Skip to content
ISO 27001, SOC 2, the DPDP Act and manual VAPT.

Resources

The Questions Clients Ask, Answered in Public

We are writing up the guidance our consultants give during engagements: framework explainers, testing notes and the checklists we work from. What is here are the answers we give most often, the topics the writing will cover, and a direct line if you need something sooner.

Answers

The Questions We Hear Most

These come up in nearly every scoping call. The answers are the same ones we give on the phone, in full, with no gate in front of them.

We need ISO 27001 and SOC 2. Is that two separate projects?
No. The two frameworks overlap heavily, so we build one control set and one evidence base that satisfies both. That is faster and considerably cheaper than running them as separate programmes, and it keeps your team answering a question once instead of twice.
How long does DPDP Act readiness take?
For most mid-size organisations, 90 to 120 days to a defensible position: data mapped, consent flows live, a working process for data principal requests and a breach playbook you have actually tested. Maturity builds from there, and we usually stay on for the first few quarters.
How long does a VAPT take?
Most web or API assessments run one to three weeks depending on scope, plus a retest window once your fixes are in. You do not wait for the report to hear bad news: critical findings reach you within three hours of discovery.
Do you help with fixes, or only report problems?
We help. Every finding carries specific remediation guidance, our engineers are available to yours during fix sprints, and we retest to confirm each closure. The retest is part of the engagement, not a separate invoice.
What does an engagement cost?
It depends on scope: how many applications and environments, which frameworks, and how much of the work sits with your team. Walk us through what you run in a short call and you get a fixed quote, not an open-ended estimate that grows later.
How do we start?
One scoping call, usually 30 to 45 minutes, with the people who will do the work. We map what you need against what is urgent, then send a written scope, timeline and price. If we are not the right fit for the problem, we will tell you that on the call.

In Preparation

What We Will Publish, and What it Will Cover

Four series, drawn from work we have already delivered. The practice page behind each one carries the methodology, the tooling and the deliverables in detail.

  1. 01

    Framework Explainers

    What ISO 27001, SOC 2, PCI DSS and the DPDP Act actually require, written for the person who has to implement them rather than the person who signs the certificate.

    Compliance Practice
  2. 02

    Testing Notes

    How we test web applications, APIs, mobile apps and cloud environments, which classes of finding keep recurring, and what proof of exploitation should look like in a report.

    VAPT Practice
  3. 03

    Remediation Guidance

    The fix advice we hand engineering teams: configuration baselines, dependency upgrades, authorisation patterns and the retest evidence that closes a finding properly.

    Hardening Practice
  4. 04

    Regulatory Updates

    Changes to Indian and international rules that alter what your programme has to prove, and what they mean for the controls you already run.

    DPDP Act Readiness

Need Something We Have Not Written Yet?

If you want the control mapping, the checklist or the test plan behind any answer on this page, ask for it. We will send what we have, and say so plainly when we do not have it yet.

We reply within one business day.