DataSurity

Assessment & Compliance Reporting

Every control, tested, evidenced and tracked to closure.

An assessment your Board and your auditor can rely on. Controls are tested on your real activities, systems and vendors, graded by the evidence behind them, reviewed by a partner and followed through to the fix.

Trusted by leading enterprises

  • Indiabulls Securities
  • KDSG Super-Speciality Hospital
  • Modicare
  • Express Inn Hotels & Resorts
  • Econo Broking
  • DAMS
  • Freesia by Express Inn
  • MBL
  • Trident Group
  • Dhani
  • Indiabulls Asset Reconstruction

Real evidence in. A report you can stand behind out.

The assessment reads your register, your records and your people, and gives leadership a clear view of where you stand.

  • Processing register
  • Discovery findings
  • Consent and rights records
  • Documents and policies
  • Stakeholder interviews
  • Sector regulator rules
DataSurity Assessment
  • Scored posture across 12 domains
  • Findings graded by evidence
  • Owners and a roadmap
  • Board report and deck
  • Annexure registers
  • A mitigation file
Built on evidence

An assessment that holds up under scrutiny

  • 181 controls

    Across 12 domains, mapped to NIST CSF 2.0, ISO 27001 and ISO 27701, and calibrated to the Act and Rules

  • 3 evidence grades

    Evidence-verified, assertion-only or not tested, shown on every finding

  • 2 citations

    On every control: the DPDP section and your sector regulator's rule, side by side

How it works

Five steps from first look to steady improvement

Features

What the assessment does for you

01

Tested where the data lives

Controls sit on the things they govern: each processing activity, system and third party. A control can't be scored without a source, and the unit tested and the sample drawn are recorded. The result reflects your operations, not a questionnaire.

02

Honest about evidence

Every finding says how it was established: verified from evidence, taken from what someone said, or not yet tested. The report shows the split, so leadership knows exactly how much of its posture rests on tested fact. AI helps extract evidence and draft working papers, with personal data anonymised first. Every finding still carries its evidence grade and a partner's approval.

03

Two regulators, one assessment

Each control carries its DPDP section and, where it applies, the RBI, SEBI, IRDAI or CERT-In rule beside it. Where the two disagree, on retention or incident reporting, the report gives the reconciled position instead of choosing one.

04

From findings to fixes, year on year

Findings go to named owners with management responses and a prioritised roadmap. Each result cites the version of the register it tested, so the next assessment measures real movement. The engagement's own record becomes the mitigation file Section 33(2) lets the Board consider.

What the Act asks, and how Assessment answers

The assessment tests the Data Fiduciary's general duties and shows the evidence behind each one.

Section
  • s.8(1), s.8(4)

    Accountability and appropriate measures to observe the Act

    Controls across 12 domains, tested and graded by evidence

  • s.8(2)

    Processors only under valid contracts

    Vendor contracts tested as control units

  • s.8(5), Rule 6

    Reasonable security safeguards

    Safeguard controls tested on each system, with Discovery evidence

  • s.8(6), Rule 7

    Breach intimation to the Board and affected people

    Incident readiness tested against both the DPDP and CERT-In clocks

  • s.10, Rule 12

    SDF duties: DPIA, independent audit, algorithmic checks

    SDF candidacy profiled per entity, with DPIA and audit readiness

  • s.17

    Exemptions

    Applied per activity, with the duties that still apply kept in scope

  • s.33(2)

    Factors the Board weighs in setting a penalty

    The assessment's record exported as a mitigation file

Deploy it your way

Built for regulated Indian enterprises: your data stays where your policies say it must.

  • 01

    SaaS, hosted in India

    Managed by SARC AI on infrastructure in Indian data centres.

  • 02

    Private cloud

    Runs in your own cloud account, under your keys and access policies.

  • 03

    On-premises

    Installed in your data centre. Scanners read in place, and nothing leaves your network.

Connects to

  • PostgreSQL
  • MySQL
  • Oracle Database
  • Microsoft SQL Server
  • MongoDB
  • MariaDB
  • IDIBM Db2
  • SAP HANA
  • Snowflake
  • Amazon Redshift
  • Google BigQuery
  • Databricks
  • Teradata
  • Amazon DynamoDB
  • Azure SQL
  • Apache Cassandra
  • Redis
  • Elasticsearch
  • Couchbase
  • ClickHouse
  • Apache Hive
  • Apache Kafka
  • SQLite
  • Neo4j

Connectors are enabled during onboarding. Logos belong to their owners and indicate compatibility, not endorsement.

Certified

  • CERTIFIEDISO 27001INFORMATION SECURITY
  • CERTIFIEDISO 27701PRIVACY INFORMATION

Frequently asked questions

How is this different from a DPDP self-assessment?

A self-assessment scores your answers to a questionnaire. This assessment tests controls on your actual activities, systems and vendor contracts, records what was sampled, and grades every result by the evidence behind it. A partner reviews each finding before it reaches the report.

How is it different from an ISO 27001 audit?

ISO 27001 tests an information security management system. DPDP also asks about lawful grounds, notices, consent, rights, processors, children's data, cross-border transfers and breach reporting. Our framework sits above NIST CSF 2.0, ISO 27001 and ISO 27701, and shows where the Act asks for more.

What does "assertion-only" mean on a finding?

That the control was scored on what someone told us, without evidence we tested ourselves. The report marks these separately from evidence-verified findings, so leadership sees clearly how much of the posture rests on tested fact.

Does it cover our sector regulator?

Yes. Sector overlays add RBI, SEBI, IRDAI or CERT-In citations beside the DPDP ones on every relevant control. Where the two conflict, such as on retention, the report reconciles them. One assessment covers both regulators.

How often should we run it?

Most organisations run it once a year. Between assessments, the processing register stays live in Data Journey Mapping, and findings are tracked to closure by their owners. Each new assessment cites the register version it tested, so progress from one year to the next is measurable.

What is a mitigation file?

Section 33(2) lists what the Data Protection Board considers when setting a penalty, including steps taken to mitigate. The assessment's own record, with its timestamps, versions and evidence, exports as the starting point of that file. The work of being assessed becomes part of your defence.

Trusted by leaders across industries

“We knew patient data sat in our hospital information system. We didn't know how much had spread into lab exports, scanned reports and shared drives until DataSurity's assessment showed us. The team understood hospital realities, from paediatric records to staff data, and gave us a plan we could actually run. Implementation is now moving ward by ward, with consent and rights handled in one place.”

Rakesh G

Head - Compliance, KDSG Hospitals (350-bed multispecialty hospital)

Knowledge resources

Find out where you stand. Then watch it improve.