Our Platforms
Software We Built Because the Work Needed It
TrustGrid and DPDPA Compass are SecureRoot's own products. We use them to run engagements, so the busywork of collecting and refreshing evidence stops eating your team's week. They support the consulting; they never replace the judgement.
Jump to a Product
Every figure on these product boards is illustrative sample data from one example programme. No screenshot here shows a named client.
01
TrustGrid
GRC and Evidence Automation
TrustGrid holds one control set mapped across every framework you are pursuing, so a single piece of evidence answers ISO 27001, SOC 2 and PCI DSS at once. Your team sees what is open, what is due and what an auditor will ask for next.
What It Covers
- One control library mapped across multiple frameworks
- Evidence collection, ownership and renewal reminders
- Audit-ready exports and internal audit tracking
- Third-party risk assessments in the same place
Inside the Product
One Control Set, Scored Against Every Framework
This is the board TrustGrid keeps current: 100 unified controls across 7 frameworks, 63 of them implemented, and the 11 failing checks named rather than averaged away.
A flat product screenshot of TrustGrid, a compliance automation platform, shown in its dark product interface. The left sidebar carries the TrustGrid mark, the line "Powered by SecureRoot Risk Advisory LLP", and grouped navigation: Overview holding Dashboard, Automation and Tasks with 23 outstanding; Compliance holding Frameworks, Controls, Applicability, Evidence, Policies and Audits; Risk holding Risk register, Third parties and Incidents; Privacy and AI holding Privacy and AI governance; Organisation holding People and access, Integrations, Trust centre, Reports and Settings. Header: compliance posture for SecureRoot Risk Advisory LLP, 7 frameworks in scope, 100 unified controls, with a button to run automated checks. Five headline figures: overall readiness 63 percent, being 63 of 100 controls implemented; 11 failing checks, from 22 passing and 7 warning out of 40; 23 open remediation and implementation tasks; 12 third parties, 2 of them overdue for reassessment; 4 rights requests, 1 past its statutory deadline. Posture trend, recorded once per day when the automated sweep runs, shown for the quarter with trust score selected: 74, 71, 69, 73, 75, 74, 72 on 06-04, 07-02, 07-30, 08-21, 08-25, 08-29, 08-30, so the trust score stands at 72 of 100 and has moved -2 points over the quarter. Trust score, a weighted blend shown broken down so it is never a black box: control readiness scores 66 at 45 percent weight, 63 of 100 controls implemented; automated checks scores 55 at 25 percent weight, 22 of 40 passing; operational hygiene scores 91 at 20 percent weight, 8 of 85 dated items overdue; risk exposure scores 100 at 10 percent weight, 0 of 11 open risks are critical. Those four weighted scores total 71.65, which rounds to the headline 72. Open findings by severity, covering failing checks, vendor findings and remediation tasks: 5 critical, 19 high, 34 medium, 15 low, which sum to the 73 open at the centre of the donut. Illustrative snapshot of a typical programme, not a named client.
A flat product screenshot of TrustGrid, a compliance automation platform, shown in its dark product interface. The left sidebar carries the TrustGrid mark, the line "Powered by SecureRoot Risk Advisory LLP", and grouped navigation: Overview holding Dashboard, Automation and Tasks with 23 outstanding; Compliance holding Frameworks, Controls, Applicability, Evidence, Policies and Audits; Risk holding Risk register, Third parties and Incidents; Privacy and AI holding Privacy and AI governance; Organisation holding People and access, Integrations, Trust centre, Reports and Settings. Header: compliance posture for SecureRoot Risk Advisory LLP, 7 frameworks in scope, 100 unified controls, with a button to run automated checks. Five headline figures: overall readiness 63 percent, being 63 of 100 controls implemented; 11 failing checks, from 22 passing and 7 warning out of 40; 23 open remediation and implementation tasks; 12 third parties, 2 of them overdue for reassessment; 4 rights requests, 1 past its statutory deadline. Posture trend, recorded once per day when the automated sweep runs, shown for the quarter with trust score selected: 74, 71, 69, 73, 75, 74, 72 on 06-04, 07-02, 07-30, 08-21, 08-25, 08-29, 08-30, so the trust score stands at 72 of 100 and has moved -2 points over the quarter. Trust score, a weighted blend shown broken down so it is never a black box: control readiness scores 66 at 45 percent weight, 63 of 100 controls implemented; automated checks scores 55 at 25 percent weight, 22 of 40 passing; operational hygiene scores 91 at 20 percent weight, 8 of 85 dated items overdue; risk exposure scores 100 at 10 percent weight, 0 of 11 open risks are critical. Those four weighted scores total 71.65, which rounds to the headline 72. Open findings by severity, covering failing checks, vendor findings and remediation tasks: 5 critical, 19 high, 34 medium, 15 low, which sum to the 73 open at the centre of the donut. Illustrative snapshot of a typical programme, not a named client.
