typical programme, not a named client.

Illustrative snapshot of one sample programme, not a named client. 63 percent readiness, a trust score of 72 broken into the four measures that produce it, and 73 open findings.

02

DPDPA Compass

DPDP Act Readiness and Privacy Operations

DPDPA Compass turns the DPDP Act into work you can assign and finish. It maps where personal data lives, tracks consent and data principal requests, and keeps the breach playbook current rather than filed away.

What It Covers

  • Personal data discovery and processing records
  • Consent capture, withdrawal and audit history
  • Data principal rights requests with response clocks
  • Breach assessment and notification workflow

Where It Fits in the Work

Inside the Product

Privacy Operations You Can Assign and Close

The working view of a DPDP Act programme: what consent you hold, which rights requests are running down their clocks, and how far the readiness assessment has actually got.

Illustrative snapshot of one sample programme, not a named client. The score is weighted: two domains the organisation cannot yet measure are excluded and the weights renormalised, never scored zero. One rights request is overdue, and the board says so.

Ready When You Are

Tell us what is due and who is asking. You will leave the call with a written scope, a timeline and a fixed price, and an honest answer if we are not the right firm for it.