02
DPDPA Compass
DPDP Act Readiness and Privacy Operations
DPDPA Compass turns the DPDP Act into work you can assign and finish. It maps where personal data lives, tracks consent and data principal requests, and keeps the breach playbook current rather than filed away.
What It Covers
- Personal data discovery and processing records
- Consent capture, withdrawal and audit history
- Data principal rights requests with response clocks
- Breach assessment and notification workflow
Inside the Product
Privacy Operations You Can Assign and Close
The working view of a DPDP Act programme: what consent you hold, which rights requests are running down their clocks, and how far the readiness assessment has actually got.
A flat product screenshot of DPDPA Compass, a privacy operations platform for the DPDP Act 2023 and the DPDP Rules 2025. Headline: weighted privacy posture score 68 of 100, up 6 points this quarter, computed across 14 of 16 assessment domains; 2 domains are not yet measurable, so the product excludes them and renormalises the weights rather than scoring them zero. Readiness assessment: 87 of 97 measurable questions answered, from 110 questions in total; the 2 excluded domains hold the remaining 13. Domain progress: Notice & Consent 82 percent, Data Principal Rights 74 percent, Security Safeguards 68 percent, Retention & Legal Holds 61 percent, Breach Response 55 percent, Processor Oversight 47 percent. Data Principal rights requests, served through a public portal with statutory response clocks: 14 open, 1 overdue, 41 closed this quarter. The five visible rows: DPR-0468, erasure, overdue 2 days; DPR-0482, access, 3 days left; DPR-0479, access, 11 days left; DPR-0485, correction, 19 days left; DPR-0486, nomination, 27 days left. Consent and discovery: 96,412 active consent records, 1,845 withdrawals in the last 90 days, 12,480 PAN and 3,214 Aadhaar-pattern identifiers found by checksum-validated discovery across 23 of 31 connected systems. DPIA: 6 in progress, 14 complete, 4 processor questionnaires open. Incident reporting: 2 open, 1 under reportability review with the decision pending. Audit trail: 48,112 hash-chained events, verified daily with no gaps found. Illustrative snapshot of a typical programme, not a named client.
A flat product screenshot of DPDPA Compass, a privacy operations platform for the DPDP Act 2023 and the DPDP Rules 2025. Headline: weighted privacy posture score 68 of 100, up 6 points this quarter, computed across 14 of 16 assessment domains; 2 domains are not yet measurable, so the product excludes them and renormalises the weights rather than scoring them zero. Readiness assessment: 87 of 97 measurable questions answered, from 110 questions in total; the 2 excluded domains hold the remaining 13. Domain progress: Notice & Consent 82 percent, Data Principal Rights 74 percent, Security Safeguards 68 percent, Retention & Legal Holds 61 percent, Breach Response 55 percent, Processor Oversight 47 percent. Data Principal rights requests, served through a public portal with statutory response clocks: 14 open, 1 overdue, 41 closed this quarter. The five visible rows: DPR-0468, erasure, overdue 2 days; DPR-0482, access, 3 days left; DPR-0479, access, 11 days left; DPR-0485, correction, 19 days left; DPR-0486, nomination, 27 days left. Consent and discovery: 96,412 active consent records, 1,845 withdrawals in the last 90 days, 12,480 PAN and 3,214 Aadhaar-pattern identifiers found by checksum-validated discovery across 23 of 31 connected systems. DPIA: 6 in progress, 14 complete, 4 processor questionnaires open. Incident reporting: 2 open, 1 under reportability review with the decision pending. Audit trail: 48,112 hash-chained events, verified daily with no gaps found. Illustrative snapshot of a typical programme, not a named client.
Ready When You Are
Tell us what is due and who is asking. You will leave the call with a written scope, a timeline and a fixed price, and an honest answer if we are not the right firm for it.